Across several incidents in the period, the data volume claimed by attackers didn't match what the affected company confirmed. The gap is routine and has a structural cause.
Attackers have an interest in inflating. A large number increases pressure to negotiate, raises the material's value in resale forums and generates headlines, which are part of the leverage.
The affected party has the opposite interest, and not always in bad faith. Confirming exposed records triggers obligations to notify people individually across several jurisdictions, with direct cost and short deadlines, so companies confirm only what they have verified.
The practical effect of that asymmetry falls on the exposed: in the interval between announcement and confirmation, a person doesn't know whether their data is in the package, and that interval is exactly when targeted scams work best.
For anyone operating systems, the lesson is about communication rather than defence: having ready the message that states what is known, what isn't yet known and what the person should do meanwhile is worth more than a note promising to investigate.
