About the archive
About OpenSpy
OpenSpy is an independent visual archive of websites before and after seizures, suspensions, takedowns, abandonment, redirects, and resurrection. It also catalogs public-interest record collections when the provenance and privacy boundaries can be stated plainly.
Web infrastructure is temporary. Reporting is scattered. Screenshots vanish. Official announcements move. Domains expire and are occasionally purchased by completely unrelated people selling questionable supplements.
OpenSpy connects snapshots, timelines, sources, domains, organizations, related operations, and public-record catalogs in one archive.
The project begins with ransomware infrastructure already documented through Extortion Wiki.
The archives answer different questions:
Extortion Wiki documents the actors and activity.
OpenSpy documents what happened to the websites.
OpenSpy does not declare a website criminal solely because it went offline. Records distinguish confirmed actions, credible reporting, technical observations, and unresolved status changes.
Public records are sourced, reviewed, and published as static archive entries. Research drafts remain outside public routes until their evidence and required fields have been checked.
OpenSpy does not turn a database name hit into an accusation. Association, correspondence, presence in a released file, and proven conduct are different things. The archive labels those differences because search boxes do not.
Who runs this?
OpenSpy is maintained by researchers, archivists, and people who got tired of official evidence disappearing behind redesigned websites.
The work includes finding status changes, checking primary sources, preserving public media, reviewing claims, and maintaining the archive. There are no invented founders, stock-photo employees, or fake job titles ending in “visionary.”