The payment described at 24-0301 went to the operator of the ALPHV franchise. Reporting since holds that the operator kept it, did not pay the affiliate who had actually carried out the intrusion, and closed the operation — an exit scam against its own contractor.
The affiliate still had the four terabytes. In April 2024 the same data was used to extort Change Healthcare a second time, under the RansomHub name.
This Is The Clearest Case In The Corpus Of What A Ransom Does Not Buy
The desk has written repeatedly that an undertaking not to publish has no enforcement mechanism. That is usually an argument from structure: there is no contract, no jurisdiction and no recourse.
Here it is not an argument. The undertaking was given by a party that did not hold the data, to a victim that had no way to know, and it failed within weeks in the most direct way available.
The Franchise Structure Is The Reason
A ransomware-as-a-service operation splits the work: the operator supplies the encryptor, the leak site and the brand, the affiliate supplies the intrusion, and the two split the proceeds. The corpus set that out at 25-0525 from a leaked affiliate panel.
A victim negotiating with the brand is negotiating with the party that holds the least. The stolen files sit with the affiliate, on the affiliate’s infrastructure, and nothing about paying the operator changes that.
What A Defender Can Take From It
Not that paying is wrong — the corpus does not make that argument, and the decision at 24-0301 was made under conditions almost no reader will face. What follows is narrower and harder to dispute: a suppression payment should be modelled as buying nothing, because in the one fully documented case it bought nothing.
Restoration is different. A decryptor either works or it does not, and that can be tested on the day.
Graded medium. That the second extortion happened is well established; the account of the operator withholding the affiliate’s share comes from criminal-forum activity and researcher reporting, and no party to it has confirmed anything.
Compiled from contemporaneous reporting, listed below. The second extortion attempt is established by the leak-site posting and subsequent coverage. The exit-scam account — that the operator retained the affiliate’s share and closed the operation — rests on criminal-forum posts read by researchers, is not confirmed by any party, and is recorded here as a reported account rather than a fact. Graded medium for that reason. Corrections: corrections@forensicpost.com.