Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks

Cory Wolff

BSides NYC 2025 (0x05) · Day 1 · Tech - Red

In "Inside Ransomware: Facts and Findings from the Blackbasta and Lockbit Leaks," Cory Wolff, Director of Offensive Security at Risk 360, provides an unprecedented look into the internal operations of two of the most prolific ransomware groups: Black Basta and LockBit. Drawing from recently leaked internal chat messages and database dumps, Wolff offers a rare glimpse beyond typical government intelligence reports and public bragging, revealing the sophisticated, business-like nature of these criminal enterprises. The talk dissects the methodologies, tools, and internal dynamics of these groups, shedding light on how they conduct reconnaissance, manage affiliates, and even handle internal missteps.

AI review

Solid threat intel briefing that squeezes genuine value from rare primary source material — the leaks themselves do most of the heavy lifting. Wolff synthesizes the data competently and lands a few genuinely good findings (the Ascension Health timeline, the Russian gov entity incident, the ZoomInfo OSINT angle), but the analysis rarely goes deeper than what a careful reader of the raw data could produce themselves.

Watch on YouTube