“No honor among thieves”: M&S hacking group starts turf war

Date:

Share:



Genevieve Stark, head of cybercrime analysis at Google Threat Intelligence Group, said DragonForce could be attempting to attract RansomHub’s affiliates. The hacking group is also believed to be behind attacks on the pages of other rivals, including BlackLock and Mamona, according to Sophos.

Stark warned that whatever the motive, the fallout brings with it an increased risk of cyberattacks. “Instability within the extortion ecosystem can have serious implications for ransomware and data theft extortion victims,” she said.

While double extortions remain rare, US company UnitedHealth Group was the victim of one last year due to a fallout between hacking groups.

In that case, RansomHub was approached by affiliate hacker group, Notchy, to try to extort a second ransom payment after an initial $22 million fee was stolen by Notchy’s original RaaS partner, which faked its disappearance in order to avoid splitting the proceeds, according to cybersecurity experts.

A person familiar with the UnitedHealth hack said multiple extortion attempts were commonplace in cyberattacks, but that follow-up attempts were often opportunistic and lacked credibility.

Rafe Pilling, director of threat intelligence at Sophos, said in a worst-case scenario, the conflict between DragonForce and RansomHub could see them both target the same victim in a battle for business.

“Cybercriminals are a ruthless bunch, and a betrayal between partners can result in a situation where the victim gets extorted twice,” he added.

The global cost of cybercrime is estimated to reach $10 trillion in 2025, according to Cybersecurity Ventures. The figure—which is up from $3 trillion in 2015—comes as hacker groups have increasingly looked to maximise profit through their attacks.

DragonForce, which was first identified in August 2023, listed a total of 82 victims on its dark-web site in the following 12 months, according to cybersecurity firm Group-IB, while RansomHub—which also came to prominence in 2023—reported about 500 victims on its site in 2024.

Jake Moore, global cybersecurity adviser at ESET, warned that the volatility of the situation could make companies’ defence and response tactics more vulnerable.

“Remember this is a Wild West, lawless environment where normal competition rules simply do not apply,” he said.

© 2025 The Financial Times Ltd. All rights reserved. Please do not copy and paste FT articles and redistribute by email or post to the web.



Source link

━ more like this

Lego’s first Pokémon sets are now available for pre-order

We learned that Lego and Pokémon would be joining forces and the first results of their partnership are here. Pre-orders for all...

Microsoft is killing one of Edge’s best features

Microsoft is quietly killing one of the best features in Edge, and if you’ve ever relied on it to stay organized online, this...

Anthropic made a version of its coding AI for regular people

If you follow Anthropic, you're probably familiar with Claude Code. Since the fall of 2024, the company has been training its AI models...

The Disney+ Hulu bundle is on sale for $10 for one month right now

The peak time for deals on streaming services — the holiday shopping season — has come and gone, but Disney is back with...

OnePlus may have cancelled a successor to its best foldable phone in a while

If you’ve been patiently waiting for the successor to the OnePlus Open, there’s some bad news for you. According to a Smartprix report...
spot_img