Tag: cyber insurance

  • Two Ransomware Crews Reportedly Team Up in Joint Campaign

    Two Ransomware Crews Reportedly Team Up in Joint Campaign

    On 4 July 2026, IT Pro reported that cybersecurity experts had issued an alert describing an ‘unprecedented’ threat campaign in which two ransomware groups appear to be collaborating rather than operating independently. The public summary characterises the activity as a coordinated effort but does not, in the material available to us, name the groups, victims, sectors, or geographies involved.

    Executive Summary

    Ransomware-as-a-service crews typically compete for affiliates, victims and press attention. A public alert describing two named groups jointly running a single campaign — if it holds up on closer inspection — would mark a shift in how the extortion ecosystem organises itself, with implications for attribution, negotiation and defensive playbooks.

    For infrastructure operators, the immediate takeaway is not a specific new indicator of compromise but a reminder that the threat model is evolving faster than many incident-response runbooks. If two crews share tooling, access brokers or leak sites, defenders can no longer assume that a given intrusion set maps cleanly to a single adversary with a single playbook.

    What ‘Unprecedented’ Actually Means Here

    The word ‘unprecedented’ is doing heavy lifting in the headline. Ransomware groups have long shared infrastructure informally: affiliates rotate between programmes, initial-access brokers sell to whoever pays, and code from leaked builders (Conti, LockBit) circulates widely. What would be genuinely new is a formal, sustained partnership in which two branded operations run a single campaign end-to-end. On the public reporting available, it is not yet clear which of those descriptions best fits the activity being flagged.

    Readers should therefore treat the alert as a lead rather than a conclusion. The substantive question for defenders is whether investigators are seeing shared command-and-control, shared negotiation portals, or merely overlapping affiliates — each of which carries a different weight.

    Why Crews Would Cooperate — and Why They Usually Don’t

    Cooperation is economically rational when it lowers cost or raises the ransom take. Sharing a proven intrusion chain, splitting proceeds on high-value targets, or pooling leverage over a single victim (double-extortion with two leak sites) can all lift returns. Law-enforcement pressure since the 2021–2024 wave of takedowns has also thinned the affiliate pool, giving surviving operators an incentive to consolidate rather than compete.

    Against that, ransomware brands are jealous of reputation. A shared campaign dilutes the ‘we always decrypt’ signal that groups use to convince victims to pay, and it creates operational security risk: every extra participant is another potential informant. Historically, crews have preferred loose federation to formal alliance for exactly that reason.

    Implications for Infrastructure Buyers

    For data-centre customers, cloud tenants and connectivity buyers, the practical response does not change dramatically because two groups are named instead of one. The controls that matter — enforced multi-factor authentication, segmented backups tested for restore, privileged-access monitoring, and rehearsed incident-response contracts — apply regardless of which brand appears on the ransom note. What does change is negotiation posture: if two crews are jointly holding data, a victim cannot assume that paying one buys silence from the other.

    Insurers and legal counsel will want to understand this quickly. Cyber-insurance policies and sanctions-screening workflows are built around identifying a specific threat actor. A joint operation complicates both attribution and any regulatory obligation to check whether payment would breach sanctions.

    How to Read Alerts Like This

    Threat-intelligence alerts serve two audiences at once: defenders who need actionable indicators, and a wider readership that includes journalists, executives and — inevitably — the attackers themselves. Strong alerts publish indicators of compromise, TTPs mapped to MITRE ATT&CK, and a clear statement of confidence. Where those elements are absent from the public summary, the honest analytical response is to note the gap rather than fill it with speculation.

    Background

    Ransomware has been the dominant cyber-extortion model since roughly 2019, when double-extortion — encrypting data and threatening to leak it — became standard practice. The ecosystem is organised around branded ‘affiliate’ programmes such as LockBit, ALPHV/BlackCat, Cl0p and their successors, most of which run as ransomware-as-a-service.

    Law-enforcement operations against LockBit and ALPHV in 2023–2024, together with source-code leaks from earlier crews such as Conti, reshaped the market. Affiliates rotated between surviving programmes, new brands emerged, and researchers have periodically flagged overlaps in tooling and personnel. Against that backdrop, a claim of formal cooperation between two named crews is notable but consistent with the direction of travel.

