Imagine waking up Monday morning to discover you’ve been breached. The attacker has stolen sensitive financial data, set up persistent access, and then greets you with a lovely ransom note at 8:00 a.m. demanding money in exchange for the encryption key. Immediately, you reach out to your security operations team, and they quickly begin assessing the damage and reviewing the breadcrumbs left behind. After triaging, the SOC team concludes that the language and indicators of compromise all point directly to Scattered Spider.
The attacker uses familiar branding, points the victim to a Telegram channel, and acts like a typical criminal group. At first, the answer feels obvious. But …
- What if that entire persona is part of the attack?
- What if the attacker actually works for a foreign government and is using a well-known criminal identity to make a state-backed operation look like ordinary ransomware?
- What if the Telegram channel is fake?
- What if the real group denies involvement?
- And what if the attacker uses Tails, Tor, proxies, hacked infrastructure, and burner accounts to make connecting the dots nearly impossible?
This sounds dramatic, but I assure you, I did not come up with this idea; every piece of it is happening right now. Threat actors pretend to be each other. They dispute attacks claimed in their names, call out fake accounts, and point fingers at nation-states, rivals, insiders, or law enforcement. Some claim they never “hacked” a victim even while holding its data. Others fill the conversation with conflicting stories and make the truth harder to find.
Bitsight Threat Intelligence tracked this behavior across Telegram channels and dark web forums between September 2025 and August 2026. While I cannot definitively confirm the attribution, they point to threat actors becoming increasingly aware of imposters. The online identities investigators rely on are fragmented, disputed, and easy to copy. Threat actors know that, and they are ready to use the confusion to their advantage. Thinking like a threat actor, if I worked for my nation's government and wanted to target an adversary, it would be a lot cleaner to just blame it on a ransomware group in a friendly-to-them country and avoid retaliation.
And that makes things complicated.
Attribution is no longer just a technical investigation
If you’ve worked in cybersecurity for any amount of time, you know that tracing a cyberattack is not straightforward. Very rarely do you find that one smoking gun like in the movies. Security analysts have to build the story using infrastructure, malware samples, targeting patterns, timing, victim profiles, access methods, and intelligence reports.
Threat actors don’t make it easy for us. They ‘sell’ or lease out their infrastructure, malware, and ransomware. Even further complicating things, threat actors don’t work in a clean silo. Ransomware groups sometimes target governments, while state-backed actors steal cryptocurrency.
While browsing the dark web, I saw on several threat actor data leak sites (DLSs) that threat actors were concerned about impersonators and scams (more on that later). But, these threat actor impersonations make the water even murkier. They create doubt that can stall law enforcement, complicate sanctions, change public statements, or determine whether an incident is treated as routine cybercrime or state espionage. It can also send investigators chasing the wrong infrastructure or the wrong country. What happens when a threat actor like Ransomhub claims an attack and then another telegram channel claiming to be the real Ransomhub denies the attack? Who do you believe?
So why does attribution matter to threat actors? Cyber threat actors care about their reputations because trust directly affects whether victims will pay. If victims don’t believe a group is who it claims to be, or that it will return their data, provide a working decryptor, or honor its promises after payment, they have far less reason to pay the ransom.
The usual suspects provide convenient cover
This works in part because conversations about state-backed cyber operations often come back to the same countries. According to the Council on Foreign Relations Cyber Operations Tracker, China, Russia, Iran, and North Korea sponsored 77% of the suspected state-backed operations in its dataset. There's no perfect attribution, so the calculation is far from perfect, but it does give us a view into which nations are usually the first suspects.
Because these countries are already familiar suspects, an attacker has a ready-made story. They can point to China, Russia, Iran, North Korea, or the United States and give investigators a believable narrative to work through.
The reverse is also true. A state-backed operator can use the name of a well-known ransomware group to make a breach look financially motivated. State-backed threat groups generally do not post about their exploits on the dark web or in the news the way other threat groups do. Why would a country admit to a large scale cyber attack on an adversarial nation and risk retribution? But, it would make sense to blame it on a ransomware group and shift all attention away from your country.
How one conversation illustrated the entire problem
On October 6, 2025, telegram channel “SLSH 6.0 part 3 - lapsus$Shiny$scatteredwizard” posted a message aimed at law enforcement and intelligence analysts. It denied involvement in breaches affecting JLR, Salesforce, and Salesloft. The channel claimed foreign government hackers carried out the JLR attack and blamed the Salesforce and Salesloft intrusions on a Chinese APT group.
“We did not hack JLR, foreign nation state actors did.”
While this could look like a one-off or just an instance of a criminal group pushing back against inaccurate reporting, they continued to insist that it was not them. In the very next message, the group complained that Western security researchers refuse to believe major intrusions can come from independent crews. The admins accused analysts of automatically blaming China, Russia, or North Korea, just after blaming foreign governments themselves.
Within an hour, the channel moved to a third explanation: impersonation. It listed @shinycorpp as its only legitimate handle, called every other account fake, and described someone being extorted by an imposter using the ShinyHunters name.
In a matter of minutes, one source:
- Denied several attacks
- Blamed foreign governments
- Criticized analysts for blaming foreign governments
- Claimed authority over the group’s official identity
- Warned that other people were using that identity
- Described an alleged scam carried out by a fake ShinyHunters account
It's hard to know. Some of those claims may have been true. Every one of them could also have been fabricated. The point is how quickly one source filled the conversation with conflicting stories. Anyone investigating the incidents is faced with confirming the validity of the channel, the claims, and the attribution. That is the attribution trap that created more questions than answers, simply by questioning the original attribution.
In a separate post from November 2025, an account using related branding admitted to “gaslighting” researchers and joked that they had never actually hacked anything. Whether the post was sarcasm, trolling, or deliberate misdirection, it underscores that creating confusion can be part of the tactic.