In early May's incidents, the volume claimed by attackers didn't match what the affected companies confirmed, a gap that is routine and structurally caused.
Attackers have an interest in inflating the number, because it increases pressure to negotiate, raises the material's value and generates coverage, which is part of the leverage.
The affected party has the opposite interest, and not always in bad faith: confirming exposed records triggers obligations to notify people individually, with direct costs and short deadlines, so companies confirm only what they verified.
The effect of that asymmetry falls on those whose data was exposed. Between the claim and the confirmation, a person doesn't know whether they're in the package, and that interval is exactly when targeted scams work best.
The practice that reduces harm is about communication: having ready the message stating what is known, what isn't yet known and what the person should do meanwhile, instead of the generic note promising to investigate.