    Source: Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaign — IT Pro report, 4 July 2026, describing a joint ransomware campaign flagged by security researchers.

  • Survey: Most Security Workers Pressured to Hide Breaches

    Survey: Most Security Workers Pressured to Hide Breaches

    Cybersecurity Dive reported on July 1, 2026 that a majority of surveyed cybersecurity workers say they have been directed to keep a security breach quiet rather than disclose it. The finding, drawn from an industry survey the outlet cited, spans practitioners across the profession rather than a single company or sector.

    Executive Summary

    The headline claim is stark: more than half of cybersecurity professionals in the survey say they have, at some point, been instructed to conceal a breach. If accurate, that behavior sits in direct tension with regulatory disclosure regimes, customer contracts, cyber insurance conditions, and the fiduciary duties boards owe shareholders.

    For enterprise buyers of cloud, connectivity, and managed security services, the report reframes a familiar question. It is no longer only whether a vendor can detect and contain an incident, but whether the vendor’s culture and governance will actually surface one when it happens. That is a procurement and audit issue as much as a technical one.

    Concealment Culture Meets a Disclosure Era

    The last three years have layered new disclosure obligations on top of old ones. The U.S. Securities and Exchange Commission requires public companies to report material cyber incidents within four business days. The European Union’s NIS2 directive tightens reporting for critical infrastructure operators. State breach notification laws and sector rules for health care, banking, and telecoms add further triggers. A survey suggesting that most practitioners have been pressured to bury an incident implies a structural mismatch between what the rules require and what internal incentives reward.

    The mismatch is easy to explain. Disclosure invites regulatory scrutiny, litigation, customer churn, and share-price impact. Silence, by contrast, is cheap in the short term and only expensive if the concealment is later exposed. Absent enforcement that is fast and predictable, rational actors under quarterly pressure will sometimes choose silence, and rank-and-file security staff will feel the weight of that choice.

    What Buyers, Insurers, and Boards Should Actually Ask

    For enterprise customers, the practical takeaway is that generic assurances about incident response are not enough. Contracts should specify notification triggers, timelines, and the identity of the executive who owns the decision to notify. Right-to-audit clauses, independent forensic requirements, and clear whistleblower protections for the vendor’s security staff all become more meaningful in light of a finding like this one.

    Cyber insurers face a related problem. Policies typically require prompt notification of incidents; systematic concealment inside insured organizations undermines the actuarial basis of the product. Boards, meanwhile, should be asking their chief information security officers a direct question on the record: have you or your team ever been asked to withhold information about an incident, and what would you do if you were? The answer, and how freely it is given, is itself a governance signal.

    Reading the Survey With Appropriate Skepticism

    The finding deserves scrutiny in both directions. Self-reported survey data on sensitive workplace behavior is prone to selection bias: practitioners who have experienced pressure to conceal are more motivated to respond, and the definition of “pressure” can stretch from an explicit order to an ambiguous hallway conversation. Without the underlying methodology, sample frame, and question wording, the headline number is directional rather than definitive.

    At the same time, dismissing the finding because the methodology is thin would be its own error. Multiple prior industry surveys, regulator enforcement actions, and post-breach litigation have documented cases in which disclosure was delayed or shaped for reasons that had little to do with investigative integrity. The honest reading is that the survey is a signal worth investigating, not a verdict, and that the burden now sits with both the researchers to publish their method and with enterprises to test the claim inside their own walls.

    Background

    Cybersecurity Dive is a trade publication covering enterprise security, regulation, and incident response. Industry surveys of security practitioners have become a recurring genre, often used to surface workplace and governance issues that formal disclosures do not capture. The findings typically inform how regulators, insurers, and boards frame their next round of questions to management.

    The broader context is a decade of expanding breach notification law, from early U.S. state statutes to GDPR in 2018, the SEC’s 2023 incident disclosure rule, and NIS2 in the EU. Each regime has raised the legal cost of silence, even as commercial incentives to stay quiet remain strong.

    Source: Most cybersecurity workers have been told to conceal a breach, report finds — Cybersecurity Dive report citing a survey in which a majority of security practitioners said they had been directed to keep a breach quiet.