Deadlock Ransomware Gang Claims Pasello and DIATER on the Dark Web as New Victims + Video

Listen to this Post

Featured ImageIntroduction: Another Day, Another Dark Web Ransomware Claim

The ransomware landscape continues to evolve at an alarming pace, with cybercriminal groups racing to expand their list of alleged victims. Every week, organizations across multiple industries appear on dark web leak sites where threat actors attempt to pressure companies into paying ransoms by publicly claiming responsibility for network intrusions and data theft.

A recent post monitored by the ThreatMon Threat Intelligence Team indicates that the Deadlock ransomware group has added Pasello and DIATER to its list of claimed victims. While such announcements often generate immediate concern, it is important to understand that listings on ransomware leak sites represent claims made by cybercriminals and should not automatically be interpreted as verified security incidents. Independent confirmation from the affected organizations is necessary before concluding that a breach or data theft has actually occurred.

Dark Web Monitoring Detects New Deadlock Claims

According to monitoring conducted by the ThreatMon Threat Intelligence Team, the ransomware group known as Deadlock has listed Pasello as a victim on its dark web leak portal.

Shortly afterward, the same threat intelligence monitoring identified another listing where DIATER was also added to the group’s victim page.

Both entries appeared on July 28, 2026, within minutes of one another, suggesting that Deadlock may have published multiple alleged victims during a coordinated update to its leak site.

What These Claims Actually Mean

A company appearing on a ransomware

Cybercriminal organizations frequently publish company names as part of psychological pressure tactics designed to force negotiations. In some situations, attackers possess stolen files. In others, negotiations may still be underway, while occasionally the claims later prove exaggerated or unsupported.

Until Pasello or DIATER release official statements, or independent forensic investigations validate the allegations, the listings should be treated as unverified claims originating from the operators of the Deadlock ransomware group.

The Growing Role of Leak Sites

Modern ransomware operations increasingly rely on extortion instead of encryption alone.

Rather than simply locking computer systems, many groups first infiltrate networks, steal confidential documents, customer information, financial records, engineering files, or employee data, and then threaten public disclosure.

Dark web leak portals have therefore become an essential component of ransomware operations. These websites serve as public pressure platforms where criminal groups attempt to increase reputational damage and financial consequences for targeted organizations.

Why Threat Intelligence Teams Monitor These Listings

Threat intelligence platforms such as ThreatMon continuously monitor ransomware leak sites to identify newly published victims as early as possible.

Early detection allows organizations, cybersecurity researchers, incident response teams, and government agencies to begin evaluating potential exposure before official disclosures become available.

These alerts should be viewed as early warning indicators rather than definitive proof that an organization has experienced a confirmed compromise.

The Expanding Ransomware Ecosystem

The emergence of groups like Deadlock demonstrates how quickly the ransomware ecosystem continues to change.

Some ransomware gangs disappear after law enforcement operations, internal disputes, or infrastructure seizures, only to be replaced by newly formed operations that adopt similar extortion techniques.

Many modern ransomware groups also operate through affiliate programs, allowing independent attackers to use shared malware and infrastructure in exchange for a percentage of ransom payments. This ransomware-as-a-service business model has significantly lowered the barrier to entry for cybercriminals worldwide.

Why Organizations Must Stay Prepared

Regardless of whether these particular claims are ultimately verified, they reinforce the importance of maintaining strong cybersecurity defenses.

Organizations should implement multi-factor authentication, continuous vulnerability management, endpoint detection and response solutions, network segmentation, secure offline backups, and comprehensive employee security awareness training.

Rapid incident detection and an established response plan remain among the most effective defenses against ransomware operations that continue to evolve in sophistication.

Deep Analysis

Understanding

Publishing multiple alleged victims within a short timeframe suggests a structured release schedule rather than isolated incidents. Ransomware operators often batch announcements to maximize media attention while demonstrating activity to future victims and affiliates.

Psychological Pressure as a Business Model

Modern ransomware is no longer purely technical. Public leak sites are designed to create urgency by threatening regulatory consequences, customer distrust, and reputational damage. The publication itself becomes part of the extortion campaign.

Verification Remains Critical

Cybersecurity professionals understand that dark web postings represent intelligence indicators, not confirmed facts. Responsible reporting requires distinguishing between a criminal claim and independently verified evidence.

The Importance of Threat Intelligence

Threat intelligence services provide valuable visibility into underground criminal activity. Even when information is unverified, early awareness enables organizations to begin internal investigations before wider public disclosure.

