Dealing with AI-Generated Extortion
Proving a Negative
How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?
This is a surprisingly challenging question to answer. Finding the answer is also more difficult because data governance has not been the traditional purview of security teams. Data governance has long been thought of as a compliance problem, unfortunately that is no longer the case. Security teams are now, whether they want to be or not, need to consider data governance. This means they have to be able to confidently say whether leaked data is real or not.
How do you do that?
History of Ransomware
What we call ransomware has evolved over the years. Ransomware has gone from largely focused on encryption to a combination of encryption and data theft to today’s reality where data theft alone is the most common version of a “ransomware” attack.
Threat actors have figured out that managing encryption keys is challenging, stealing data and holding it hostage is significantly easier. They’ve also figured out that stealing the right data can be just as profitable as encryption and, as we’ve seen from ransomware trends, switching to data theft only allows groups to accelerate the number of attacks. Compare the number of victims from 2024 to 2025 in the Recorded Future® Ransomware dashboard with a noticeable rise in ransomware trends.
Enter 0APT
If data theft is easier than encryption, then just making up data using generative AI is even easier than that. Which is what we saw with “0APT” (their name, not a designation that Recorded Future provided), who created a list of victims that were completely made up, including fake leaked data. From Insikt Group® reporting at the time:
In late January 2026, Insikt Group reported the launch of 0APT Blog, an extortion blog operated by 0APT Ransomware Group, which allegedly runs an affiliate program via its ransomware-as-a-service (RaaS) model. As of February 5, 2026, the extortion blog listed 61 breached victims, with operators stating they planned to leak an additional 115 victims located in multiple countries and operating across various sectors and industries. Insikt Group identified multiple reports regarding the functionality of
0APT ransomware and listed victims, indicating that the ransomware is fake and that all their victims listed on the blog were AI-generated. Among the primary reasons discussed include:
- Multiple uploaded files were empty.
- Low-programming practices, including a combination of AI-generated scripts and unprofessional web development.
- Source code analysis found that some comments were in Hindi and Urdu, which likely indicates that the operators of 0APT ransomware are based in Southern Asia, while the majority of top-tier ransomware groups primarily operate from Russia or a nation within the Commonwealth of Independent States (CIS).
- Such a large number of victims compromised within a very short period can be carried out by a well-established, organized ransomware group; however, 0APT Blog states that the threat group is currently recruiting penetration testers with network access to join their RaaS affiliate program.
0APT is not alone; other groups are starting to latch on to this trend (ransomware groups are really good at copying each other). ALP-001 is another threat group that surfaced in March with questionable data that may have been AI-generated. According to Reliaquest reporting at the time:
Data Governance + Intelligence
So, how do organizations fight back against AI-generated “leaked documents?” In other words, how do you prove a negative? The answer really comes in two parts: Data Governance and Intelligence.
Security needs to be more involved in the data governance process. It’s not just a matter of knowing where and how data is stored; organizations also need to understand the format of how the data is stored and how it is secured. This type of data governance requires more than just surveys; it requires a deeper understanding of business relationships. It also means working closely with the compliance team and all departments because every department in your organization has data that resides in the cloud; knowing those relationships is critical to the success of this process.
In addition to understanding your data footprint, having intelligence on the threat actors and your suppliers is important. By tracking breaches to your partners and vendors your organization can be better prepared for potential data leak reporting. Remember, a threat actor doesn’t care where the leaked data comes from, if they think your organization is a high-profile target, then you will most likely find your organization listed on the data leak site.
But, you also have to understand the reputation of the threat actor. That sounds like an oxymoron – all threat actors are inherently untrustworthy – but there is a sliding scale even for threat actors. Understanding the veracity of threat actor claims is as important as knowing where and how your data is stored. Which is why the Diamond Model for threat intelligence can be so important. It affords your team an up-to-date look at the reliability of a threat actor and allows you to make a more informed assessment about their claims. For example, this is the Diamond Model for 0APT:
Conclusion
While they are still isolated cases, more so-called ransomware groups are relying on AI-generated data to create fake data leak sites and using that fake data to try to extort organizations. The way to “prove a negative,” to show that the data isn’t real is through a combination of reliable data governance and external threat intelligence.
Learn how to stay ahead of threat actors using AI-generated extortion tactics. Speak to our threat intelligence experts today.