BlurThis

Guide

Why extortion groups post screenshots of your admin panel

By Shaibaz, graphic designer and creator of BlurThis

Ransom notes often include a picture of a dashboard. Why crews post that picture, separate from defender snips that become a record.

News desk laptop showing a dashboard photo with credentials barred
Illustration by BlurThis

Extortion crews treat a dashboard PNG like a press kit. They do not wait for a full dump. They post a picture of an admin panel, a file tree, or a mailbox, and that picture is the proof they were inside. This page is that leak-site habit: why the picture works as theater, and why your internal snips should not mirror it unbarred.

It is not a tutorial for anyone’s intrusion, not a catalog of crews, and not an invitation to invent a named victim who “got owned because they used Gaussian blur.” The sibling on defender captures that become a record is proof-of-hack screenshots.

In May 2026, BleepingComputer reported that RansomHouse claimed a Trellix source-code intrusion and posted screenshots as proof of access. That write-up is the citation for the pattern, not a claim that a named person paid ransom because they forgot to blur a table. Screenshots are already the leak channel those groups use. Do not add yours, unbarred, to a public ticket or a Slack that forwards to a vendor.

Why a screenshot is useful as “proof” at all

UI mockup with private fields coveredOpen larger image in a new tab

It is fast to read. A dump takes time to verify. A picture of an internal admin UI, a source tree, or a mailbox is a shape civilians and journalists recognize. Leak sites and negotiation posts use that shape because it travels: one image, one claim, minimal work for the audience.

You should recognize the same shape when you attach it from the defender’s side: hostnames, user counts, backup products, customer rows. CISA’s StopRansomware pages and the joint ransomware guide talk about reporting, backups, and containment. They do not tell you to paste a live tenant into chat. The operational overlap is narrower: assume pictures travel, and assume the pictures you generate during IR will travel the same way the adversary’s pictures travel.

Cover your own admin screens before you share internally

A “quick snip” of production with customer rows visible becomes attachment number four in an email thread that leaves the company. Incident channels spawn vendor threads. Vendor threads spawn tickets. Tickets spawn PDFs. Your unbarred admin panel does not stay in the war room.

You can still show “we have an admin UI” with a barred table. You can describe row counts in text. You do not need the live tenant ID in the address bar to ask for help. Hygiene for tokens in chrome: URL bar.

Bar an admin panel before it hits Slack

  1. Crop to the control that is actually broken. Drop the rest of the desktop, the SSO tile strip, and any second monitor.
  2. Open the crop in Paint, Preview, or a browser tab. Pick a filled rectangle, not a highlighter.
  3. Paint Black bar over customer names, emails, account IDs, and any license or seat count that identifies the tenant.
  4. Cover the full address bar, query strings, and session crumbs. Cover backup-product logos sitting next to a hostname that names a plant or a hospital.
  5. Zoom to 100%. If a glyph peeks out, enlarge the bar. Export PNG. Send that file, not the original.
Paint-style canvas with a solid black rectangle covering fake UIOpen larger image in a new tab

What you should see after export: a panel that still proves a UI exists, with every identifier gone. If you can still read a customer surname at the edge of a bar, someone else can too.

What defenders should cover on a production snip

  • Customer names and rows that would identify a tenant.
  • Internal hostnames and VPN names in title bars.
  • SSO tiles that name the org.
  • License counts and backup product plus server name in one frame.
  • Query strings, tokens, and cookies in the chrome.
  • Anything a second group could use after the first screenshot is mirrored.

This post does not accuse a victim of bad blur. Extortion reporting is full of claims, leak-site theater, and screenshots offered as evidence. It is not a dataset of named staff who “got owned because they used Gaussian blur.” Do not invent that story. Do not paste an unbarred production snip into a public issue because the other side already uses pictures. That would be adding volume to the same channel.

Should you screenshot the leak site to brief leadership?

If you must, crop to the claim you need and bar anything that names customers, staff, or hosts that were not already in the briefing text. A leak-site collage is still a screenshot with extra tabs. Do not add your VPN hostname in the chrome of that capture. Do not add a Slack toast over the collage. The crews already use pictures as proof. Your briefing PNG should not become a second proof pack.

Journalists will ask for confirmation. Answer in words your counsel approved. Do not reply with an unbarred admin panel “so they can see it is real.” Real is a statement. The panel is data.

If the bars look wrong after you paste

A light smear on a customer column is the wrong tool. Short names survive polite Blur. Use a fill. If Slack or email recompressed the file into a mushy JPEG, go back to the PNG export and attach it as a document, not as an inline photo. If a toast with another tenant name slid in while you captured, recapture after you dismiss notifications, or bar the banner after the fact.

Prefer text for counts and timelines. Prefer a cropped region over a full desktop. Prefer a meeting without notification toasts. Then send the export, not the original. Rotate credentials that appeared on screen even under a bar you are not sure survived the hop.

Recap

Leak sites already speak in screenshots. Your internal admin snips are the same dialect. Crop, paint opaque bars, export PNG, inspect at zoom, and keep the raw panel out of the thread that will be forwarded. Bar the panel before it hits the incident channel: redact the snip in BlurThis.

Related guides

Back to all guides