A pro-Ukraine member of the Conti ransomware gang posts 339 days' worth of the group's chat logs, after its leaders declared support for Russia
A member of the Conti ransomware group, believed to be Ukrainian of origin, has leaked the gang's internal chats after the group's leaders posted …
The RecordCatalin Cimpanu
Context & Ripple Effects
Conti’s public alignment with Russia turned an internal wartime divide into an operational exposure: the resulting logs later provided a detailed view of the group’s hierarchy, while the leaker was subsequently identified in coverage as Ukrainian IT specialist Danylo. The leak matters as more than reputational damage because it made the organization’s internal workings available beyond its leaders and affiliates.
First-order effects
Conti’s leadership and members lose the confidentiality of nearly a year of internal communications, with the group’s structure and hierarchy exposed to outside scrutiny.
The pro-Ukraine leaker’s release makes Conti’s Russia-aligned leadership position a source of internal fracture rather than a unified public signal.
Conti’s leaders face a more fragile affiliate model as operational information circulates publicly; later reporting says the group took its infrastructure offline and leaders partnered with smaller ransomware groups.
Third-order effects
The episode points to politically driven insider leaks as a durable weakness for ransomware organizations whose members and leadership are split by conflict loyalties.
Conti’s subsequent move from a single visible operation toward partnerships with smaller groups suggests ransomware capability can persist even as a branded organization fractures.
The trend: Geopolitical alignment is becoming an operational risk for cybercrime groups, exposing internal divisions that can disperse both intelligence and attack tools.
This is a damaging leak for the Conti operation as it will be pored over by law enforcement and security researchers in the days to come. With that said, it is also damaging to undisclosed victims who paid ransoms to hide their attacks, decrypt data, or prevent the leak of data.
The Conti ransomware leaks are wild. The ransomware gang was reportedly in dispute about is support of Russia. Then these files appeared. More than 60k messages, inc victim details, bitcoin addresses etc. A potentially huge win for law enforcement https://www.bleepingcomputer.com…
I consolidated and translated them in a JSON format for easy parsing and analysis 🙂 There is some interesting stuff there but a lot of it is boring chatter... Be warned, this is google translation! 😄 https://github.com/... https://twitter.com/...
Conti Leaks is bananas. The ransomware gang needed to pay $10k to their lawyer to represent Alla Witte, who was arrested by the FBI. https://twitter.com/...
We've indexed the first file here: https://intelx.io/... 🔓 The large conti.7z file will be indexed later and added to this thread. #Conti #ransomware https://twitter.com/... https://twitter.com/...
I've said it before and I'll say it again: The Achilles heel of end to end encryption is that the message gets decrypted once it reaches the other end https://twitter.com/...
In revenge, they leaked over 60,000 internal messages tonight from a Jabber log server used by the ransomware gang to discuss their operations, internal practices, and extortion attempts. Below is the message sent to journalists. https://twitter.com/...