Inside a bad actor's mind: what a ransomware crew tells you without meaning to
by Claudiu Hulea · IT Management Consultant
Ransomware crews do not live only in the dark. They give interviews, publish “manifestos”, run Telegram channels, employ spokespeople. It is an industry with PR. And the way they talk about themselves is worth reading — not to believe them, but because, decoded, their self-justification is a mirror of exactly what you got wrong.
A warning up front: everything such a group says is unverifiable self-promotion. They lie, exaggerate, blame the victim, manage their image. We do not link to or amplify their channels. But precisely because it is propaganda, it is worth taking apart — underneath the bravado is a document about you.
The first lie: “we don’t attack”
The favourite positioning of some groups — RansomHouse is the classic example — is that they break into no one: they merely “find vulnerabilities” and “negotiate compensation” for their work. It is extortion rebranded as consulting. It sounds almost reasonable — until it meets reality: the same groups have taken hospitals offline and disrupted patient care. And when asked about the consequences, the answer is invariably the same: the victim is to blame — they did not invest enough, they preferred their own image over their defences.
Note the pattern, because you will see it again: first the denial, then shifting the blame onto the one who got hit. It is the same structure used by institutions that say “the data was not compromised” while the data turns up for sale — except here it is the attacker using it. The reflex matters, on both sides of the line.
What it accidentally confirms
Strip away the bravado and the emojis, and what remains is a security guide written by the wrong side.
“You get in where people think about money, not security.” Translated: organisations that cut corners on security end up paying for it. The entry vector is not sorcery — it is a reused password, an exposed management service, missing MFA, a deferred patch. DFIR reports have repeated it for years.
They stay inside for a long time. Groups brag about months — sometimes more — of undetected presence. Even if their numbers are bravado, the direction is confirmed by independent data: the median time from compromise to detection (annual reports such as Mandiant M-Trends) is measured in days and weeks, with a long tail of cases stretching into months. The conclusion for you: prevention is not enough; detection and response decide.
It is an industrialised business. The internal Conti leaks revealed departments for HR, development, negotiation, PR — an NGO of harm, with an org chart. And ransom payments have, in a single year, passed the one-billion-dollar mark (Chainalysis estimates). You are not the target of a personal vendetta; you are a row in a yield spreadsheet, and the filter is how unprepared you are.
They don’t always encrypt. The RansomHouse model is often data theft plus “name-and-shame”, with no encryption (behaviour documented by the independent platforms that track ransomware leaks). Which means: backups alone do not save you. If the leverage is publishing your data, restoring from copies does not erase the extortion. Data governance and segmentation matter as much as your recovery objective.
The part that stings: reputation
The most instructive thing an extortionist says is about reputation: money can be earned again; a destroyed reputation and years lost to lawsuits cannot. They say it as a threat. But it is, word for word, the argument your security team should be making in the budget meeting.
This is where the circle closes with the two breaches of this summer: the attacker knows reputation is the real currency. So does the citizen. The institution that, once hit, defends its image instead of its people inverts the very causality the extortionist exploits — and loses, in the end, both the image and the people.
Their advice, turned inside out
Asked what they would recommend to a company that has been hit, the same groups answer serenely: accept the facts, understand the mistakes your security team made, invest so it does not happen again. Erase the context and it is the audit checklist any honest consultant hands you.
That does not make them any less criminal. Behind “compensation for vulnerabilities” are hospitals shut down and people — including the elderly, who cannot reset their data — who pay the bill. No one should romanticise them. But read them: the lesson is not in the bravado, it is in the boring controls that, between the lines, they tell you themselves you skipped.
At Braincap we work on exactly the points the “attacker’s mind” calls weaknesses: a security audit for the entry vector, monitoring and response for the time they spend undetected, a penetration test to learn where someone would get in before someone else does. Get in touch.
Statements attributed to ransomware groups are unverifiable self-promotion and are treated as such; we do not link to or amplify these groups’ channels. The independent facts — detection time, extortion economics, modus operandi — come from reputable research sources (reports such as Mandiant M-Trends, Chainalysis, the internal Conti leaks, independent platforms that monitor ransomware leaks), not from the attackers’ own statements.
Frequently asked questions
Do ransomware groups really give interviews?
Yes. Many groups do deliberate PR — Telegram channels, "manifestos", spokespeople — and some have given interviews to journalists (LockBit is a well-known example). It is propaganda, to be read critically: everything they say is unverifiable self-promotion, meant to legitimise them and pressure victims. Useful not as a source of truth, but as a mirror of the patterns they exploit.
What is "double extortion" and why don't backups alone save me?
In double extortion, the attacker first steals the data, then encrypts it (or merely threatens to publish it). Some groups — RansomHouse is an example — often operate through data theft and "name-and-shame", sometimes with no encryption at all. The takeaway: if the leverage is publishing your data, restoring from backup does not stop the extortion. Data governance, segmentation and least-privilege access matter as much as your recovery objective.
What is the most common entry vector?
Not an exotic vulnerability, but poor hygiene: reused or exposed credentials, management services reachable from the internet, missing or weak MFA, deferred patches on exposed assets. DFIR reports have said it for years — the entry point is almost always a corner cut on security, not attacker "magic".