The Dark Dive cover art

The Dark Dive

The Dark Dive

Written by: Searchlight Cyber
Listen for free

About this listen

The Dark Dive podcast is designed to demystify the dark web - arming you with everything you need to know about what the dark web is and how it is used. Join us for a deep dive into dark web markets, hacking forums, and ransomware leak sites. Listen to real life stories from experts that feature criminals buying and selling stolen data, trading exploits, and planning cyberattacks from the dark web. Most importantly, find out how the cybersecurity and law enforcement community can do something about it. Want to find out more? Email: thedarkdive@slcyber.io Website: www.slcyber.io LinkedIn: www.linkedin.com/company/searchlight-cyber X: www.twitter.com/SLCyberSec Weekly newsletter: www.slcyber.io/beacon/Copyright 2025 Searchlight Cyber Economics Politics & Government
Episodes
  • 20. Ransomware Landscape Update: More Groups, More Victims
    Sep 25 2025

    In this episode of The Dark Dive we check in on the ransomware landscape, following major developments identified by the Searchlight Cyber threat intelligence team.

    Luke Donovan, Head of Threat Intelligence at Searchlight Cyber, shares trends that his team has identified from the dark web in 2025 including: an escalation in the number of ransomware attacks, more than 35 new ransomware groups emerging, and alarming new tactics for vulnerability exploitation and victim extortion.

    This episode also features the famous Searchlight "Top Five Ranking" of ransomware groups, discussion of why LockBit has disappeared from the list, and advice for private sector and government cybersecurity professionals in a hostile ransomware landscape.

    Further reading:

    - The report discussed throughout the episode, "An Escalation in Attacks: The Ransomware Landscape in H1 2025": https://www.slcyber.io/whitepapers-reports/an-escalation-in-attacks-the-ransomware-landscape-in-h1-2025/

    - Our dedicated podcast on the recent hack of LockBit, "A Deep Dive Into The LockBit Data Leaks" (mentioned at 30.00): https://slcyber.io/podcasts/a-deep-dive-into-the-lockbit-data-leaks/

    - Our previous ransomware report where we predicted Akira as a group to watch, "More Groups, More Problems: Ransomware in 2023" (mentioned at 32.49): https://slcyber.io/whitepapers-reports/ransomware-in-2023/

    - Our previous podcast episode on Qilin's attack on the UK's National Health Service, "The Qilin Ransomware Group vs The National Health Service" (mentioned 34.35): https://slcyber.io/podcasts/the-qilin-ransomware-group-vs-the-national-health-service/

    - The ransomware report we released at the beginning of this year, where RansomHub featured no.1, "Same Game, New Players: Ransomware in 2025" (mentioned 36.35): https://slcyber.io/whitepapers-reports/same-game-new-players-ransomware-in-2025/

    Want to find out more or have a suggestion for future podcast episodes?

    Email: thedarkdive@slcyber.io

    Website: www.slcyber.io

    LinkedIn: www.linkedin.com/company/searchlight-cyber

    X: www.twitter.com/SLCyberSec

    Weekly newsletter: www.slcyber.io/beacon/

    Show More Show Less
    50 mins
  • 19. A Deep Dive Into The LockBit Data Leaks
    Jul 21 2025

    On May 7th, 2025 the notorious ransomware group LockBit’s dark web leak site displayed an unusual message: “Don’t do crime, crime is bad xoxo from Prague”. Alongside this text was the link to an archive file, containing data that appeared to have been stolen from the LockBit ransomware group itself.

    In this month's episode of The Dark Dive, members of the Searchlight Cyber threat intelligence team share what they learned by downloading and analysing the files. They share insights into the "Lite" version of LockBit's Ransomware-as-a-Service scheme captured in the data, what we learnt about the 76 affiliate hackers caught up in the data leak, and from the 208 victim negotiations.

    Juicy details include the range of payments that the hackers demand from their victims, unexpected conversations in the negotiation chats, and the deliberate targeting of Chinese enterprises.

    Further reading:

    - Previous episode of The Dark Dive on LockBit - "The LockBit TakeDown" (Discussed at 01.20): https://slcyber.io/podcasts/the-lockbit-takedown/

    - Listen to previous episode of The Dark Dive - "Ransomware Groups on the Dark Web" - for more information on Ransomware-as-a-Service schemes (Discussed from 01.50 onwards): https://slcyber.io/podcasts/ransomware-gangs-on-the-dark-web/

    - The episode of The Dark Dive that covers TOX and other messaging applications - "Encrypted Communication Apps: From Telegram to EncroChat" (Discussed at 10.20) : https://slcyber.io/podcasts/encrypted-communication-apps-from-telegram-to-encrochat/

    Want to find out more or have a suggestion for future podcast episodes?

    Email: thedarkdive@slcyber.io

    Website: www.slcyber.io

    LinkedIn: www.linkedin.com/company/searchlight-cyber

    X: www.twitter.com/SLCyberSec

    Weekly newsletter: www.slcyber.io/beacon/

    Show More Show Less
    41 mins
  • 18. ASM in the Age of CTEM
    Jun 24 2025

    This month's episode of The Dark Dive revisits the topic of Attack Surface Management. In particular, how it relates to a relatively new cybersecurity term, CTEM: Continuous Threat Exposure Management.

    In a lively discussion, guests Michael Gianarakis and Ben Jones help define CTEM, a security process that has quickly gained traction thanks to being championed by the analyst firm Gartner. They debate what CTEM adds to cybersecurity, how it builds on previously established concepts, and where ASM and threat intelligence play a role in the process.

    Along the way, Michael and Ben give practical advice for how organizations should be implementing CTEM, including common pitfalls to avoid and ways that security teams can measure the success and maturity of their CTEM program.

    This episode ties in with the new e-book published by Searchlight Cyber, "ASM in the age of CTEM", which you can download here for free: https://slcyber.io/ebooks/asm-in-the-age-of-ctem/

    Want to find out more or have a suggestion for future podcast episodes?

    Email: thedarkdive@slcyber.io

    Website: www.slcyber.io

    LinkedIn: www.linkedin.com/company/searchlight-cyber

    X: www.twitter.com/SLCyberSec

    Weekly newsletter: www.slcyber.io/beacon/

    Show More Show Less
    56 mins
No reviews yet