When Cybercriminals Fall Out, Don’t Let It Stop Your Workshop

A hands-on business reviewing its IT protection and backup plan on screen, representing keeping a workshop running and avoiding downtime during a cyber attack.
When attackers fall out, keep your workshop moving with tested backups and trusted support, not a criminal’s promise.
  • Cybercriminals only ever look after themselves — even when one ransomware gang turns on another, it’s still about pressure and profit, not helping you.
  • An attacker’s “offer to help” won’t get you back to work — there’s no proof they can recover your files and no reason a criminal will keep a promise.
  • Trusting an attacker adds downtime, not fixes it — for a workshop, every extra hour down means stalled jobs, idle staff and unhappy customers.
  • The fast route back to production is protection and trusted support — tested backups, early monitoring and a simple plan everyone knows.
  • Decisions made in a panic make things worse — a plan sorted in advance keeps the workshop moving on the day.

Now and then a story does the rounds in the tech world that almost sounds like good news: cybercriminals turning on each other. One ransomware group threatens another, promising to expose them, leak their data, and even help the other lot’s victims unlock their files. If you run a busy workshop, garage or manufacturing operation, it’s easy to think, “Serves them right,” and move on.

But if your business has actually been hit, and someone claiming to be one of these groups says they can get your files back, it stops being an amusing headline and starts sounding like a shortcut. When the machines are down, jobs are stacking up and staff are standing around, any offer to fix it fast is tempting. This post is a plain-English look at why that particular shortcut leads straight to a dead end, and what actually keeps your operation moving.

There’s only one thing you can rely on cybercriminals for

Let’s be blunt. The one thing you can rely on a cybercriminal for is that they’ll look after themselves. When one ransomware crew recently started threatening a rival, claiming they’d expose them and even help their victims, nothing about their motivation had changed. It was still about gaining an edge, piling on pressure and making money. Falling out with a competitor is just another move in a nasty game.

Think of it like a dodgy supplier who’s let you down before turning up and swearing that this time the parts will arrive on Friday. You wouldn’t stop the job and bet the week on their word, because you know there’s nothing holding them to it. A cybercriminal’s “help” is exactly that, a promise with nothing behind it.

Why the “helpful” attacker just keeps you down for longer

Picture your workshop mid-attack. Systems are locked, the job scheduler is frozen, and nobody can pull up a drawing or an invoice. Then a message pops up from a second group saying they can undo the first group’s damage. When you’re losing money by the hour, it’s genuinely tempting to give it a go.

Here’s the problem. There’s no proof they can recover anything, and even if they could, you’re still dealing with a criminal outfit that has zero obligation to actually do it. You could hand over money or access, wait, and end up exactly where you started, only poorer and further behind. It’s like being stuck between two con artists and hoping one turns out to be the honest one. Meanwhile the clock keeps ticking and the downtime keeps growing. These attackers rely on that pressure to make you act fast, the same trick behind fake alert emails designed to rush you into a bad click, which we covered in our guide to spotting fake Azure alerts and keeping your business moving.

Downtime is the real cost, not the ransom

For a hands-on business, the headline figure isn’t the ransom demand, it’s the downtime. Every hour your systems are down is an hour of stalled production, idle staff, delayed deliveries and customers wondering where their job is. That cost mounts up fast, and it doesn’t stop when the systems come back, because you’ve still got the backlog to clear.

That’s exactly why trusting an attacker is such a bad bet: it doesn’t shorten the downtime, it stretches it out while you wait on an empty promise. The businesses that bounce back quickest are the ones that never handed control to anyone but their own trusted support in the first place. A big part of that is knowing your data is genuinely safe and recoverable, something a lot of firms assume without ever checking. We looked at that gap between confidence and reality in our post asking whether your data is actually as secure as you think.

What actually keeps the work flowing

If the answer is never “trust another attacker”, what is it? It’s not flashy, but it works: get the right protection in place before anything goes wrong, and have trusted support ready if it does. For a workshop, that comes down to three practical things.

1. Backups you’ve actually tested. A backup only counts if you’ve proven you can restore from it. An untested backup is a fingers-crossed job. Regular restore tests mean that if you’re ever hit, you can rebuild from your own copy and get back to work, no criminal required.

2. Monitoring that catches trouble early. Plenty of attacks start quietly, a dodgy login here, some unusual activity there, days before anything obvious happens. Keeping an eye on your systems means you can spot and stop it early, long before you’re ever staring at a locked screen wondering who to trust.

3. A simple plan everyone knows. When something goes wrong, you’ll be making calls under pressure. A straightforward plan, who to ring, what to shut down, who tells the customers, takes the guesswork out at the worst possible moment. That plan should also cover the basics that stop attackers getting in at all, and few things do that better than making sure old logins can’t be used against you, which is why we keep banging the drum about why multi-factor authentication matters more than ever.

Don’t make the big decisions in a panic

The nasty thing about a cyber attack is that it forces big decisions fast, when you’re stressed and short on time. That’s deliberate. Attackers push hard because a rushed decision is usually a worse one. The businesses that come through with the least disruption aren’t the ones that think brilliantly on their feet on the day; they’re the ones that already decided what they’d do, so on the day they’re just following the plan.

That’s where a trusted IT partner comes in. Having people on your side whose job is to keep your business running, not to squeeze it, means that when trouble hits you’ve got proper help acting in your interest, getting you back to full production as quickly and safely as possible.

The bottom line for hands-on businesses

When cybercriminals fall out, enjoy the headline and then forget about it. Their infighting doesn’t change what they are or make their promises worth anything. If your business is ever hit, “trust the other attacker” should never be on the list of options, no matter how good the offer sounds or how long you’ve been down. The reliable route is the one you sort out in advance: tested backups, early monitoring, a simple plan, and trusted support. If you’re not fully confident your workshop could keep moving through an attack, that’s worth fixing now, before you need it. Get in touch and we’ll help you put a practical plan in place, so whatever the criminals get up to next, your operation keeps running.

Scroll to Top