Multiple Victims May Indicate Active Campaigns

When several organizations appear within minutes, analysts often consider whether the threat actor recently completed a coordinated campaign targeting a specific industry, geography, or vulnerable technology. Additional victims may emerge over the coming days if this pattern continues.

Reputation Damage Can Exceed Technical Damage

For many organizations, the public announcement itself can become a crisis. Customers, investors, partners, and regulators frequently seek immediate clarification, placing communication teams under significant pressure regardless of whether the attack is ultimately confirmed.

Data Theft Continues to Replace Encryption

Many ransomware operators increasingly prioritize data exfiltration over encrypting systems. Stolen information often provides longer-term leverage, especially if victims possess reliable backups that reduce the impact of encryption alone.

Defensive Readiness Matters More Than Ever

Organizations should assume that attempts at intrusion are inevitable. Continuous monitoring, privileged access management, rapid patch deployment, and employee awareness remain essential components of a mature cybersecurity strategy.

Supply Chain Exposure Cannot Be Ignored

Even companies with strong security programs can become indirect victims through compromised vendors, managed service providers, or software suppliers. Supply chain security is now an essential element of cyber resilience.

Global Collaboration Remains Essential

Governments, private companies, security vendors, and intelligence platforms continue sharing indicators of compromise and attack techniques. This collective defense model significantly improves the industry’s ability to identify emerging ransomware campaigns quickly.

What Undercode Say:

Treat Every Dark Web Listing with Healthy Skepticism

Deadlock’s announcement should be viewed as an intelligence signal rather than confirmed evidence. Cybercriminals have a clear incentive to exaggerate or strategically publish claims to strengthen their negotiating position.

Speed Is Important, Accuracy Is More Important

Security teams should investigate reports immediately without assuming every published victim has experienced confirmed data theft. Responsible cybersecurity balances rapid response with evidence-based conclusions.

Leak Sites Are Becoming Strategic Weapons

Ransomware groups increasingly use public exposure as a primary weapon. The threat of reputational harm can be as powerful as malware itself, especially for organizations operating in regulated industries.

Threat Intelligence Provides Valuable Early Warnings

Monitoring services like ThreatMon help organizations identify potential incidents before official disclosures become available. Early visibility allows faster containment if an intrusion has actually occurred.

Public Claims Should Trigger Internal Reviews

Organizations named on ransomware portals should immediately review authentication logs, privileged account activity, endpoint alerts, cloud access, and outbound network traffic while coordinating with incident response teams.

Communication Strategy Is Now Part of Cybersecurity

Technical containment alone is no longer enough. Organizations need prepared communication plans that address customers, regulators, employees, investors, and business partners during cybersecurity incidents.

Continuous Security Investment Pays Off

Companies investing in proactive detection, network monitoring, backup testing, and employee awareness generally recover faster from ransomware attempts than organizations relying solely on perimeter defenses.

The Human Element Remains Critical

Many ransomware attacks begin with phishing, credential theft, or social engineering. Employee education continues to be one of the most effective layers of defense against modern cybercrime.

International Cooperation Must Continue

Law enforcement successes have disrupted numerous ransomware groups, but new actors rapidly emerge. Global intelligence sharing remains essential for slowing the growth of ransomware ecosystems.

Organizations Should Prepare Before They Become Targets

The most successful incident response begins long before an attack occurs. Security exercises, backup validation, tabletop simulations, and continuous monitoring significantly improve organizational resilience against future ransomware campaigns.

✅ Fact: Threat intelligence monitoring reported that the Deadlock ransomware group listed Pasello and DIATER as alleged victims on July 28, 2026.

✅ Fact: At the time of reporting, the available information originated from ransomware leak site monitoring and does not independently verify that either organization experienced a confirmed breach.

✅ Fact: There is currently no publicly available official confirmation from Pasello or DIATER validating the ransomware group’s claims, so they should be treated as allegations pending further investigation.

Prediction

(+1) Threat intelligence platforms will continue improving automated monitoring of ransomware leak sites, enabling organizations to receive earlier warnings and respond more quickly to potential compromises before widespread public disclosure.

(-1) If Deadlock remains operational and successful in attracting affiliates, additional organizations may appear on its dark web leak portal in the coming weeks, potentially increasing pressure on businesses through public extortion campaigns even before incidents are independently verified.

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.pinterest.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube