Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites

Ransomware Double-Claiming (TL-2026-2248), also tracked as Double-Claimed Ransomware Victims, is a informational-severity ransomware operation, first published 2026-06-17. It has no confirmed attribution, maps to 10 MITRE ATT&CK techniques (T1005, T1021, T1078), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-2248

Threat ID
TL-2026-2248
Also known as
Double-Claimed Ransomware Victims, Ransomware Leak-Site Duplicate Claims
Severity
INFORMATIONAL
Status
ACTIVE
Category
RANSOMWARE
First published
2026-06-17
Last reviewed
2026-06-17
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
health, financial services, automotive manufacturing, technology, government administration
Target regions
North America, Europe, Asia
Detection rules
9
Indicators of compromise
20

Malware and tooling in Ransomware Double-Claiming

Malware and tooling: 0apt, ALPHV/BlackCat, AgendaCrypt, BlackCat (Windows), BlackCat - S1068, Clop, DEVMAN, DragonForce, LockBit, RansomHub - S1212, beast, dispossessor

Bitdefender's analysis of 98 ransomware leak-site claims across 49 organizations (Jan-Jun 2026) shows victims are frequently claimed by two different groups for five distinct reasons - shared-affiliate rebranding, unpaid-affiliate re-extortion, genuine repeat breaches, access-broker credential resale, and outright fabrication. Stripping out 0APT's 549 fabricated victims alone flips the apparent Q1 2026 ransomware victim growth rate from +15% YoY to -6% YoY.

How Ransomware Double-Claiming works

Bitdefender's Business Insights team curated a dataset of 98 leak-site claims spanning 49 distinct victim organizations posted between January and June 2026, deliberately selecting cases where the same organization (matched by name and root domain) was claimed by two different ransomware brands. The analysis identifies five non-exclusive mechanisms driving double-claims: (1) a single criminal operation running multiple brand names on shared infrastructure - e.g., the DragonForce cartel absorbing displaced RansomHub affiliates after RansomHub's April 2025 collapse, Qilin's 'gravitational pull' on the same affiliate pool, and Hunters International's identical-infrastructure rebrand into the data-extortion-only World Leaks; (2) data re-extortion, where an affiliate left unpaid by one operator (the ALPHV/BlackCat exit-scam after the Change Healthcare ransom) takes the same stolen dataset to a second brand (RansomHub) for a fresh shakedown, with a median 12-day gap between postings; (3) genuine repeat breaches, where an organization patches the originally exploited flaw but leaves systemic weaknesses (weak identity controls, flat networks, no monitoring) in place, letting a second, unrelated actor - or an access broker reselling credentials from the first breach - get back in (16 of 49 cases show 31+ day gaps consistent with separate incidents); (4) cartel/shared-infrastructure claims, where multiple affiliated brands (Beast preceding Qilin three times, The Gentlemen appearing three times, Devman handing off to DragonForce three times) each independently post the same breach; and (5) outright fabrication or false attribution, exemplified by the RaaS group 0APT posting 91 fake victims within 48 hours in January 2026 and a further 458 the following month (549 total) before rival group KryBit hacked 0APT's own infrastructure in April 2026, confirmed no data had ever been exfiltrated from the listed victims, and defaced 0APT's leak site. Removing just 0APT's fabricated claims from the Q1 2026 headline count (3,014 victims, +15% YoY) drops the total to 2,465 victims, a -6% YoY decline - demonstrating that a single fabricating brand can singlehandedly invert a widely reported industry trend line. The piece also cites LockBit's post-Operation Cronos claim of a US Federal Reserve breach that turned out to be recycled Evolve Bank & Trust data, and Dispossessor's wholesale reposting of existing Cl0p, LockBit, and Hunters International victim lists without any original access, as further fabrication/false-attribution precedents. Bitdefender's conclusion: raw leak-site victim counts are an unreliable threat-intel metric without de-duplication, and organizations facing a second claim against an already-remediated incident need a structured triage process (verify proof, compare data samples, assess group/cartel relationships, evaluate what security changes occurred since the first breach) rather than treating every claim as a new, independent intrusion requiring full incident response and separate ransom consideration.

