Two ransomware gangs are at war right now, and one of them just offered to hand a rival’s victims their data back.
If that sounds like good news, I get it. Watching criminals turn on each other feels like it should work in your favor.
It doesn’t. Not if your firm is the one whose client files ended up in the middle of it.
0APT vs. Krybit, in plain English
In April 2026, a group calling itself 0APT threatened a rival ransomware operation known as Krybit. According to reporting from The Register and TechRadar, 0APT said that if Krybit didn’t pay up or reach out, 0APT would publish the names, photos, and locations of the people behind it. Then 0APT told Krybit’s own victims to contact 0APT directly to get their files unlocked.
This is a version of double extortion, the tactic where a gang encrypts your files and threatens to leak them too, so paying feels like the only way out. That threat works on a firm because a firm has a reputation and a client base to protect. It doesn’t work the same way on a rival criminal group. Krybit has no legitimate reputation to lose, and cybersecurity researchers have noted that this tactic loses much of its sting once the target is another gang instead of a paying victim.
0APT pressed ahead anyway, releasing a sample of Krybit’s stolen data as a warning shot. A researcher at Barricade Cyber Solutions in South Carolina examined that sample and found plaintext login credentials belonging to Krybit’s own operators, along with five cryptocurrency wallet addresses. The same review turned up no record of any victim ever paying Krybit a ransom, which suggests Krybit’s own success claims may have been overstated. Krybit’s site is offline now, replaced by an apology message.
Gangs turning on each other isn’t new. In 2025, a group called DragonForce defaced two rival operations, BlackLock and Mamona, and leaked their internal communications. DragonForce also took over the ransomware brand RansomHub and shut it down after a month of infighting in April 2025.
Your confidentiality duty didn’t take the week off
Here’s the part that matters for your firm. If Krybit had hit you, and your matter files were somewhere in that stolen data, 0APT’s offer might look tempting. Someone claiming they can unlock your files for free, instead of the ransom you were already dreading? Of course that’s tempting.
Think about what you’d actually be doing. It’s the same as if the person who stole your file cabinet called offering to sell your client files back, while a second burglar threatened to publish the first one’s name and address unless he paid up. You don’t want either one anywhere near your files, and calling either of them doesn’t change what’s already been taken.
It’s the duty of confidentiality that’s on the line here, the one framed under ABA Model Rule 1.6(c) as reasonable efforts to prevent unauthorized disclosure of client information. California firms carry a comparable duty through Business and Professions Code section 6068(e), Rule 1.1’s competence standard, and Formal Opinion 2010-179, even though the rule structure runs differently. Reasonable efforts doesn’t mean perfect. It means not making a bad situation worse by handing a second criminal actor more access to data you already lost to a first one.
None of this stays theoretical for long. A cyber insurance renewal will ask what your firm’s incident response actually looked like, and “we called the rival gang that offered to help” is not the answer an underwriter wants to see. Opposing counsel in an active matter would have a field day with it too, if it ever surfaced that your response to a breach was contacting an unverified criminal group instead of following your incident response plan.
What your firm should do instead
If ransomware hits your firm, and anyone outside your incident response plan offers to help, don’t engage. Preserve your firewall logs and network traffic data instead. That’s the evidence your forensics team, your breach counsel, and your insurer will need to determine what was actually accessed and whose matters were touched.
The bigger lesson isn’t really about 0APT and Krybit. It’s what this feud shows about the ransomware world generally: unstable, unpredictable, and full of people who lie to each other as easily as they lie to you. None of that instability lowers your firm’s exposure. Tested, immutable backups, monitoring that catches unusual activity early, and a response plan that already accounts for your confidentiality duty, that’s what does.
Back to where this started. Could you tell a client what happened to their file without relying on a rival criminal gang’s word for it? If the honest answer is no, that’s the gap worth closing before a regulator, insurer, client, or opposing counsel is the one asking. We help firms map where client data lives, document what an incident actually touched, and have the answers ready before that happens.


