Ransomware Double-Claiming: Why the Same Victim Appears on Two Leak Sites
Ransomware Double-Claiming (TL-2026-2248), also tracked as Double-Claimed Ransomware Victims, is a informational-severity ransomware operation, first published 2026-06-17. It has no confirmed attribution, maps to 10 MITRE ATT&CK techniques (T1005, T1021, T1078), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-2248
- Threat ID
- TL-2026-2248
- Also known as
- Double-Claimed Ransomware Victims, Ransomware Leak-Site Duplicate Claims
- Severity
- INFORMATIONAL
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-06-17
- Last reviewed
- 2026-06-17
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- health, financial services, automotive manufacturing, technology, government administration
- Target regions
- North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Ransomware Double-Claiming
Malware and tooling: 0apt, ALPHV/BlackCat, AgendaCrypt, BlackCat (Windows), BlackCat - S1068, Clop, DEVMAN, DragonForce, LockBit, RansomHub - S1212, beast, dispossessor
Bitdefender's analysis of 98 ransomware leak-site claims across 49 organizations (Jan-Jun 2026) shows victims are frequently claimed by two different groups for five distinct reasons - shared-affiliate rebranding, unpaid-affiliate re-extortion, genuine repeat breaches, access-broker credential resale, and outright fabrication. Stripping out 0APT's 549 fabricated victims alone flips the apparent Q1 2026 ransomware victim growth rate from +15% YoY to -6% YoY.
How Ransomware Double-Claiming works
Bitdefender's Business Insights team curated a dataset of 98 leak-site claims spanning 49 distinct victim organizations posted between January and June 2026, deliberately selecting cases where the same organization (matched by name and root domain) was claimed by two different ransomware brands. The analysis identifies five non-exclusive mechanisms driving double-claims: (1) a single criminal operation running multiple brand names on shared infrastructure - e.g., the DragonForce cartel absorbing displaced RansomHub affiliates after RansomHub's April 2025 collapse, Qilin's 'gravitational pull' on the same affiliate pool, and Hunters International's identical-infrastructure rebrand into the data-extortion-only World Leaks; (2) data re-extortion, where an affiliate left unpaid by one operator (the ALPHV/BlackCat exit-scam after the Change Healthcare ransom) takes the same stolen dataset to a second brand (RansomHub) for a fresh shakedown, with a median 12-day gap between postings; (3) genuine repeat breaches, where an organization patches the originally exploited flaw but leaves systemic weaknesses (weak identity controls, flat networks, no monitoring) in place, letting a second, unrelated actor - or an access broker reselling credentials from the first breach - get back in (16 of 49 cases show 31+ day gaps consistent with separate incidents); (4) cartel/shared-infrastructure claims, where multiple affiliated brands (Beast preceding Qilin three times, The Gentlemen appearing three times, Devman handing off to DragonForce three times) each independently post the same breach; and (5) outright fabrication or false attribution, exemplified by the RaaS group 0APT posting 91 fake victims within 48 hours in January 2026 and a further 458 the following month (549 total) before rival group KryBit hacked 0APT's own infrastructure in April 2026, confirmed no data had ever been exfiltrated from the listed victims, and defaced 0APT's leak site. Removing just 0APT's fabricated claims from the Q1 2026 headline count (3,014 victims, +15% YoY) drops the total to 2,465 victims, a -6% YoY decline - demonstrating that a single fabricating brand can singlehandedly invert a widely reported industry trend line. The piece also cites LockBit's post-Operation Cronos claim of a US Federal Reserve breach that turned out to be recycled Evolve Bank & Trust data, and Dispossessor's wholesale reposting of existing Cl0p, LockBit, and Hunters International victim lists without any original access, as further fabrication/false-attribution precedents. Bitdefender's conclusion: raw leak-site victim counts are an unreliable threat-intel metric without de-duplication, and organizations facing a second claim against an already-remediated incident need a structured triage process (verify proof, compare data samples, assess group/cartel relationships, evaluate what security changes occurred since the first breach) rather than treating every claim as a new, independent intrusion requiring full incident response and separate ransom consideration.
