Change Healthcare and Federal Reserve: Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags

Change Healthcare and Federal Reserve: Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags

Ransomware’s Double Trouble: Why Victims Are Being Claimed Twice in 2026

In 2026, a troubling trend has emerged in the ransomware landscape: the same victim organizations are appearing on leak sites under two different ransomware group names. Bitdefender’s analysis of five months of data tracking 98 claims across 49 distinct victims reveals that this phenomenon is not a fluke but a systemic issue with multiple underlying causes.

The Mechanics Behind Duplicate Claims

The median gap between the first and second claim is 12 days, with a mean of 23 days and some cases stretching up to 96 days. Only five cases were posted simultaneously, suggesting that most duplicates stem from staggered rather than coordinated attacks. The patterns vary, but four primary explanations account for the trend:

  1. One Attack, Two Brands
    Some groups operate under multiple names within the same criminal network. For example, the DragonForce cartel absorbed affiliates from defunct operations like RansomHub, leading to the same victim appearing under both Qilin and DragonForce. Similarly, Hunters International rebranded as World Leaks, yet victims were listed under both names. In these cases, the breach is singular, but the leak site postings double-count the incident.

  2. Recycled Data, Second Extortion
    When affiliates don’t receive their cut of a ransom payment, they may relist the stolen data under a new group. The Change Healthcare breach, initially claimed by ALPHV/BlackCat, later resurfaced under RansomHub after an affiliate dispute. This creates two distinct extortion attempts from the same dataset, with the second group operating independently of the first.

  3. Two Real Breaches, Same Victim
    Some organizations are breached twice sometimes through the same vulnerability, other times through a different but equally unpatched weakness. In 16 of the 49 cases analyzed, the gap between claims exceeded 31 days, suggesting separate intrusions. Often, the root cause isn’t a single missed patch but systemic security failures: unchanged credentials, unenforced multi-factor authentication, or undetected network access. Access brokers exacerbate this by reselling stolen credentials to multiple threat actors.

  4. No Breach at All
    Some claims are outright fabrications. Groups like 0APT and Dispossessor have been caught reposting victim lists from other leak sites or inventing attacks entirely. After Operation Cronos disrupted LockBit, the group falsely claimed the Federal Reserve as a victim, later revealed to be data from Evolve Bank. These fake claims waste resources, as organizations may respond to a non-existent breach.

The Impact on Statistics and Response

The prevalence of duplicate and fabricated claims distorts ransomware statistics. For instance, Q1 2026’s raw leak site data showed a 15% increase in victims year-over-year. However, removing 0APT’s 549 fake claims reversed the trend, revealing a 6% decline. This noise complicates threat assessments and incident response.

For victims, distinguishing between these scenarios is critical:

  • Same breach, two groups? Treat it as one negotiation.
  • Recycled data? Paying the second group doesn’t silence the first.
  • Two real breaches? The issue isn’t just the breach it’s the security posture that allowed it.
  • No breach at all? Verification is key before taking action.

The rise of duplicate claims underscores the need for defenders to look beyond surface-level leak site postings. Context timing, group relationships, and data authenticity determines the appropriate response. Without it, organizations risk misallocating resources, overpaying ransoms, or failing to address the real vulnerabilities that led to repeat victimization.

Source: https://www.bitdefender.com/en-gb/blog/businessinsights/claimed-twice-five-reasons-same-ransomware-victim-appears-under-two-flags

Change Healthcare cybersecurity rating report: https://www.rankiteo.com/company/change-healthcare

Federal Maritime Commission cybersecurity rating report: https://www.rankiteo.com/company/federal-maritime-commission

"id": "CHAFED1781757064",
"linkid": "change-healthcare, federal-maritime-commission",
"type": "Ransomware",
"date": "1/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organization'}],
 'data_breach': {'data_encryption': True,
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Stolen credentials',
                                              'Sensitive data',
                                              'Personally identifiable '
                                              'information']},
 'date_publicly_disclosed': '2026',
 'description': 'In 2026, a troubling trend has emerged where the same victim '
                'organizations are appearing on ransomware leak sites under '
                'two different group names. Bitdefender’s analysis of five '
                'months of data tracking 98 claims across 49 distinct victims '
                'reveals systemic causes for this phenomenon, including '
                'rebranding, affiliate disputes, separate breaches, and '
                'fabricated claims.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'identity_theft_risk': True},
 'initial_access_broker': {'data_sold_on_dark_web': True},
 'lessons_learned': 'The rise of duplicate claims underscores the need for '
                    'defenders to look beyond surface-level leak site '
                    'postings. Context—timing, group relationships, and data '
                    'authenticity—determines the appropriate response. '
                    'Organizations must verify claims before taking action to '
                    'avoid misallocating resources or overpaying ransoms.',
 'motivation': ['Financial gain',
                'Extortion',
                'Data resale',
                'Affiliate disputes'],
 'post_incident_analysis': {'corrective_actions': ['Improve verification of '
                                                   'ransomware claims',
                                                   'Enforce multi-factor '
                                                   'authentication and '
                                                   'credential rotation',
                                                   'Patch vulnerabilities '
                                                   'promptly',
                                                   'Monitor for threat actor '
                                                   'rebranding and '
                                                   'relationships'],
                            'root_causes': ['Rebranding of ransomware groups',
                                            'Affiliate disputes leading to '
                                            'relisting of stolen data',
                                            'Separate breaches due to systemic '
                                            'security failures',
                                            'Fabricated claims by threat '
                                            'actors']},
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransomware_strain': ['Qilin',
                                      'DragonForce',
                                      'Hunters International',
                                      'World Leaks',
                                      'ALPHV/BlackCat',
                                      'RansomHub',
                                      'LockBit']},
 'recommendations': ['Verify the authenticity of ransomware claims before '
                     'responding.',
                     'Treat duplicate claims from the same breach as a single '
                     'negotiation.',
                     'Address systemic security failures (e.g., unpatched '
                     'vulnerabilities, unchanged credentials, lack of MFA) to '
                     'prevent repeat breaches.',
                     'Monitor threat actor relationships and rebranding to '
                     'contextualize claims.'],
 'references': [{'source': 'Bitdefender'}],
 'threat_actor': ['DragonForce',
                  'Qilin',
                  'Hunters International',
                  'World Leaks',
                  'ALPHV/BlackCat',
                  'RansomHub',
                  '0APT',
                  'Dispossessor',
                  'LockBit'],
 'title': 'Ransomware’s Double Trouble: Duplicate Victim Claims in 2026',
 'type': 'Ransomware',
 'vulnerability_exploited': ['Unpatched vulnerabilities',
                             'Unchanged credentials',
                             'Lack of multi-factor authentication',
                             'Undetected network access']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.