# Darkfield > Darkfield is a free, public observatory of ransomware operators, dark-web leak-site victim disclosures, exploited zero-days, and blacklisted cryptocurrency wallets. It tracks hundreds of ransomware groups and tens of thousands of victim disclosures on permanent, citable URLs, and exposes the whole corpus through a free JSON feed, REST API, and an official Model Context Protocol (MCP) server. Built by Orizon (https://orizon.one). Darkfield is free to use, including commercially, with attribution. The data is a record of public operator *claims* on leak sites, not independently verified breaches — see the methodology before relying on it. Every operator and victim has a permanent dossier URL suitable for citation. ## Core data - [Ransomware operators](https://darkfield.orizon.one/groups): Every tracked ransomware/extortion group, with aliases, claimed victims, active timeline, infrastructure, and per-operator dossiers. - [Victim disclosures](https://darkfield.orizon.one/victims): Leak-site victim disclosures with company, sector, country, status, and date — each a permanent dossier. - [Sectors](https://darkfield.orizon.one/sectors): Ransomware targeting broken down by industry sector. - [Countries](https://darkfield.orizon.one/countries): Targeting broken down by victim country. - [Zero-days](https://darkfield.orizon.one/zero-days): Exploited CVEs linked to ransomware activity. - [Lineage graph](https://darkfield.orizon.one/lineage): Interactive map of how operators connect to victims via shared aliases and infrastructure. ## Free data access (no signup, no key) - [Data feed & API overview](https://darkfield.orizon.one/data): How to pull the data into tools, dashboards, and research. - [JSON feed](https://darkfield.orizon.one/feed.json): Most recent victim disclosures as JSON (CORS-open). - [RSS feed](https://darkfield.orizon.one/feed.xml): Same, as RSS 2.0. - [Interactive API reference](https://darkfield.orizon.one/api-reference): Full read API. Free; a free Observer key (50 requests/day) is needed only to call it. - [MCP server](https://github.com/Orizon-eu/orizon-darkfield/tree/main/mcp-server): Official Model Context Protocol server so AI assistants (Claude, Cursor) can query live ransomware intelligence directly. Tools: search_ransomware, get_operator, list_operators, recent_disclosures, ransomware_stats. ## Research & reference - [Research reports](https://darkfield.orizon.one/research): Original analysis, including the half-year ransomware index. - [Methodology](https://darkfield.orizon.one/methodology): How disclosures are collected, deduplicated, and what the data does and does not mean. - [About](https://darkfield.orizon.one/about): What Darkfield is, who builds it, and how to cite it. ## How to cite Cite as: "Darkfield (https://darkfield.orizon.one), Orizon." Deep-link the specific operator or victim dossier where possible.