Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Ransomware gangs can sell services to one another and still compete, retaliate, or break into each other’s systems. These groups are not unified organizations with dependable alliances: operators, affiliates, access brokers, and infrastructure providers may all play separate roles, and their relationships are often transactional. Reports of attacks between gangs can point to rivalry or disputes, but the available evidence does not establish one motive—or even independently confirm every reported incident.

How can ransomware groups cooperate and still become rivals?

Ransomware-as-a-service (RaaS) is a criminal business arrangement in which operators provide ransomware tools or other services and affiliates may use them to carry out attacks. Other actors can supply access to victims’ networks or provide infrastructure. The UK National Cyber Security Centre (NCSC) describes these functions as work that can be performed by different threat actors and sold as a service.

A business relationship is not the same as loyalty. A group may buy or rent a service from another actor without having a lasting alliance, shared objectives, or a reliable way to resolve disputes. That structure creates room for competition over money, access, reputation, and affiliates—as well as for opportunistic attacks. These are plausible pressures in a fragmented criminal market, not proof of the motive behind any particular incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The division of labor also makes it hard to say who was responsible for an attack. As the NCSC puts it, “Attribution of a ransomware (or other cyber crime) incident to a single responsible actor is often impossible.” The person who gains access, the affiliate who deploys ransomware, and the operator who runs a leak site may be different actors.

What do reported attacks between ransomware groups show?

Two reported incidents illustrate why claims about gang-on-gang attacks need careful attribution. They differ in what was targeted and how firmly the reporting establishes what happened.

Incident What was reported Attribution and limits
LockBit infrastructure, May 2025 Broadcom’s 2026 report says LockBit’s infrastructure was hijacked and defaced. The actor was unknown and was described as “likely a rival ransomware gang.” The report does not establish the actor’s identity or motive.
ShinyHunters–Clop, reported September 2026 ITPro reported that ShinyHunters claimed to have taken over Clop’s website and infrastructure after a dispute. This is ShinyHunters’ claim, not independent confirmation of the takeover’s full scope or motive. Clop had not publicly commented in ITPro’s report, and an analyst cautioned that ShinyHunters could benefit from publicity.

In the second case, KnowBe4 Lead CISO Advisor Javvad Malik told ITPro: “When relationships are built on deception and fear, double-crossing and betrayal is always a credible threat.” That is Malik’s interpretation of the reported dispute, not proof that betrayal explains every conflict between criminal groups.

Why might one group target another?

Rivalry, retaliation, disputes, and opportunism are all plausible explanations, but the incidents above do not establish a single general cause. An attack on criminal infrastructure or a leak site might disrupt operations or damage a rival’s reputation. A dispute could involve business relationships or affiliates. Yet the available reporting does not confirm the motive in either example, so these possibilities should not be presented as settled explanations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Law-enforcement action and public leaks can also change the conditions in which groups operate. The Cyber Threat Intelligence Integration Center (CTIIC) said the ransomware threat became more fragmented following Operation Cronos, which began targeting LockBit actors and infrastructure in February 2024. That finding describes a broader change in the threat landscape; it does not show that the operation caused a particular gang-on-gang attack.

Do ransomware statistics show that gangs are attacking each other more often?

No reliable prevalence estimate for attacks between ransomware groups is established in the cited sources. Overall ransomware counts cannot answer how often gangs target one another.

CTIIC reported 2,593 ransomware attacks in 2022, 4,591 in 2023—a 77% year-to-year increase—and 5,289 in 2024, a 15% increase. These are counts of ransomware attacks overall, not of attacks on other gangs. CTIIC defines its cases as claimed or reported events in which actors encrypt or steal data and pressure victims for payment. It also warns that reporting based on leak sites and dark-web forums may inflate counts.

The Canadian Centre for Cyber Security reports a different, Canada-specific measure: an average 26% year-over-year increase in ransomware incidents known to the Cyber Centre from 2021 to 2024, with that average estimated to continue through 2025. This is neither a global count nor a measure of gang rivalry. The centre describes the broader environment as “a highly sophisticated and interconnected threat ecosystem that is constantly evolving.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does this mean for defenders?

For organizations, the main lesson is not that rival gangs will disrupt one another on their behalf. It is that a ransomware incident can involve several actors and services, making attribution uncertain and resilience planning more complex. Treat claims about an attacker’s identity or motive as claims until they are independently supported, and avoid assuming that a named group performed every stage of an incident.

Defensive planning should account for both encryption and data theft. The Canadian Centre for Cyber Security notes that stolen-data extortion means backups alone are not a complete mitigation. Organizations need a broader resilience plan that addresses recovery, protection of sensitive information, and response to extortion, rather than relying on the hope that criminal rivals will disable one another.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.