The Attribution Trap: What Happens When Threat Actors Manipulate the Story of an Attack?

cyber threat actor attribution blog
emma-stevens-bio-portrait
Written by Emma Stevens
Senior Threat Intelligence Advisor

Imagine waking up Monday morning to discover you’ve been breached. The attacker has stolen sensitive financial data, set up persistent access, and then greets you with a lovely ransom note at 8:00 a.m. demanding money in exchange for the encryption key. Immediately, you reach out to your security operations team, and they quickly begin assessing the damage and reviewing the breadcrumbs left behind. After triaging, the SOC team concludes that the language and indicators of compromise all point directly to Scattered Spider.

The attacker uses familiar branding, points the victim to a Telegram channel, and acts like a typical criminal group. At first, the answer feels obvious. But … 

  • What if that entire persona is part of the attack?
  • What if the attacker actually works for a foreign government and is using a well-known criminal identity to make a state-backed operation look like ordinary ransomware?
  • What if the Telegram channel is fake?
  • What if the real group denies involvement?
  • And what if the attacker uses Tails, Tor, proxies, hacked infrastructure, and burner accounts to make connecting the dots nearly impossible?

This sounds dramatic, but I assure you, I did not come up with this idea; every piece of it is happening right now. Threat actors pretend to be each other. They dispute attacks claimed in their names, call out fake accounts, and point fingers at nation-states, rivals, insiders, or law enforcement. Some claim they never “hacked” a victim even while holding its data. Others fill the conversation with conflicting stories and make the truth harder to find.

Bitsight Threat Intelligence tracked this behavior across Telegram channels and dark web forums between September 2025 and August 2026. While I cannot definitively confirm the attribution, they point to threat actors becoming increasingly aware of imposters. The online identities investigators rely on are fragmented, disputed, and easy to copy. Threat actors know that, and they are ready to use the confusion to their advantage. Thinking like a threat actor, if I worked for my nation's government and wanted to target an adversary, it would be a lot cleaner to just blame it on a ransomware group in a friendly-to-them country and avoid retaliation.

And that makes things complicated.

Attribution is no longer just a technical investigation

If you’ve worked in cybersecurity for any amount of time, you know that tracing a cyberattack is not straightforward. Very rarely do you find that one smoking gun like in the movies. Security analysts have to build the story using infrastructure, malware samples, targeting patterns, timing, victim profiles, access methods, and intelligence reports.

Threat actors don’t make it easy for us. They ‘sell’ or lease out their infrastructure, malware, and ransomware. Even further complicating things, threat actors don’t work in a clean silo. Ransomware groups sometimes target governments, while state-backed actors steal cryptocurrency.

While browsing the dark web, I saw on several threat actor data leak sites (DLSs) that threat actors were concerned about impersonators and scams (more on that later). But, these threat actor impersonations make the water even murkier. They create doubt that can stall law enforcement, complicate sanctions, change public statements, or determine whether an incident is treated as routine cybercrime or state espionage. It can also send investigators chasing the wrong infrastructure or the wrong country. What happens when a threat actor like Ransomhub claims an attack and then another telegram channel claiming to be the real Ransomhub denies the attack? Who do you believe?

Figure 1. A dark web post warns that fake ShinyHunters and BreachForums personas were operating across Telegram and cloned forums
Figure 1. A dark web post warns that fake ShinyHunters and BreachForums personas were operating across Telegram and cloned forums. 

So why does attribution matter to threat actors? Cyber threat actors care about their reputations because trust directly affects whether victims will pay. If victims don’t believe a group is who it claims to be, or that it will return their data, provide a working decryptor, or honor its promises after payment, they have far less reason to pay the ransom.

The usual suspects provide convenient cover

This works in part because conversations about state-backed cyber operations often come back to the same countries. According to the Council on Foreign Relations Cyber Operations Tracker, China, Russia, Iran, and North Korea sponsored 77% of the suspected state-backed operations in its dataset. There's no perfect attribution, so the calculation is far from perfect, but it does give us a view into which nations are usually the first suspects.

Because these countries are already familiar suspects, an attacker has a ready-made story. They can point to China, Russia, Iran, North Korea, or the United States and give investigators a believable narrative to work through.

The reverse is also true. A state-backed operator can use the name of a well-known ransomware group to make a breach look financially motivated. State-backed threat groups generally do not post about their exploits on the dark web or in the news the way other threat groups do. Why would a country admit to a large scale cyber attack on an adversarial nation and risk retribution? But, it would make sense to blame it on a ransomware group and shift all attention away from your country.

How one conversation illustrated the entire problem

On October 6, 2025, telegram channel “SLSH 6.0 part 3 - lapsus$Shiny$scatteredwizard” posted a message aimed at law enforcement and intelligence analysts. It denied involvement in breaches affecting JLR, Salesforce, and Salesloft. The channel claimed foreign government hackers carried out the JLR attack and blamed the Salesforce and Salesloft intrusions on a Chinese APT group.

Figure 2. A Telegram channel using SLSH branding denied involvement in the JLR, Salesforce, and Salesloft intrusions, blamed foreign actors, and identified one handle as its only legitimate account copy
Figure 2. From Bitsight Threat Intelligence: A Telegram channel using SLSH branding denied involvement in the JLR, Salesforce, and Salesloft intrusions, blamed foreign actors, and identified one handle as its only legitimate account. 

“We did not hack JLR, foreign nation state actors did.”

While this could look like a one-off or just an instance of a criminal group pushing back against inaccurate reporting, they continued to insist that it was not them. In the very next message, the group complained that Western security researchers refuse to believe major intrusions can come from independent crews. The admins accused analysts of automatically blaming China, Russia, or North Korea, just after blaming foreign governments themselves.

Within an hour, the channel moved to a third explanation: impersonation. It listed @shinycorpp as its only legitimate handle, called every other account fake, and described someone being extorted by an imposter using the ShinyHunters name.

In a matter of minutes, one source:

  • Denied several attacks
  • Blamed foreign governments
  • Criticized analysts for blaming foreign governments
  • Claimed authority over the group’s official identity
  • Warned that other people were using that identity
  • Described an alleged scam carried out by a fake ShinyHunters account

It's hard to know. Some of those claims may have been true. Every one of them could also have been fabricated. The point is how quickly one source filled the conversation with conflicting stories. Anyone investigating the incidents is faced with confirming the validity of the channel, the claims, and the attribution. That is the attribution trap that created more questions than answers, simply by questioning the original attribution. 

In a separate post from November 2025, an account using related branding admitted to “gaslighting” researchers and joked that they had never actually hacked anything. Whether the post was sarcasm, trolling, or deliberate misdirection, it underscores that creating confusion can be part of the tactic.

Threat actor branding becomes a cluster of competing identities

Bitsight found similar identity conflicts across other channels using ShinyHunters and Scattered LAPSUS$ Hunters branding. On September 16, 2025, one channel denied targeting SK Telecom. It called a viral screenshot fake and directed followers to @shinyc0rp as the real account. The poster added that the real group would never claim a major victim without showing proof.

Figure 3. Channels using Scattered LAPSUS$ Hunters branding denied the SK Telecom, Vercel, and Anthropic Mythos compromises while warning about impersonators
Figure 3. From Bitsight Threat Intelligence: Channels using Scattered LAPSUS$ Hunters branding denied the SK Telecom, Vercel, and Anthropic Mythos compromises while warning about impersonators. 

By April 2026, a different channel claimed ShinyHunters had left Telegram completely. It called every Telegram channel using the name fraudulent, denied breaches at Vercel and Anthropic, and blamed Indonesian actors for hijacking the brand. That channel directed readers to specific clearnet and onion sites instead. This created a mess of names, finger pointing, and attribution confusion. If you don’t know who is targeting you, how do you defend against them? What security controls do you put into place? 

An attacker simply using the same voice, tone, or breadcrumbs as a threat group can be enough to get news outlets and analysts repeating the story. This also creates issues for threat groups. If a group is impersonating them, ransoms a company, and does not return the data, this creates mistrust from the victims of the actual threat group. How do you know if you pay the ransom that you will get your data back? This also creates legal issues, can this group face charges related to an attack that they did not perpetrate. 

CARDINAL showed how to deny an attack without denying access

Another example involved a Telegram channel titled “We are CARDINAL.” On March 20, 2026, the channel referenced what they described as a leaked classified report and posted what sounded like a denial: “We didn't hack it. We didn't leak it. You left it where we could find it.”

Figure 4.  A post attributed to CARDINAL and forwarded through a Russian Legion channel denied “hacking” or “leaking” while claiming persistent access and operational impact.
Figure 4. From Bitsight Threat Intelligence: A post attributed to CARDINAL and forwarded through a Russian Legion channel denied “hacking” or “leaking” while claiming persistent access and operational impact.

In the same message, the channel claimed access to systems tied to Ramstein Air Base, nuclear command, B-52 deployments, and backup networks. It also claimed responsibility for delaying a military cargo flight. Bitsight did not independently verify those claims. The message was reposted on March 22 and later shared by a Russian Legion channel.

In this case, semantics mattered greatly. CARDINAL rejected the words “hacking” and “leaking,” but they did not deny accessing the files or disrupting operations. Instead, they blamed poor security for leaving the information exposed. The actor narrowed the accusation until it could deny the label without giving up the boast. For defenders, that is why denials cannot be treated as simple true-or-false statements. Analysts have to look at what is actually being denied.

  • “We did not hack the victim” does not mean “we never entered the network.”
  • “We did not deploy ransomware” does not mean “we had no role in the breach.”
  • “We did not leak the files” does not mean “we did not steal them.”
  • Those gaps give attackers plenty of room to shape the story.

Impersonation is widespread across cybercrime forums

On August 22, 2026, a Cracked forum member named Novusy warned that a Telegram account, @BloodRainn12, was impersonating them to scam users. Novusy said @Novusy and their forum profile were their only legitimate accounts. They also shared screenshots from a buyer who had been approached by someone using the Novusy name to close deals. Bitsight also saw Wolfstreet.Cash warn customers about fake accounts posing as the service. Russian-language actors including Cat_Bit and Santa Muerte posted similar warnings about fraudsters taking payments under their names.

Figure 5. Wolfstreet.Cash warns users that fake accounts are posing as the service and tells customers to verify contact information through official channels
Figure 5. From Bitsight Threat Intelligence: Wolfstreet.Cash warns users that fake accounts are posing as the service and tells customers to verify contact information through official channels.

Bitsight also saw Wolfstreet.Cash warn customers about fake accounts posing as the service. Accounts posting in Russian, including Cat_Bit and Santa Muerte, posted similar warnings about fraudsters taking payments under their names.

Figure 6.  Novusy warned that impersonators were using its name across Telegram and cybercrime forums, while a prospective buyer sought verification before making contact
Figure 6. From Bitsight Threat Intelligence: Novusy warned that impersonators were using its name across Telegram and cybercrime forums, while a prospective buyer sought verification before making contact. 

These examples involved scams, not complex ransomware and encryption attacks, however, they demonstrate how easy it is to copy an online reputation. Personas can be spun up in a matter of seconds. If a fraudster can use a stolen name to trick buyers, then another actor can use that same name to claim a breach, send a ransom note, or create a false story around an intrusion. The bar is low. A matching username, copied graphics, familiar slang, and access to a popular chat app may be enough.

Privacy tools do not guarantee anonymity, but they make the story harder to untangle

Privacy-focused operating systems such as Tails are designed to leave minimal traces on the device they run from and route internet traffic through Tor by default. Attackers can combine tools like these with VPNs, residential proxies, leased servers, compromised infrastructure, disposable accounts, and stolen credentials to hide where they are operating from. This isn’t foolproof. Attackers can still make mistakes (human and non-human) and their tools or infrastructure can fail them. Attribution is about building confidence from many imperfect clues. If an attacker can erase or distort several of those signals, then the few that remain can carry more weight than they should.

Imagine a North Korean operator launching an attack through Tor and compromised infrastructure while using Scattered Spider branding. The attacker writes ransom notes in casual English, copies familiar language, and sends the victim to a newly created Telegram channel that looks real. Using Tails can’t prove North Korea carried out the attack AND Scattered Spider branding doesn’t necessarily prove Scattered Spider carried it out either.

The power comes from combining these techniques. When technical evidence is limited, familiar criminal branding can fill the gap with an easy explanation. The attacker does not have to prove they are Scattered Spider; they only need that story to compete with the state-backed theory. This creates enough uncertainty to buy time, reduce immediate political pressure, and cause a victim to treat the breach as ordinary extortion instead of a possible state-backed operation.

