Ransomware Rivals Expose Each Other’s Operations

The real damage here is not the public taunts. It is the exposure of admin panels, affiliates, victim negotiations, and access logs, which forces ransomware crews to rebuild trust and infrastructure fast. That kind of leak breaks the business side of extortion, not just the branding. Halcyon says 0APT exposed KryBit’s primary operators, affiliates, and negotiation data, including 20 potential victims, ransom demands of $40,000-$100,000, and exfiltration volumes of 10-250GB. KryBit then leaked 0APT’s operational data set, including access logs, PHP source code, and system files, and those logs showed 0APT’s earlier claims about 190+ victims were fabricated. The forward risk is operational churn. Groups hit this way have to rotate leaked components and reconstitute affiliate networks, and the exposure also weakens confidence in any leak-site claims that are meant to pressure victims.

Part of the PlainSec briefing for 2026-04-29

Sources