logo

'Dumbass' criminal breaks the 'first rule of ransomware club'

ID: 7b832dfb-6cea-51f0-a518-086c3c439262

STIX ID: report--7b832dfb-6cea-51f0-a518-086c3c439262

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

...
...

A Nova (RAlord affiliate) ransomware operator accidentally infected Eriell Group, an oilfield services company in Uzbekistan/Moscow; Nova apologized, banned the affiliate, and claimed no files were encrypted or leaked while offering free recovery help. The article highlights the informal rule among many Russian/CIS-tolerated ransomware groups not to attack CIS organizations and surveys other developer/operator mistakes that have undermined ransomware operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.