The article describes an emerging extortion trend where threat actors use generative AI to fabricate leaked data and fake victim lists on ransomware leak sites, eliminating the need for actual intrusions. Groups like 0APT and ALP-001 have deployed this tactic, creating real pressure on defenders who must now validate whether extortion claims reflect genuine compromises or fabricated datasets. The recommended defense combines data governance (understanding where and how organizational data is stored) with threat intelligence (assessing the reliability and reputation of threat actors making claims).
0APT
1 post
Dealing with AI-Generated Extortion