/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Experts say ransomware group DragonForce, which targeted M&S, Harrods, and the Co-op, started a turf war with rival RansomHub that may bring more company hacks

A clash between rival criminal ransomware groups could result in corporate victims being extorted twice, cyber experts warn Bluesky: @shashj Bluesky: Shashank Joshi / @shashj : Cyber gangland.  “The ransomware group linked to the recent cyber attacks on UK retailers M&S, Harrods and the Co-Op has begun a turf war with its rivals, triggering a battle within the industry that could bring more hacks” www.ft.com/content/22cb...

Financial Times Kieran Smith

Context & Ripple Effects

DragonForce was tied to a concentrated run of attacks against major UK retailers, including the group's claimed campaign against M&S, Harrods, and Co-op. Subsequent coverage said Co-op contained the operational impact by shutting systems down quickly, though customer data was still reportedly taken.

The reported conflict with RansomHub matters because it shifts the immediate risk beyond a single intrusion: competing groups may contest access to the same corporate victims and use stolen data as parallel leverage.

First-order effects

  • Companies already targeted by either group face a heightened risk of overlapping extortion demands, including demands tied to the same compromised data.
  • DragonForce and RansomHub’s dispute could turn corporate network access and stolen victim information into contested assets, rather than tools controlled by one extortion crew.

Second-order effects

  • Security teams and incident-response providers may need to plan for multiple claimants and separate leak threats after one breach, complicating negotiation, communications, and recovery decisions.
  • Retailers and other large organizations may prioritize rapid isolation of affected systems; the earlier Co-op response that limited ransomware deployment illustrates why containment can alter an attacker’s options even when data theft is alleged.

Third-order effects

  • If rival groups repeatedly reuse access or data against the same victims, ransomware defense will increasingly center on preventing and containing data exfiltration as well as restoring encrypted systems.
  • The episode reinforces the fragmented, service-oriented ransomware ecosystem seen in the earlier LockBit ransomware-as-a-service case, where criminal specialization can make attribution and victim response more complex.

The trend: Ransomware is evolving from isolated encryption events into a contested extortion market in which access, data, and victim pressure can be traded or fought over by multiple criminal groups.

Discussion

  • @shashj Shashank Joshi on bluesky
    Cyber gangland.  “The ransomware group linked to the recent cyber attacks on UK retailers M&S, Harrods and the Co-Op has begun a turf war with its rivals, triggering a battle within the industry that could bring more hacks” www.ft.com/content/22cb...