“No honor among thieves”: M&S hacking group starts turf war

Date:

Share:



Genevieve Stark, head of cybercrime analysis at Google Threat Intelligence Group, said DragonForce could be attempting to attract RansomHub’s affiliates. The hacking group is also believed to be behind attacks on the pages of other rivals, including BlackLock and Mamona, according to Sophos.

Stark warned that whatever the motive, the fallout brings with it an increased risk of cyberattacks. “Instability within the extortion ecosystem can have serious implications for ransomware and data theft extortion victims,” she said.

While double extortions remain rare, US company UnitedHealth Group was the victim of one last year due to a fallout between hacking groups.

In that case, RansomHub was approached by affiliate hacker group, Notchy, to try to extort a second ransom payment after an initial $22 million fee was stolen by Notchy’s original RaaS partner, which faked its disappearance in order to avoid splitting the proceeds, according to cybersecurity experts.

A person familiar with the UnitedHealth hack said multiple extortion attempts were commonplace in cyberattacks, but that follow-up attempts were often opportunistic and lacked credibility.

Rafe Pilling, director of threat intelligence at Sophos, said in a worst-case scenario, the conflict between DragonForce and RansomHub could see them both target the same victim in a battle for business.

“Cybercriminals are a ruthless bunch, and a betrayal between partners can result in a situation where the victim gets extorted twice,” he added.

The global cost of cybercrime is estimated to reach $10 trillion in 2025, according to Cybersecurity Ventures. The figure—which is up from $3 trillion in 2015—comes as hacker groups have increasingly looked to maximise profit through their attacks.

DragonForce, which was first identified in August 2023, listed a total of 82 victims on its dark-web site in the following 12 months, according to cybersecurity firm Group-IB, while RansomHub—which also came to prominence in 2023—reported about 500 victims on its site in 2024.

Jake Moore, global cybersecurity adviser at ESET, warned that the volatility of the situation could make companies’ defence and response tactics more vulnerable.

“Remember this is a Wild West, lawless environment where normal competition rules simply do not apply,” he said.

© 2025 The Financial Times Ltd. All rights reserved. Please do not copy and paste FT articles and redistribute by email or post to the web.



Source link

━ more like this

IKEA goes all in on Matter with new smart home products

IKEA continues its push into the smart home category a new line of -compatible products, set to launch in January. The ready-to-assemble...

The end of the triple lock pension could be inevitable – London Business News | Londonlovesbusiness.com

The end of the triple lock pension could be inevitable due to the increasing cost of providing it to the UK’s aging population,...

Samsung Galaxy Z Flip 7 hands-on: Bigger screens, bigger battery, better foldable?

Once again, it’s time for Samsung’s mid-year Galaxy foldable showcase. Over the last 10 years, Samsung gave us curved edges, curved screens, and...

deVere CEO slams UK wealth tax talk telling the Chancellor to ‘shut it down now’ – London Business News | Londonlovesbusiness.com

Nigel Green, CEO of global financial advisory giant deVere Group, has warned that recent speculation about a possible UK wealth tax could already...

CBI calls for bold action to revitalise UK public equity markets – London Business News | Londonlovesbusiness.com

With domestic capital shifting away from UK equities, new listings having slowed, private equity taking many companies out of the market, and high-growth...
spot_img