A ransomware post naming Carita and carita.com shows how extortion crews use public pressure long before any breach is independently confirmed.