The myth of a cybercriminal moral code

Office workers at night time

When news broke recently of a UK cyber attack in which an cyber group threatened to put children at risk, the shock was not only in the technical breach but in the blatant disregard for human impact. This sits in stark contrast with certain ransomware groups who publicly insist they follow a “moral code,” claiming not to attack organisations such as hospitals, schools, or non-profits.

If your business has experienced a suspected cyber incident and you’re in urgent need of support, get in touch with the team at Zensec immediately. 

So, is there really such a thing as ethics in cyber crime? Or are these just marketing ploys within a dark economy? To answer, it helps to explore the spectrum of cyber criminality, from chaotic opportunists to highly structured criminal enterprises.

From the basement to the “boardroom”

Opportunistic lone actors
At one end of the spectrum are the so-called “basement hackers.” Often individuals or small crews, they strike opportunistically, using cheap tools or stolen code. Targets are random: anyone who clicks the wrong link or leaves a server open is fair game. Their operations are messy and their attacks scattershot.

Mid-tier groups
Further along are more organised gangs. They might specialise in stealing credentials, running phishing campaigns, or selling initial access to larger gangs. While still opportunistic, they have some structure, some repeatable playbooks, and often carve out a niche in the underground market.

Enterprise-scale syndicates
At the far end sit ransomware cartels that resemble corporations more than street gangs. They run like businesses: developers write malware, negotiators handle “customer service,” and recruiters entice affiliates. Some even operate with HR-like processes, offering “salaries” or commissions. For these groups, brand reputation matters and this is where the myth of a moral code often appears.

The so-called “moral code”

Take RansomHub, which claims not to target non-profits or repeat victims. Or RansomHouse, which styles itself as a “force for good,” arguing that its leaks expose weak security. Such statements echo corporate PR, painting criminals as disciplined actors who are principled in their choice of victims.

But these claims should be treated with extreme caution. Law enforcement and national cyber agencies repeatedly warn that ransomware groups cannot be trusted. A gang that spares one type of victim may still devastate another and nothing stops them breaking their own rules when it suits.

Why criminals make these claims

If the rules aren’t reliable, why do groups bother with them? There are three main reasons:

  1. Reputation with affiliates – Larger groups rely on a network of partners to spread their malware. A “brand” that seems disciplined can attract more affiliates.
  2. Negotiation leverage – Telling victims they are “reasonable” can encourage payment, as victims may believe they’re dealing with criminals who will keep their word.
  3. Reduced law-enforcement heat – By avoiding hospitals or schools, groups hope to draw less political outrage and therefore fewer resources against them.

In other words, the moral code isn’t so much about morals as it is self-serving. It’s propaganda designed to support a criminal business model.

A hierarchy without ethics

It is tempting to see a hierarchy of morality in the cyber underworld: at the bottom, reckless loners attacking anyone; at the top, disciplined cartels sparing certain institutions. In reality, the hierarchy is about scale and professionalism, not ethics.

The recent UK case threatening to expose children shows just how hollow the idea of cyber criminal “morality” is. Where one group claims restraint, another shows none at all. And at the end of the day, even the most “disciplined” syndicate causes devastating harm to businesses, staff, and communities.

What organisations should remember

  • All groups are criminal. No claim of restraint should influence risk assessments or incident response.
  • Trust official guidance, not criminal promises. The UK’s National Cyber Security Centre (NCSC) and law enforcement provide reliable advice; ransomware groups do not.
  • Scale matters for defenders. Larger, more organised groups may be more sophisticated and persistent, requiring stronger defences but smaller opportunists can be just as damaging if ignored.

Final thoughts

There is no moral code in cyber crime only the illusion of one. For the gangs, it’s branding. For the rest of society, it’s a reminder that the threat landscape spans from reckless opportunists to business-like cartels.

Understanding these narratives helps us to strip away the myth and focus on what matters: building resilience, preparing for incidents, and remembering that when criminals claim ethics, it’s only ever in service of their own profit.

Don’t wait until a cyber criminal decides your organisation is an easy target. Our cyber experts work with businesses to identify vulnerabilities, implement preventative strategies, and defend against ransomware attacks – get in touch today to strengthen your cyber resilience.

Update: The shifting “morality” of cybercriminals

Since publishing this post, a further development has emerged, underlining how ransomware groups manage their image. Following significant public backlash, the group responsible for the nursery attack have removed the data from their leak site stating “We are sorry for hurting kids,” the cyber-criminals told BBC News.

But lets be clear, this doesn’t reflect genuine morality, it reflects brand protection. For these groups, being seen to cross an “invisible line” can:

  • Damage their reputation in the underground economy
  • Impact their ability to recruit affiliates
  • Erode the so-called “trust” that underpins their criminal business model.

In other words, even when they appear to backtrack, it’s not about ethics. It’s about preserving credibility and ensuring their brand continues to function in the criminal marketplace.

This development reinforces the point: cybercriminals’ claims of a moral code are not rooted in principle, but in self-interest.

References