MITRE ATT&CK techniques used in TL-2026-2248
Collection
Lateral Movement
Initial Access
T1078 Valid Accounts; T1133 External Remote Services
Impact
T1491.002 Defacement: External Defacement; T1657 Financial Theft
Exfiltration
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Resource Development
T1583 Acquire Infrastructure; T1588.002 Obtain Capabilities: Tool; T1650 Acquire Access
Remediation for Ransomware Double-Claiming
Immediate actions
- Do not treat a second leak-site claim against an already-remediated victim as automatic proof of a new intrusion - verify actual data samples and proof-of-access before triggering full incident response or ransom negotiation
- Compare the newly posted data samples against previously exfiltrated/leaked material to determine whether the second claim is recycled data rather than a fresh breach
- Route any second-claim disclosure decision through legal counsel rather than an automated victim-notification workflow
Workarounds
- Disable fully-automated public breach-notification or customer-communication workflows that trigger solely on a name match against a new leak-site posting; require manual triage first
Longer-term hardening
- Maintain and consult a current map of known ransomware cartel/rebrand relationships (e.g., DragonForce-RansomHub affiliate absorption, Hunters International-to-World Leaks) before attributing a new claim to a genuinely new actor
- Treat raw ransomware leak-site victim counts as an unreliable trend metric for board/executive reporting unless de-duplicated for fabricated and rebranded claims
- After any ransomware incident, remediate systemic weaknesses (identity/credential hygiene, network segmentation, monitoring coverage) in addition to the originally exploited flaw, since patching only the initial vector leaves the door open for unrelated repeat breaches or access-broker resale
- Monitor underground/access-broker markets for resale of credentials tied to your organization following any confirmed breach
Timeline of Ransomware Double-Claiming
- An ALPHV/BlackCat affiliate breaches Change Healthcare's network and spends nine days moving laterally and staging data before deploying ransomware.
- Change Healthcare (via UnitedHealth subsidiary Optum) pays a $22 million ransom to ALPHV/BlackCat for deletion of the stolen data.
- ALPHV/BlackCat pulls an exit scam, shutting down its operation without paying its affiliate's share of the Change Healthcare ransom.
- The unpaid affiliate takes its retained copy of the Change Healthcare data to RansomHub, which lists the 4TB dataset and demands a second ransom.
- LockBit lists the US Federal Reserve on its leak site, claiming 33TB of exfiltrated banking data; the group instead publishes data actually belonging to Evolve Bank & Trust.
- The FBI, with the UK NCA and German authorities, seizes the servers of the Dispossessor operation, which had been wholesale-reposting Cl0p, LockBit, and Hunters International victim lists as its own.
- Hunters International operators launch World Leaks as a parallel, extortion-only (no-encryption) brand on the same infrastructure.
- RansomHub's infrastructure goes dark; its affiliates begin migrating to Qilin and DragonForce.
- Qilin claims a record 72-74 victims for April, the largest monthly total of any group, attributed to absorbing displaced RansomHub affiliates.
- Hunters International formally announces its shutdown, confirming the full transition of operations to the World Leaks data-extortion brand.
- The newly formed 0APT RaaS group posts 91 victims to its leak site within 48 hours of launch.
- 0APT posts a further 458 victims over the following month, bringing its cumulative claimed-victim total to 549.
- Rival group KryBit breaches 0APT's own infrastructure, confirms none of the 549 claimed victims were ever actually breached, and defaces 0APT's leak site.
- Bitdefender publishes its 'Claimed Twice' analysis of 98 leak-site claims across 49 organizations, showing that removing 0APT's 549 fabricated claims alone flips reported Q1 2026 ransomware victim growth from +15% YoY to -6% YoY.
Sources cited for Ransomware Double-Claiming
- Claimed Twice: Five Reasons the Same Ransomware Victim Appears Under Two Flags
- Infighting in the Ransomware Scene: 0APT vs. KryBit Leads to Data Leaks
- Ransomware Turf War as 0APT and KryBit Groups Trade Blows
- 0APT vs. KryBit Ransomware Actors List Opposing Operators as Victims
- Hunters International Rebrands as World Leaks in Shift to Data Extortion
- Hunters International Said Ransomware Now 'Too Risky'
- RansomHub Went Dark April 1; Affiliates Fled to Qilin, DragonForce Claimed Control
- DragonForce: The Ransomware Cartel Guarding Its Burrow
- Change Healthcare and RansomHub Redefine Double Extortion
- Second Ransomware Group Extorting Change Healthcare
- LockBit Holds Its Word, Publishes US Federal Reserve Alleged Data
- LockBit Lied: Stolen Data Is From a Bank, Not US Federal Reserve
- Qilin Ransomware Ranked Highest in April 2025 with 72 Data Leak Disclosures
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
- FBI Disrupts the Dispossessor Ransomware Operation, Seizes Servers
More in ransomware
- Magniber Ransomware: Rewritten 2022 Variant Uses MSI Installer, AES-NI Encryption, and UAC Bypass
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)
Detection coverage for TL-2026-2248
As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2248 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.