MITRE ATT&CK techniques used in TL-2026-2248

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Initial Access

T1078 Valid Accounts; T1133 External Remote Services

Impact

T1491.002 Defacement: External Defacement; T1657 Financial Theft

Exfiltration

T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Resource Development

T1583 Acquire Infrastructure; T1588.002 Obtain Capabilities: Tool; T1650 Acquire Access

Remediation for Ransomware Double-Claiming

Immediate actions

  • Do not treat a second leak-site claim against an already-remediated victim as automatic proof of a new intrusion - verify actual data samples and proof-of-access before triggering full incident response or ransom negotiation
  • Compare the newly posted data samples against previously exfiltrated/leaked material to determine whether the second claim is recycled data rather than a fresh breach
  • Route any second-claim disclosure decision through legal counsel rather than an automated victim-notification workflow

Workarounds

  • Disable fully-automated public breach-notification or customer-communication workflows that trigger solely on a name match against a new leak-site posting; require manual triage first

Longer-term hardening

  • Maintain and consult a current map of known ransomware cartel/rebrand relationships (e.g., DragonForce-RansomHub affiliate absorption, Hunters International-to-World Leaks) before attributing a new claim to a genuinely new actor
  • Treat raw ransomware leak-site victim counts as an unreliable trend metric for board/executive reporting unless de-duplicated for fabricated and rebranded claims
  • After any ransomware incident, remediate systemic weaknesses (identity/credential hygiene, network segmentation, monitoring coverage) in addition to the originally exploited flaw, since patching only the initial vector leaves the door open for unrelated repeat breaches or access-broker resale
  • Monitor underground/access-broker markets for resale of credentials tied to your organization following any confirmed breach

Timeline of Ransomware Double-Claiming

  • An ALPHV/BlackCat affiliate breaches Change Healthcare's network and spends nine days moving laterally and staging data before deploying ransomware.
  • Change Healthcare (via UnitedHealth subsidiary Optum) pays a $22 million ransom to ALPHV/BlackCat for deletion of the stolen data.
  • ALPHV/BlackCat pulls an exit scam, shutting down its operation without paying its affiliate's share of the Change Healthcare ransom.
  • The unpaid affiliate takes its retained copy of the Change Healthcare data to RansomHub, which lists the 4TB dataset and demands a second ransom.
  • LockBit lists the US Federal Reserve on its leak site, claiming 33TB of exfiltrated banking data; the group instead publishes data actually belonging to Evolve Bank & Trust.
  • The FBI, with the UK NCA and German authorities, seizes the servers of the Dispossessor operation, which had been wholesale-reposting Cl0p, LockBit, and Hunters International victim lists as its own.
  • Hunters International operators launch World Leaks as a parallel, extortion-only (no-encryption) brand on the same infrastructure.
  • RansomHub's infrastructure goes dark; its affiliates begin migrating to Qilin and DragonForce.
  • Qilin claims a record 72-74 victims for April, the largest monthly total of any group, attributed to absorbing displaced RansomHub affiliates.
  • Hunters International formally announces its shutdown, confirming the full transition of operations to the World Leaks data-extortion brand.
  • The newly formed 0APT RaaS group posts 91 victims to its leak site within 48 hours of launch.
  • 0APT posts a further 458 victims over the following month, bringing its cumulative claimed-victim total to 549.
  • Rival group KryBit breaches 0APT's own infrastructure, confirms none of the 549 claimed victims were ever actually breached, and defaces 0APT's leak site.
  • Bitdefender publishes its 'Claimed Twice' analysis of 98 leak-site claims across 49 organizations, showing that removing 0APT's 549 fabricated claims alone flips reported Q1 2026 ransomware victim growth from +15% YoY to -6% YoY.

Sources cited for Ransomware Double-Claiming

More in ransomware

Detection coverage for TL-2026-2248

As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2248 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats