{"uid":"cap_jGFztsmnwqCKnBBdShmwC","slug":"telesint-ransomware-activity-feed-9a675f11","name":"Telesint Ransomware Activity Feed","description":"Ransomware group activity from Telegram: victim posts, leak site announcements, extortion demands. Filters: severity, min_confidence, since, tag(lockbit|blackcat|cl0p|ransomhub), sector, country, limit, offset.","url":"https://telesint-api.onrender.com/ransomware","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{"tag":{"type":"string","description":"Ransomware group tag, e.g. lockbit, blackcat, cl0p, ransomhub, play, akira"},"limit":{"type":"number","description":"Page size, default 20, max 100"},"since":{"type":"string","description":"ISO 8601 timestamp filter, e.g. 2026-05-01T00:00:00Z"},"offset":{"type":"number","description":"Pagination offset, default 0"},"sector":{"type":"string","description":"Targeted sector: finance | healthcare | government | energy | retail"},"country":{"type":"string","description":"Targeted country keyword, e.g. us | uk | de | fr"},"severity":{"type":"string","description":"Minimum severity: critical | high | medium | low | info"},"organization":{"type":"string","description":"Targeted organization name partial match"},"min_confidence":{"type":"number","description":"Minimum AI confidence score 0-100"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"items":[{"id":"r1a2n3s4-o5m6-7890-abcd-ransom789012","ts":"2026-05-27T08:30:00Z","tlp":"WHITE","iocs":[{"type":"url","value":"https://lockbit3[.]onion/victims/usbank-data","context":"Ransomware leak site"}],"tags":["lockbit","ransomware","finance","data-leak","double-extortion"],"ttps":[{"id":"T1486","name":"Data Encrypted for Impact","tactic":"Impact"},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactic":"Exfiltration"}],"actor":{"name":"LockBit","aliases":["LockBit 3.0","LockBit Black"],"motivation":"financial","nation_state":null},"target":{"sectors":["finance"],"countries":["US"],"organizations":["Regional Bank Corp"]},"channel":"https://t[.]me/darkwebinformer","summary":"LockBit 3.0 claims breach of US regional bank — 2.4M customer records including SSNs posted to leak site","category":"ransomware","severity":"critical","confidence":88}],"limit":20,"total":27,"offset":0,"source":"TeleSint","endpoint":"ransomware"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.04","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.04/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.04","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.04","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_4-OebHtnNymAJoUahXBpr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.04","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns ransomware group activity intelligence sourced from Telegram, including victim posts, leak site announcements, and extortion demands, with filtering by group, severity, sector, country, and confidence.","exampleAgentPrompt":"Pull the latest high-severity ransomware activity from Telesint for LockBit and BlackCat groups targeting the healthcare sector in the US since May 1st 2025, with a minimum confidence of 75, and give me the top 25 results.","exampleUseCases":null,"resultDescription":"A paginated list of ransomware group activity records sourced from Telegram, including victim posts, leak site announcements, and extortion demands. Each record includes group tag, severity, AI confidence score, targeted organization/sector/country, and timestamps.","failureModes":["Invalid tag value returns 400 or empty results","since parameter not in ISO 8601 format causes parse error","min_confidence outside 0-100 range may return error or be ignored","Render.com cold start may cause initial latency spike or timeout","No matching results for filter combination returns empty array","Payment not processed (x402 protocol failure) blocks access"],"whenToPreferThis":"Use this endpoint when you need Telegram-sourced ransomware threat intelligence specifically — victim announcements, leak posts, and extortion activity — filtered by specific threat actor groups like LockBit, BlackCat, Cl0p, or RansomHub. Prefer this over generic threat feeds when you need near-real-time ransomware group activity with AI-scored confidence, sector/country targeting context, and Telegram provenance.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:55:55.387Z","isFirstParty":false}