
A ransomware group recently threatened to expose another group, leak information about its members, and help victims recover their files.
That last part is the one that could catch people out.
When a business is locked out of its systems and under pressure to get back online, an offer of help can sound worth considering. But this isn’t a rescue service. It’s one criminal group trying to gain an advantage over another.
They may claim they have a working recovery tool. They may promise not to cause any more damage. They may even make themselves sound like the reasonable side of the argument.
None of that makes them trustworthy.
There’s no guarantee they can recover the data, and no reason to believe they’ll keep their word. Even if they do help with one part of the problem, they could use the conversation to gather more information, demand money, or create a second problem while you’re still dealing with the first one.
It’s a bit like having two burglars arguing in your office and deciding one of them seems helpful.
If your business is hit by ransomware, don’t start negotiating with another criminal group because they claim to have the answer. Bring in your IT provider, cybersecurity team, insurance carrier, and legal counsel. Depending on the situation, law enforcement may also need to be involved.
The better option, of course, is to make those decisions before everyone is staring at locked screens.
Your incident plan should spell out who gets called, who has authority to make decisions, where the backups are, and whether those backups have actually been tested. “We have backups somewhere” is not the same as knowing you can restore the business from them.
Cybercriminals do turn on each other. They leak names, steal each other’s tools, and make promises to victims when it suits them.
You can rely on them to act in their own interest. Nothing more.
Share this post


