Cyber criminals arguing among themselves might sound like good news.

One group targeting another. Threats being exchanged. Claims that they will expose identities, leak information, or even help victims caught in the middle.

At first glance, it can almost feel like justice. The reality, however, is much simpler: there is only one thing you can trust cyber criminals for, and that is looking after their own interests.

A recent dispute between ransomware groups illustrates this perfectly. One group began threatening another, claiming it would reveal identities, publish sensitive information and even help victims regain access to locked files.

For businesses affected by a cyber attack, that kind of promise can sound appealing. When operations are disrupted and important data is inaccessible, any offer of assistance may seem worth considering. But that is exactly where the danger lies.

These groups are not motivated by fairness, ethics or a desire to help victims. Their objectives remain the same:

  • Gain leverage
  • Create pressure
  • Increase control
  • Generate profit

Even when cyber criminals turn against one another, the underlying motive rarely changes.

In this case, one group claimed it could help victims recover their data. The problem is that there is no reliable evidence to support those claims. And even if the capability existed, businesses would still be placing their trust in a criminal organisation with no accountability and no obligation to honour its promises.

It is similar to being caught between two scammers and hoping that one of them is the trustworthy option. That is not a position any business should find itself in.

The situation highlights an important lesson for organisations of all sizes: when a cyber attack occurs, your response strategy should never depend on trusting another attacker.

No matter how convincing the offer may appear, or how stressful the situation becomes, relying on cyber criminals introduces additional risk at a time when your business is already vulnerable.

Across South Africa, businesses are facing growing pressure from ransomware attacks, business email compromise, banking-related scams and other cyber threats. Criminals often impersonate trusted organisations, including well-known South African banks and service providers, making it even more important to verify communications and follow established security procedures.

A far safer approach is to invest in strong cyber security measures before an incident occurs and rely on trusted experts if something goes wrong.

This includes:

  • Maintaining secure, tested and easily recoverable backups
  • Using monitoring tools to identify suspicious activity as early as possible
  • Establishing a documented cyber incident response plan
  • Regularly reviewing security controls and user awareness training
  • Implementing security measures that continue to support business continuity during power disruptions and other operational challenges
  • Working with experienced cyber security professionals who are focused on protecting your business

For many medium-sized businesses, cyber resilience is no longer simply an IT concern. It is a business requirement. A successful attack can lead to operational downtime, financial losses, reputational damage and, where personal information is involved, potential obligations under South Africa’s Protection of Personal Information Act (POPIA).

When an incident occurs, decisions often need to be made quickly and under pressure. The choices made during those critical moments can either limit the damage or create even greater challenges.

That is why preparation matters. Having tested backups, clear recovery procedures, trusted technology partners and a well-defined response plan can make the difference between a manageable disruption and a major business crisis.

The best time to prepare is before an attack happens.

If you are not completely confident in how your business would respond to a ransomware attack or other cyber security incident, now is the time to review your strategy, strengthen your defences and ensure your response plan is ready.

Need guidance on improving your organisation’s cyber security, ransomware preparedness or incident response strategy? Contact GZD for practical, expert advice tailored to your business and its unique risk profile.


Give us a call  ‣  031 818 9060