On September 09, 2024, the Taliban-run website salaam.af appeared on the LockBit 3.0 ransomware leak site, claiming that its internal files had been exfiltrated during a ransomware attack. The listing states that data belonging to Taliban users was taken, though the exact number of affected individuals and the full scope of records remain undisclosed by the group.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch salaam.af
Get alerted the next time salaam.af files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about salaam.af’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The LockBit 3.0 leak page explicitly lists salaam.af as a victim and describes the incident as a successful ransomware operation that resulted in the theft of internal files. The disclosure does not quantify the volume of data taken, list specific file types beyond “internal files,” or provide samples. It also does not state when the initial compromise occurred or whether any encryption was deployed. The primary disclosure source is the official LockBit 3.0 onion site, mirrored on ransomware.live at the URL listed below.
Data exposed: Internal files exfiltrated in ransomware attack. Affected: Taliban users. These sparse but official claims from the threat actor’s own platform are the sole primary facts available.
Why This Matters for You and Your Family
Even when a breach targets a government-affiliated Afghan site, ordinary people whose personal information appears in those internal files face direct risk. If you or any member of your family ever interacted with salaam.af, used an email address tied to Afghan government services, or had documents processed by Taliban-linked entities, your details may now sit in a criminal archive. Ransomware groups rarely limit themselves to the named target; once data leaves the victim’s network it spreads through resale, extortion, and public leaks. Your family’s addresses, phone numbers, or identity documents could surface next on dark-web markets or extortion boards.