Why “proof of hack” is usually a screenshot
Extortion groups post dashboards as evidence. Your own screenshots can become that evidence if you share them raw.

“We have your files” lands harder with a picture of the files. Leak sites and negotiation blogs are full of admin UI, not poetry.
If you work in IT, your own screenshots of those same panels are practice for the adversary’s proof pack: hostnames, user counts, backup products. Share internally with bars. Share externally almost never.
In May 2026, BleepingComputer reported that RansomHouse claimed a Trellix source-code breach and offered leak-site screenshots as proof of access. That coverage is the citation for “screenshots as evidence,” not a claim that a named defender paid because they forgot to blur a table.
What should you cover on a “we got owned?” snip?
- Customer names in the table
- Internal URLs
- SSO tiles
- Anything that proves which plant or which hospital
- License and seat counts that identify the tenant
- Backup product plus a hostname in the same frame
You can still show a panel exists. You can describe impact in text. You do not need live customer rows in the PNG that will be forwarded to a lawyer, a journalist, or a vendor.
Why do extortion groups post pictures instead of a full dump?
Speed and readability. A dump is work. A screenshot of an admin console is a shape a reader understands. The Trellix/RansomHouse reporting is one instance of that pattern: claimed access, images as proof. Other crews do the same genre. This post is not a catalog of crews. It is a warning about the format.
Why they post them: Why they post them. Keys in chrome: API keys.
Should IT paste the same panels into Slack during IR?
Only after bars, and only in the channel that needs them. Incident Slack is still Slack. It is forwarded, screenshotted again, dropped into email, dropped into a ticket. Treat every IR snip as if it will leave the company. Bar URLs. Bar names. Crop the desktop. Wait out notifications. Export PNG. Keep the original off the thread.
“We will redact in the press deck later” is how the unredacted file becomes the file that leaks. Redact before the first paste.
Is a blur over a customer column enough for IR?
Customer names and account numbers are short secrets. A polite smear is the wrong tool. Use a fill. This is not a PETS recreation in the SOC. It is the same operational rule: leftover structure is leftover data. If you would not put the column in the status page, do not put it in the PNG.
What is not in this article?
A named victim whose only mistake was blur. A claim that Trellix staff posted the leak-site images. A tutorial for running a leak site. The documented hook is narrower: crews already use screenshots as proof, and defender screenshots of the same class of UI should be barred before they travel.
How do you brief counsel without handing them a proof pack?
Written timeline. Counts. Systems named in the vocabulary they already use. If an image is required, one cropped panel with customer columns filled, URLs filled, and SSO tiles filled. Counsel forwards. Forwarded PNGs become exhibits. Exhibits get copied. Start from the barred export.
Status pages and public statements are not the place for a thumbnail of the admin UI “for authenticity.” Authenticity is the statement. The thumbnail is hostnames and rows. The BleepingComputer Trellix/RansomHouse report is what crews do with pictures. Do not donate a cleaner copy from the inside.
Vendor Zoom calls collect the same panels in a shared desktop. Stop sharing, bar, then share a window that is already clean. A live share is a screenshot that keeps updating. Treat the share the same as a PNG you would attach: no customer column, no live URL, no SSO tile with the org name.
Bar the war-room snip before it is the attachment everyone forwards. Assume counsel, vendors, and a second channel will see the PNG: redact before you paste into Slack.
