Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites — Threadlinqs Intelligence
As of 2026-08-30, Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites is a informational-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-2248 · Severity: INFORMATIONAL · Status: ACTIVE · Category: RANSOMWARE
Bitdefender's analysis of 98 ransomware leak-site claims across 49 organizations (Jan-Jun 2026) shows victims are frequently claimed by two different groups for five distinct reasons -
Bitdefender's Business Insights team curated a dataset of 98 leak-site claims spanning 49 distinct victim organizations posted between January and June 2026, deliberately selecting cases where the same organization (matched by name and root domain) was claimed by two different ransomware brands. The analysis identifies five non-exclusive mechanisms driving double-claims: (1) a single criminal operation running multiple brand names on shared infrastructure - e.g., the DragonForce cartel absorbing displaced RansomHub affiliates after RansomHub's April 2025 collapse, Qilin's 'gravitational pull' on the same affiliate pool, and Hunters International's identical-infrastructure rebrand into the data-extortion-only World Leaks; (2) data re-extortion, where an affiliate left unpaid by one operator (the ALPHV/BlackCat exit-scam after the Change Healthcare ransom) takes the same stolen dataset to a second brand (RansomHub) for a fresh shakedown, with a median 12-day gap between postings; (3) genuine repeat breaches, where an organization patches the originally exploited flaw but leaves systemic weaknesses (weak identity controls, flat networks, no monitoring) in place, letting a second, unrelated actor - or an access broker reselling credentials from the first breach - get back in (16 of 49 cases show 31+ day gaps consistent with separate incidents); (4) cartel/shared-infrastructure claims, where multiple affiliated brands (Beast preceding Qilin three times, The Gentlemen appearing three times, Devman handing off to DragonForce three times) each independently post the same breach; and (5) outright fabrication or false attribution, exemplified by the RaaS group 0APT posting 91 fake victims within 48 hours in January 2026 and a further 458 the following month (549 total) before rival group KryBit hacked 0APT's own infrastructure in April 2026, confirmed no data had ever been exfiltrated from the listed victims, and defaced 0APT's leak site. Removing just 0APT's fabricated claims from the Q1 2026 headline count (3,014 victims, +15% YoY) drops the total to 2,465 victims, a -6% YoY decline - demonstrating that a single fabricating brand can singlehandedly invert a widely reported industry trend line. The piece also cites LockBit's post-Operation Cronos claim of a US Federal Reserve breach that turned out to be recycled Evolve Bank & Trust data, and Dispossessor's wholesale reposting of existing Cl0p, LockBit, and Hunters International victim lists without any original access, as further fabrication/false-attribution precedents. Bitdefender's conclusion: raw leak-site victim counts are an unreliable threat-intel metric without de-duplication, and organizations facing a second claim against an already-remediated incident need a structured triage process (verify proof, compare data samples, assess group/cartel relationships, evaluate what security changes occurred since the first breach) rather than treating every claim as a new, independent intrusion requiring full incident response and separate ransom consideration.
Target sectors: health, financial services, automotive manufacturing, technology, government administration
Target regions: North America, Europe, Asia
Timeline
- An ALPHV/BlackCat affiliate breaches Change Healthcare's network and spends nine days moving laterally and staging data before deploying ransomware.
- Change Healthcare (via UnitedHealth subsidiary Optum) pays a $22 million ransom to ALPHV/BlackCat for deletion of the stolen data.
- ALPHV/BlackCat pulls an exit scam, shutting down its operation without paying its affiliate's share of the Change Healthcare ransom.
- The unpaid affiliate takes its retained copy of the Change Healthcare data to RansomHub, which lists the 4TB dataset and demands a second ransom.
- LockBit lists the US Federal Reserve on its leak site, claiming 33TB of exfiltrated banking data; the group instead publishes data actually belonging to Evolve Bank & Trust.
- The FBI, with the UK NCA and German authorities, seizes the servers of the Dispossessor operation, which had been wholesale-reposting Cl0p, LockBit, and Hunters International victim lists as its own.
- Hunters International operators launch World Leaks as a parallel, extortion-only (no-encryption) brand on the same infrastructure.
- RansomHub's infrastructure goes dark; its affiliates begin migrating to Qilin and DragonForce.
- Qilin claims a record 72-74 victims for April, the largest monthly total of any group, attributed to absorbing displaced RansomHub affiliates.
- Hunters International formally announces its shutdown, confirming the full transition of operations to the World Leaks data-extortion brand.
- The newly formed 0APT RaaS group posts 91 victims to its leak site within 48 hours of launch.
- 0APT posts a further 458 victims over the following month, bringing its cumulative claimed-victim total to 549.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, INFORMATIONAL, threat intelligence, cybersecurity, T1650, T1583, T1588.002, T1078, T1133, T1021, T1005, T1567.002, T1657, T1491.002