'Dumbass' criminal breaks the 'first rule of ransomware club'
A ransomware affiliate hit a company in Uzbekistan, triggering an apology, a ban, and a promise of free recovery help.
Intelligence analysis by GPT-5.4 Mini

Nova, the affiliate program for RAlord, apologized to Eriell Group after one of its affiliates infected the company, which has headquarters in Uzbekistan and an office in Moscow. The gang said the affiliate was banned, no files were encrypted, and it would help recovery for free.
A thief broke the gang’s own rule and stole from the wrong neighborhood, so the gang kicked the thief out and said sorry. It is like a school club having a rule about not messing with certain classmates, and one member breaking it by accident.
Analysis
What happened
The Register reports that Nova, the affiliate program for the ransomware crew RAlord, issued an apology on Tuesday to Eriell Group after one of its affiliates made what threat hunter Dominic Alvieri called the “dumbass of the day” mistake: infecting a company based in Uzbekistan, with a corporate office in Moscow.
According to the article, Eriell contacted Nova to report the problem. Nova then said the affiliate had been banned from the criminal operation and issued what it called a formal apology. The group also claimed it would help Eriell with recovery free of charge.
Why the target mattered
The piece says the incident violated a long-standing ransomware norm: avoid organizations in the Commonwealth of Independent States. Allan Liska of Recorded Future said that rule is still very much in effect in 2026. The reason, as the article explains, is that while cybercrime is illegal in Russia and other CIS countries, authorities in the region often tolerate extortionists unless they hit local organizations. The article also notes that some ransomware crews explicitly forbid attacks on CIS targets.
Broader context
The story uses this case as one example of criminals making mistakes that undercut their own operations. It cites other incidents where threat actors slipped up, including groups that fell into honeypots or made coding errors that weakened their malware. The article also quotes Trellix’s John Fokker, who said his team started publishing the Dark Web Roast because they were tired of the security industry “glorifying threat actors.” His point was that these actors are just people using computers to steal data and money, not mythical supervillains.
What is known and unknown
The article says the malware group claimed it did not encrypt any files and promised not to leak stolen data. That is the gang’s statement, not an independently verified outcome. The reporting does not say whether Eriell suffered lasting data loss or whether the promise will hold.
Key points
- Nova apologized to Eriell Group after an affiliate infected the company, which is based in Uzbekistan and has an office in Moscow.
- The ransomware affiliate was banned from the operation, according to the article.
- Nova claimed no files were encrypted and promised free recovery help and no data leak.
- The story says ransomware crews often avoid CIS targets because local authorities may tolerate cybercriminals unless local organizations are hit.
- The article frames the incident as another example of criminals making basic operational mistakes.
If the group’s claims are true, Eriell may avoid file encryption and a public leak, which would limit damage. The affiliate’s ban could also reduce the chance of a repeat mistake against another CIS organization.
The apology and promise are coming from the criminals themselves, so there is no guarantee they will hold. Even without encryption, stolen data could still be misused, and the incident shows how quickly a single sloppy affiliate can create real harm.



