Duplicate Ransomware Leak-Site Claims: RaaS Cartels, Affiliate Re-Extortion, Access-Broker Resale, and Fabrication (Bitdefender 'Claimed Twice')

Duplicate Ransomware Leak-Site Claims (TL-2026-0843), also tracked as Claimed Twice, is a info-severity tracked intrusion set, first published 2026-06-17. It has no confirmed attribution, maps to 21 MITRE ATT&CK techniques (T1021, T1048, T1078), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-0843

Threat ID
TL-2026-0843
Also known as
Claimed Twice, Duplicate ransomware victim claims
Severity
INFO
Status
TRACKING
Category
THREAT_INTEL
First published
2026-06-17
Last reviewed
2026-06-17
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
healthcare, financial, manufacturing, government, technology
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in Duplicate Ransomware Leak-Site Claims

Malware and tooling: BlackCat (ELF), BlackCat - S1068, Clop - S0611, LockBit, Qilin, RansomHub, beast

Bitdefender's June 2026 'Claimed Twice' analysis documents five structural reasons the same victim is posted on two ransomware leak sites and shows how fabricated claims (notably 0APT's 549 fake Q1-2026 victims, exposed when rival KryBit hacked 0APT) distort ecosystem statistics. The concrete cases it cites — the ALPHV/BlackCat-to-RansomHub re-extortion of Change Healthcare and the 0APT/KryBit feud — map to a real ransomware-as-a-service extortion kill chain spanning access brokers, affiliate movement, data theft, double extortion, and leak-site fabrication.

How Duplicate Ransomware Leak-Site Claims works

On 2026-06-17 Bitdefender published 'Claimed Twice', an analysis of a measurement problem in ransomware reporting: victim organizations increasingly appear on multiple ransomware data-leak sites (DLS) under different group flags, making leak-site counts unreliable. Across January-June 2026 the researchers counted 98 duplicate leak-site claims spanning 49 distinct organizations (every one posted twice), with a median gap of 12 days, a mean of ~23 days, and a maximum gap of 96 days between first and second posting (5 same-day, 16 within the first week, 12 in the 8-30 day band, 16 at 31+ days). Qilin alone accounted for 20 of the 98 claims.

The report identifies five structural causes: (1) one attacker, two groups — ransomware-cartel operations and rebrands where affiliates work across multiple brands and share infrastructure; (2) same data, claimed again — affiliate non-payment and re-extortion / data resale, exemplified by the ALPHV/BlackCat affiliate who, after BlackCat's exit scam following Change Healthcare's USD 22M payment, took the retained data to RansomHub for a second extortion attempt; (3) two real breaches — genuinely distinct intrusions of the same victim by unrelated groups; (4) access-broker resale — an initial-access broker (IAB) selling the same foothold/credentials to multiple operators; and (5) no breach at all — outright fabrication and wholesale plagiarism of victim lists.

The headline data point is 0APT: the group emerged in late January 2026 posting 91 victims in 48 hours and 458 the following month, but the claims were fabricated — over 180 zip filenames referenced organizations like Boeing, Goldman Sachs, and Mayo Clinic yet every download returned HTTP 502. In April 2026 rival group KryBit hacked 0APT, defaced its leak site ('Next time, don't play with the big boys'), and dumped 0APT's full operational dataset including access logs, PHP source, and system files, revealing infrastructure running AnLinux-Parrot OS serving content from an Android phone's internal SD card. Removing 0APT's 549 fabricated claims from Q1 2026 reverses the apparent trend from 3,014 claimed victims (+15% YoY) to 2,465 (~-6% YoY) — 'one fabricated brand is the entire distance between ransomware surged and ransomware fell.' This record is filed as THREAT_INTEL: the source carries no CVE, CVSS, or affected product/version, but the named cartels, the documented ALPHV→RansomHub chain, the IAB resale model, and the 0APT/KryBit feud are corroborated, trackable adversary behaviors with defensive and analytic value.

MITRE ATT&CK techniques used in TL-2026-0843

Lateral Movement

T1021 Remote Services

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing

Collection

T1213 Data from Information Repositories

Discovery

T1482 Domain Trust Discovery

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1657 Financial Theft

Credential Access

T1555 Credentials from Password Stores

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities; T1650 Acquire Access

Reconnaissance

T1591 Gather Victim Org Information

defense-impairment

T1685 Disable or Modify Tools

Remediation for Duplicate Ransomware Leak-Site Claims

Immediate actions

  • Treat single-source ransomware leak-site victim counts as unverified until cross-site duplicates are reconciled
  • When a duplicate claim appears, verify whether downloadable samples actually resolve before treating a victim as confirmed compromised (0APT's claims returned HTTP 502 on every download)

Longer-term hardening

  • De-duplicate cross-DLS claims by victim entity before producing trend statistics; flag fabricated/plagiarized brands so they do not inflate quarter-over-quarter figures
  • Correlate duplicate claims against initial-access-broker marketplace activity and affiliate movement between RaaS brands
  • Track ransomware-cartel infrastructure sharing and rebrands to avoid double-counting one operator as two groups
  • Assume affiliate non-payment and exit scams can produce a second extortion event from the same stolen data; plan victim notification and IR accordingly

Timeline of Duplicate Ransomware Leak-Site Claims

  • An ALPHV/BlackCat affiliate breaches Change Healthcare, dwelling ~9 days to move laterally and steal PHI/PII before deploying ransomware.
  • Operation Cronos disrupts LockBit's infrastructure, accelerating affiliate migration to other RaaS brands (ALPHV, RansomHub) and the rebrand/cartel dynamics that later produce duplicate cross-leak-site claims.
  • ALPHV/BlackCat pulls an exit scam after receiving a ~USD 22M Bitcoin ransom, going dark without paying its affiliate, who retains a copy of the stolen Change Healthcare data.
  • The unpaid affiliate re-extorts Change Healthcare through RansomHub, leaking stolen data — the canonical 'same data, claimed again' duplicate-claim case.
  • Dispossessor surfaces re-posting previously leaked victim data from defunct groups (e.g. LockBit), an early example of the 'no breach at all' plagiarism/recycled-claim cause.
  • Qilin affiliate-partnership spike: 71 victims posted in a single month, illustrating cross-brand affiliate movement that produces duplicate claims.
  • 0APT emerges, posting 91 fabricated victims in 48 hours (458 the following month); zip filenames cite Boeing, Goldman Sachs, and Mayo Clinic but every download returns HTTP 502.
  • Q1 2026 closes at 3,014 claimed victims (+15% YoY); removing 0APT's 549 fabricated claims yields 2,465 (~-6% YoY), reversing the apparent trend.
  • Rival group KryBit hacks 0APT, defaces its leak site, and dumps 0APT's full operational dataset (access logs, PHP source, system files) — exposing infrastructure on AnLinux-Parrot OS served from an Android phone SD card and proving the claims were fake.
  • Bitdefender publishes 'Claimed Twice', quantifying 98 duplicate claims across 49 organizations (median 12-day gap) and the five structural causes.

Sources cited for Duplicate Ransomware Leak-Site Claims

Threats related to Duplicate Ransomware Leak-Site Claims

Detection coverage for TL-2026-0843

As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0843 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats