To check a ransomware attack claim in 2026, compare it against official records. For a public company that means SEC filings. For a healthcare provider it means the HHS breach portal. You can also use the company's own breach notice and government security advisories.
A post on a leak site starts the checking process but proves nothing by itself, because ransomware groups sometimes post old, recycled or fake data to pressure a victim into paying. Ransomware is malicious software that locks or steals an organization's data so criminals can demand payment. Most groups now use "double extortion": they encrypt systems and also threaten to publish stolen files on a dark-web leak site. Those sites are where most public claims first appear, and the number of listings keeps growing.
Table of Contents
- Which Official Records Confirm an Attack?
- How to Read a Company's Own Statement
- What Security Advisories Can and Cannot Tell You
- Red Flags in Leak-Site Claims
- Why a Real Breach May Not Show Up Yet
- Frequently Asked Questions
Which Official Records Confirm an Attack?
For US public companies, the best confirmation is a filing on EDGAR, the SEC's public database. The SEC's cybersecurity disclosure compliance guide explains the rule. Under Item 1.05 of Form 8-K, adopted July 26, 2023, a company must disclose a cybersecurity incident within four business days of deciding it is material. The clock starts when the company decides the incident is material, not when it finds the attack. So a filing can come days or weeks after a claim first appears.
Search EDGAR for the company name and look for an 8-K that cites Item 1.05. For hospitals, clinics and health insurers, go to the HHS breach portal. Under the HHS Breach Notification Rule, a HIPAA-covered organization must report a breach affecting 500 or more people to the Office for Civil Rights within 60 days of finding it. The organization must also notify the affected people and major local media. Those reports then appear on HHS's public, searchable portal.
How to Read a Company's Own Statement
A breach notice sent to affected people is a strong sign that an incident happened. A healthcare provider's letter plus coverage in local media is the confirmation pattern that HIPAA requires for larger breaches. Be careful with statements that stop short of disclosure.
According to the SEC's Form 8-K compliance interpretations, paying a ransom or ending the attack does not excuse a public company from filing. If an incident is material, a "we paid and it's resolved" statement cannot replace the four-business-day disclosure. A flat denial also counts as evidence. When a company rejects a claim and explains why, that response carries weight, especially if the criminals' sample doesn't hold up.
What Security Advisories Can and Cannot Tell You
Joint government advisories describe how a ransomware group works. On August 10, 2026, FBI, CISA, DC3, NSA, the Secret Service and South Korea's National Police Agency published a #StopRansomware advisory on Gunra. It describes Gunra as double-extortion ransomware built from leaked Conti code and rented out to affiliates, the criminals who carry out the attacks. It targets healthcare, financial services, government and nonprofits.
On August 18, 2026, FBI, CISA and HHS updated their Medusa advisory with FBI findings as of April 2026. It reports that Medusa developers and affiliates had hit more than 500 victims across critical-infrastructure sectors. Use advisories to judge whether a claim makes sense. For example, a Gunra claim against a hospital matches that group's documented targets. An advisory confirms the group's methods and scale, though, not whether a particular named victim was really hit.
Red Flags in Leak-Site Claims
Leak-site listings hit a record in Q1 2026, up 22% year over year, according to SecurityBrief UK's report on leak-site growth. More listings mean more claims to check before anyone treats them as confirmed. Palo Alto Networks' Unit 42 research team has seen attackers use old or fake data to pressure victims.
Watch for: Europcar is a clear example. Researchers told Dark Reading about ransomware groups making fake attack claims, and Europcar denied a claimed theft of 48.6 million customer records. The company said the sample posted on a dark-web forum was clearly fake.
- Sample data that matches an earlier, already-reported breach
- Records that could have been scraped from public sources
- Files that look like they came from a misconfigured, publicly exposed server
- A huge record count with a tiny or messy sample
- A flat denial from the company that says the sample is fake
Why a Real Breach May Not Show Up Yet
Official records run on different clocks. A public company's 8-K deadline starts only once it decides an incident is material. A healthcare provider has up to 60 days after finding a large breach to report it to HHS. Small healthcare breaches are slower still.
HHS lets breaches affecting fewer than 500 people be reported up to 60 days after the end of the calendar year. A real small breach found in February may not appear on the portal until the following March. When records are still missing, look for a notice letter, a company statement or state-level coverage. Label the claim as a claim until one of those sources backs it up.
Frequently Asked Questions
Does a private company have to file with the SEC after a ransomware attack?
No. Item 1.05 of Form 8-K applies to public companies, so a private firm's attack won't show up on EDGAR.
Where do I search for a hospital ransomware breach?
Search the HHS Office for Civil Rights breach portal for breaches affecting 500 or more people. Also check the provider's notice letters and local news.
Does a #StopRansomware advisory name a group's victims?
Advisories describe a group's methods, targets and overall scale, like Medusa's 500-plus victims. They do not confirm any single claimed victim.
You Might Also Like
- How to Verify Healthcare Data Breach News Claims in 2026: breach notices and security advisories, Evidence, and Red Flags
- How to Verify Financial Sector Data Breach News Claims in 2026: breach notices and security advisories, Evidence, and Red Flags
- What Is New With Ransomware Attacks in August 2026? Latest breach notices and security advisories and Key Takeaways