BlurThis

Home/Blog/

Why extortion groups post screenshots of your admin panel

Ransom notes often include a picture of a dashboard. That is why you should cover yours before you share internally too.

Green code filling a computer screen
Photo from Unsplash

Extortion crews do not always dump a database on day one. They post pictures: an admin panel, a file tree, a mailbox. The screenshot is the proof that they were inside.

Coverage of groups such as RansomHouse has made that pattern obvious — dashboards and repos as evidence, not as decoration. In May 2026, BleepingComputer reported that RansomHouse claimed a Trellix source code intrusion and posted screenshots as proof of access. This article is not a claim that a named person paid ransom because they forgot to blur. It is the narrower point: screenshots are already the leak channel those groups use. Do not add yours, unbarred, to a public ticket or a Slack that forwards to a vendor.

Why is a screenshot useful as “proof” at all?

Because it is fast to read. A dump takes time to verify. A picture of an internal admin UI, a source tree, or a mailbox is a shape civilians and journalists recognize. Leak sites and negotiation posts use that shape. You should recognize it too when you attach the same shape from the defender’s side: hostnames, user counts, backup products, customer rows.

The BleepingComputer Trellix/RansomHouse write-up is one public example of claimed access backed by images. It is not a walkthrough of their tooling. It is a reminder that the format of the proof is a PNG of someone else’s screen.

Is internal sharing still sharing?

A “quick snip” of production with customer rows visible becomes attachment number four in an email thread that leaves the company. Bar the rows. Bar the URL. Assume the PNG will be forwarded. Incident channels spawn vendor threads. Vendor threads spawn tickets. Tickets spawn PDFs. Your unbarred admin panel does not stay in the war room.

Related: proof-of-hack shots. Hygiene for tokens in chrome: URL bar.

What should defenders cover before they paste a panel?

Customer names. Internal hostnames. SSO tiles that name the org. License counts. Backup product logos next to a server name that identifies a plant or a hospital. Query strings. Session cookies. Anything that would help a second group pick a target after the first screenshot is mirrored.

You can still show “we have an admin UI” with a barred table. You can describe row counts in text. You do not need the live tenant ID in the address bar to ask for help.

Does this post accuse a victim of bad blur?

No. Extortion reporting is full of claims, leak-site theater, and screenshots offered as evidence. It is not a dataset of named staff who “got owned because they used Gaussian blur.” Do not invent that story. Do not paste an unbarred production snip into a public issue because the other side already uses pictures. That would be adding volume to the same channel.

What do you do with a screenshot you must send during an incident?

New file. Solid bars on secrets. PNG. Inspect at zoom. Rotate credentials that appeared. Prefer text for counts and timelines. Prefer a cropped region over a full desktop. Prefer a meeting without notification toasts. Then send the export, not the original.

Should you screenshot the leak site to brief leadership?

If you must, crop to the claim you need and bar anything that names customers, staff, or hosts that were not already in the briefing text. A leak-site collage is still a screenshot with extra tabs. Do not add your VPN hostname in the chrome of that capture. Do not add a Slack toast over the collage. The crews already use pictures as proof. Your briefing PNG should not become a second proof pack.

Journalists will ask for confirmation. Answer in words your counsel approved. Do not reply with an unbarred admin panel “so they can see it is real.” Real is a statement. The panel is data.

Bar the panel before it hits the incident channel: redact the snip in BlurThis.