Blog | RTGroup.ca

Why Trusting Cybercriminals Is Never Part of a Smart Cyber Security Strategy

Written by Ian Robertson | Sep 1, 2026

 

When cybercriminals begin targeting each other, it can seem like an unexpected twist in the ongoing fight against cybercrime.

One criminal group accuses another of dishonesty. Threats are exchanged publicly. Promises are made to expose rival gangs or even help victims recover stolen data.

At first glance, this might appear to be good news for businesses. If criminals are fighting among themselves, perhaps it weakens their operations or creates opportunities for victims to recover more quickly.

Unfortunately, that is rarely how cybercrime works.

The only thing businesses can consistently rely on is that cybercriminals act in their own best interests. Whether they are attacking companies or arguing with rival groups, their goals remain the same: financial gain, influence, and control.

Understanding this reality is an important part of developing a strong cyber security strategy.

Cybercriminals Are Not Working for Victims

Over the past several years, ransomware groups have become more organised. Many operate like businesses, complete with customer support, affiliate programs, negotiation teams, and even marketing strategies designed to pressure victims into paying.

Occasionally, disagreements between these groups become public.

One criminal organisation may accuse another of stealing profits, breaking agreements, or operating unfairly. Sometimes they threaten to reveal private information about rival gangs or claim they can help victims recover encrypted files.

While this may sound encouraging, businesses should remember one important fact.

These organisations are still criminal enterprises.

Their actions are never motivated by protecting victims or correcting wrongdoing. Instead, every decision is designed to increase their own influence or generate more money.

Even when they claim to be helping businesses, their true objective remains personal gain.

Why Promises From Criminals Cannot Be Trusted

Imagine your business has experienced one of many modern ransomware attacks.

Your files are encrypted.

Operations have stopped.

Employees cannot access important information.

Customers are waiting for answers.

Then another criminal group contacts you with an offer to recover your data or unlock your systems.

During such a stressful event, that offer might sound tempting.

However, there is no reason to believe these promises are genuine.

There is often no evidence that the group has the technical ability to restore your files. Even if they do possess the required tools, they have no legal or ethical obligation to honour any agreement they make.

Businesses would essentially be placing their trust in another criminal organisation.

That introduces additional risks instead of reducing them.

In many cases, organisations that communicate with cybercriminals expose themselves to further extortion attempts, additional financial losses, or future targeting.

Criminals Often Use Confusion as a Weapon

Cybercriminals understand that confusion creates opportunities.

When a business experiences a cyberattack, leaders are forced to make important decisions under significant pressure.

Every minute of downtime may affect customers, employees, suppliers, and revenue.

Attackers know this.

That is why they often create urgency through deadlines, threats of public data leaks, or promises that appear to offer an easy solution.

When multiple criminal groups become involved, the confusion increases.

Victims may struggle to determine which information is accurate, who is responsible for the attack, or whether any promises can be trusted.

This uncertainty benefits criminals far more than it benefits the organisations they target.

Businesses should avoid making decisions based on pressure created by attackers.

Instead, they should follow a well-prepared incident response plan developed before an attack ever occurs.

Prevention Is Always Better Than Negotiation

One of the most effective ways to reduce the impact of ransomware attacks is to focus on prevention rather than recovery.

Although no security solution can guarantee complete protection, multiple layers of defence significantly reduce the likelihood of a successful attack.

Effective cyber security begins with understanding where vulnerabilities exist and addressing them before criminals have an opportunity to exploit them.

This includes maintaining current software updates, securing user accounts, implementing multi-factor authentication, educating employees about phishing emails, and monitoring systems for suspicious activity.

Strong security practices create multiple barriers that attackers must overcome.

The more difficult a business is to compromise, the more likely criminals are to move on to easier targets.

Backups Are Only Valuable if They Work

Many organisations believe they are protected simply because they have backups.

Unfortunately, having backups is only one part of the solution.

Businesses also need to ensure their backups are complete, isolated from attackers, and regularly tested.

If backups have never been restored successfully during testing, there is no guarantee they will function during an emergency.

An effective backup strategy should answer several important questions:

  • Are backups performed regularly?
  • Are multiple copies stored securely?
  • Can data be restored quickly?
  • Are backups protected from ransomware encryption?
  • Has the recovery process been tested?

Reliable backups remain one of the strongest forms of business data protection because they allow organisations to recover without depending on criminals.

Early Detection Makes a Significant Difference

Cyberattacks rarely happen instantly.

Many attackers spend days or even weeks exploring networks before launching ransomware.

During this time they attempt to gain administrator privileges, disable security tools, locate valuable information, and identify backup systems.

Continuous monitoring helps detect these activities before serious damage occurs.

Security monitoring solutions can identify unusual login attempts, unexpected file activity, suspicious software installations, or abnormal network traffic.

Detecting these warning signs early provides organisations with valuable time to respond before attackers achieve their objectives.

Early detection is an essential component of modern business data protection.

Employee Awareness Remains One of the Strongest Defences

Technology alone cannot stop every cyberattack.

Employees play an equally important role.

Many successful attacks begin with a phishing email that appears legitimate.

An employee may unknowingly click a malicious link, open an infected attachment, or provide login credentials to a fake website.

Regular security awareness training helps staff recognise these threats before they become serious incidents.

Training should include:

  • Identifying phishing emails.
  • Creating strong passwords.
  • Using multi-factor authentication.
  • Reporting suspicious activity quickly.
  • Understanding safe internet browsing habits.

Well-informed employees become another valuable layer of cyber security.

Incident Response Plans Reduce Panic

When organisations experience a cyberattack, panic often leads to poor decision-making.

Without a documented response plan, valuable time may be lost deciding what to do next.

An incident response plan outlines the steps that should be taken immediately after discovering a security incident.

It identifies key responsibilities, communication procedures, technical recovery processes, and external contacts.

Having a clear plan allows businesses to respond confidently instead of reacting emotionally.

This reduces downtime, limits financial losses, and improves recovery efforts.

Most importantly, it removes the temptation to rely on promises made by cybercriminals.

The Growing Role of Artificial Intelligence

Artificial intelligence is changing both cybercrime and cyber defence.

Attackers increasingly use AI to automate phishing campaigns, improve social engineering tactics, and identify vulnerable systems more efficiently.

Fortunately, security professionals are also using AI to strengthen defences.

Modern AI-powered security tools can analyse large volumes of activity, identify unusual behaviour, prioritise risks, and respond to threats much faster than traditional manual processes.

As AI technology continues to evolve, it will play an increasingly important role in improving cyber security and supporting stronger business data protection for organisations of every size.

Businesses should expect AI to become an important part of future security strategies.

Trust Should Always Come From Trusted Professionals

One of the biggest lessons businesses can learn from public disputes between cybercriminal groups is surprisingly simple.

Never confuse conflict between criminals with trustworthiness.

Even when one group claims to expose another or promises assistance, both organisations remain focused on their own interests.

Businesses should never rely on criminals for advice, recovery, or technical support.

Instead, organisations should build relationships with experienced security professionals before an emergency occurs.

Trusted technology partners can help develop security strategies, monitor systems, recover from incidents, and provide guidance based on proven best practices rather than empty promises.

Preparation always provides better outcomes than desperation.

A Strong Security Strategy Is Built Before an Attack

Every organisation hopes it will never become the target of cybercrime.

Unfortunately, ransomware attacks continue to affect businesses of every size and across every industry.

The best defence is not hoping criminals overlook your business.

It is building a comprehensive strategy that includes layered cyber security, reliable business data protection, tested backups, continuous monitoring, employee education, and a documented incident response plan.

When these elements work together, businesses are better prepared to prevent attacks, minimise disruption, and recover quickly if an incident occurs.

Most importantly, they avoid placing their future in the hands of people who have never intended to help them in the first place.

About Robertson Technology Group

Robertson Technology Group provides managed technology support and cyber security solutions for small to medium-sized businesses across Canada. Rather than offering one-size-fits-all services, we work closely with each client to understand their business goals, operational needs, and security requirements.

Our team delivers personalized support, proactive monitoring, reliable business data protection, and practical cyber security solutions that help reduce risk while improving day-to-day technology management. We continually evaluate emerging technologies, including AI-powered security analysis, to help clients stay ahead of evolving threats. Whether your business has five employees or two hundred, Robertson Technology Group provides trusted expertise that allows you to focus on running your business while we help protect the technology that supports it.