Disrupting Ransomware Infrastructure: A Collaborative Effort to Protect Critical Infrastructure
International law enforcement agencies have successfully dismantled the critical infrastructure used by the BlackSuit ransomware group, a successor to Royal ransomware, which has compromised over 450 known victims in the United States. The operation resulted in the seizure of servers, domains, and digital assets used to deploy ransomware, extort victims, and launder proceeds. The BlackSuit ransomware gang's targeting of U.S. critical infrastructure represents a serious threat to public safety. The collaborative effort involved law enforcement agencies from the United States, the United Kingdom, Germany, Ireland, Ukraine, Lithuania, France, and Canada.
Key Takeaways:
- The operation resulted in the seizure of servers, domains, and digital assets used to deploy ransomware, extort victims, and launder proceeds.
- The BlackSuit ransomware group has compromised over 450 known victims in the United States since 2022.
- The group has received more than $370 million in ransom payments, based on present-day valuations of cryptocurrency.
- The group used double-extortion tactics, encrypting victims' systems while threatening to leak stolen data to further coerce payment.
- The takedown was conducted under Operation Checkmate, a Europol Joint Cyber Action Task Force-coordinated initiative specifically targeting the Royal and BlackSuit ransomware groups.
- The investigation involved international law enforcement partners from the United Kingdom's National Crime Agency and Northwest Regional Organized Crime Unit, Germany's Landeskriminalamt Niedersachsen, Ireland's An Garda SÈ¡ochÈína-Garda National Cyber Crime Bureau, Ukraine's National Police of Ukraine-Cyberpolice Department, Lithuania's Criminal Police Bureau, France's Office Anti-Cybercriminalité, and Canada's Royal Canadian Mounted Police and Delta Police Department.
- The case is being prosecuted by the U.S. Attorney's Office for the Eastern District of Virginia, with collaboration from international partners.
Statistics:
- Over 450 known victims in the United States compromised by the BlackSuit ransomware group since 2022.
- More than $370 million in ransom payments received by the group, based on present-day valuations of cryptocurrency.
- 450+ victims in critical infrastructure sectors, including healthcare, education, public safety, energy, and government.
Sources:
- US Immigration and Customs Enforcement
- HSI Cyber Crimes Center
- U.S. Department of Justice National Security Division's National Security Cyber Section
- U.S. Attorney's Office for the Eastern District of Virginia
- IRS Criminal Investigation's Cyber Crimes Unit
- Europol
- UK's National Crime Agency and Northwest Regional Organized Crime Unit
- Germany's Landeskriminalamt Niedersachsen
- Ireland's An Garda SÈ¡ochÈína-Garda National Cyber Crime Bureau
- Ukraine's National Police of Ukraine-Cyberpolice Department
- Lithuania's Criminal Police Bureau
- France's Office Anti-Cybercriminalité
- Canada's Royal Canadian Mounted Police and Delta Police Department.