Abstract header image of a person holding an umbrella beside a red flourish

Dealing with AI-Generated Extortion

Proving a Negative

How do you prove a negative in cybersecurity? How do you prove that you weren’t attacked, or that there is no intruder in your network? These are questions that security teams have been forced to ask for a while, but there is a new question that is becoming increasingly common: How do you prove that files weren’t stolen from your network? Or, even more of a challenge, how do you prove that files weren’t stolen from your partners, vendors, or their partners or vendors?

This is a surprisingly challenging question to answer. Finding the answer is also more difficult because data governance has not been the traditional purview of security teams. Data governance has long been thought of as a compliance problem, unfortunately that is no longer the case. Security teams are now, whether they want to be or not, need to consider data governance. This means they have to be able to confidently say whether leaked data is real or not.

How do you do that?

History of Ransomware

What we call ransomware has evolved over the years. Ransomware has gone from largely focused on encryption to a combination of encryption and data theft to today’s reality where data theft alone is the most common version of a “ransomware” attack.

Threat actors have figured out that managing encryption keys is challenging, stealing data and holding it hostage is significantly easier. They’ve also figured out that stealing the right data can be just as profitable as encryption and, as we’ve seen from ransomware trends, switching to data theft only allows groups to accelerate the number of attacks. Compare the number of victims from 2024 to 2025 in the Recorded Future® Ransomware dashboard with a noticeable rise in ransomware trends.

alt=""

Line graph of ransomware trends

Figure 1: Rise in ransomware trends increasing from 2024 to 2025 (Source: Recorded Future)

Enter 0APT

If data theft is easier than encryption, then just making up data using generative AI is even easier than that. Which is what we saw with “0APT” (their name, not a designation that Recorded Future provided), who created a list of victims that were completely made up, including fake leaked data. From Insikt Group® reporting at the time:

In late January 2026, Insikt Group reported the launch of 0APT Blog, an extortion blog operated by 0APT Ransomware Group, which allegedly runs an affiliate program via its ransomware-as-a-service (RaaS) model. As of February 5, 2026, the extortion blog listed 61 breached victims, with operators stating they planned to leak an additional 115 victims located in multiple countries and operating across various sectors and industries. Insikt Group identified multiple reports regarding the functionality of

0APT ransomware and listed victims, indicating that the ransomware is fake and that all their victims listed on the blog were AI-generated. Among the primary reasons discussed include:

0APT is not alone; other groups are starting to latch on to this trend (ransomware groups are really good at copying each other). ALP-001 is another threat group that surfaced in March with questionable data that may have been AI-generated. According to Reliaquest reporting at the time:

The main significance of 0APT and ALP-001 is not that they’re established top-tier threats, but that even fraudulent or low-credibility leak sites can create real pressure for defenders. When an organization is named, the immediate problem isn’t attribution but rather deciding whether the claim reflects a real intrusion, a recycled dataset, or a fabricated leak. That extra validation adds time, cost, and executive pressure to an already compressed decision window.

Data Governance + Intelligence

So, how do organizations fight back against AI-generated “leaked documents?” In other words, how do you prove a negative? The answer really comes in two parts: Data Governance and Intelligence.

Security needs to be more involved in the data governance process. It’s not just a matter of knowing where and how data is stored; organizations also need to understand the format of how the data is stored and how it is secured. This type of data governance requires more than just surveys; it requires a deeper understanding of business relationships. It also means working closely with the compliance team and all departments because every department in your organization has data that resides in the cloud; knowing those relationships is critical to the success of this process.

In addition to understanding your data footprint, having intelligence on the threat actors and your suppliers is important. By tracking breaches to your partners and vendors your organization can be better prepared for potential data leak reporting. Remember, a threat actor doesn’t care where the leaked data comes from, if they think your organization is a high-profile target, then you will most likely find your organization listed on the data leak site.

But, you also have to understand the reputation of the threat actor. That sounds like an oxymoron – all threat actors are inherently untrustworthy – but there is a sliding scale even for threat actors. Understanding the veracity of threat actor claims is as important as knowing where and how your data is stored. Which is why the Diamond Model for threat intelligence can be so important. It affords your team an up-to-date look at the reliability of a threat actor and allows you to make a more informed assessment about their claims. For example, this is the Diamond Model for 0APT:

A structural diagram illustrating the Diamond Model for the 0APT threat group, mapping the relationships between the adversary, their capabilities, infrastructure, and the victim to assess the credibility and operational tactics of the threat actor
Figure 2: Diamond Model for 0APT in the Recorded Future portal (Source: Recorded Future)

Conclusion

While they are still isolated cases, more so-called ransomware groups are relying on AI-generated data to create fake data leak sites and using that fake data to try to extort organizations. The way to “prove a negative,” to show that the data isn’t real is through a combination of reliable data governance and external threat intelligence.

Learn how to stay ahead of threat actors using AI-generated extortion tactics. Speak to our threat intelligence experts today.