State-linked operations can hide behind criminal tactics

A 2024 joint advisory from the FBI, CISA, and the Department of Defense Cyber Crime Center described Iranian state-sponsored actors working directly with ransomware affiliates. According to the advisory, the actors gained access to victim networks and then worked with ransomware affiliates to encrypt their data and extort victims, while hiding their Iran-based identity and remaining vague about their nationality. The advisory also discussed Pay2Key, a 2020 hack-and-leak campaign that used tactics commonly associated with ransomware. However, the FBI explicitly assessed the Pay2Key as separate from the ransomware-enabling activity. The FBI assessed that the goal was aimed at undermining confidence in Israel-based cyber-infrastructure.

While looking at various threat actor pages, we came across a warning from Akira, a well-known ransomware group.

Figure 7. Akira’s data leak site warns that impersonators copied its brand and directs victims to what it claims is its only legitimate chat-room link.
Figure 7. Akira’s data leak site warns that impersonators copied its brand and directs victims to what it claims is its only legitimate chat-room link.

The warning discussed impersonators, and this also makes it harder to trust a lot of the surface clues. A ransom note doesn’t prove they want money just as a DLS doesn’t prove a criminal group was behind the breach. Government operators can work with criminal affiliates, use commercial tools, or borrow extortion tactics to hide their real objective. This makes forensics even more difficult. 

Why this matters

Attribution changes how an organization responds. When an attack looks like everyday extortion, the response may focus on isolation, recovery, ransom negotiations, and leak management. On the other hand, if that breach is assessed to be possible state-backed espionage, the focus changes. The organization may need to hunt for long-term backdoors, assess what intelligence was lost, review partner connections, and prepare for later disruption.

Those are very different incident response playbooks. A state-backed APT hiding behind Scattered Spider’s branding can mislead a victim into treating an intrusion like a financial and data issue while missing the deeper access the attacker may have kept. On the other side, a ransomware actor who blames a nation-state can make the attack look more sophisticated, intimidate the victim, and distract investigators from a straightforward extortion scheme.

Bad attribution can also spread to third parties. If an attacker gets in through a cloud provider, MSP, or software vendor, the label attached to the actor can shape which partners are warned and which indicators they search for. At the geopolitical level, official attribution can lead to sanctions, indictments, diplomatic action, or even military responses. An attacker does not need to stop every one of those actions — creating enough doubt to slow the decision may be enough. The main takeaway is that threat actor communications should be treated as part of the attack strategy. Every message may be written to shape what defenders believe.

The main takeaway is that threat actor communications should be treated as part of the attack strategy. Every message may be written to shape what defenders believe.

What defenders should do

  1. Separate what you observed from what you confirmed. It is accurate to write, “A Telegram channel using ShinyHunters branding denied involvement.” It is a much bigger leap to write, “ShinyHunters did not launch the attack.” The first documents what happened, while the second accepts an unverified claim as fact.
  2. Capture the full conversation, not just one quote. Contradictions often appear in the next post. Archive timestamps, edit histories, forwarded messages, user IDs, linked domains, onion URLs, wallet addresses, and the surrounding thread.
  3. Trace each claim back to its original source. A message from a long-established channel should not be treated the same as a screenshot shared by an aggregator or a brand-new account.
  4. Track how key actor identities change over time. Record handle changes, channel moves, quiet periods, official announcements, infrastructure links, and previous impersonation warnings.
  5. Anchor the investigation in technical evidence that is harder to fake. Long-term infrastructure links, malware code overlap, access methods, victim patterns, blockchain activity, internal telemetry, and verified control of established channels should carry more weight than a familiar avatar or writing style.

Actor communications can provide useful context. Defenders just need to remember that those messages may be part of the attack, too. Follow the trust but verify mindset. 

Conclusion

Through our research, we found threat actors fighting over established handles, creating fake profiles, denying attacks, shifting blame, and arguing over what counts as a hack. Some openly joke about misleading researchers. Others deny a breach while still boasting about access. We also saw that for state-backed operators ransomware relationships, criminal tactics, and extortion infrastructure can support goals that have little to do with making money. Throw in Tor, privacy-focused operating systems like Tails, proxies, compromised infrastructure, and burner accounts, and the story becomes even harder to untangle. Attribution itself has become a target.

Bitsight cta background color
2026 gartner magic quadrant cover

Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies

Get the report and see why Bitsight was named a Visionary.

 

Download

Bitsight cta background color