Don’t do SECURITY. Do business SECURELY.

FBI and European partners take down Hive ransomware network

The FBI revealed it had secretly infiltrated the Hive ransomware gang, giving decryption keys to victims before seizing its servers.

The US Justice Department announced that the FBI, working with German and Dutch authorities, had disrupted the Hive ransomware network. Investigators had secretly been inside Hive’s systems since July 2022.

What happened

  • Hive had targeted more than 1,500 victims worldwide, including hospitals and schools, and received over $100m in ransom payments.
  • The FBI provided decryption keys to more than 300 victims under attack and over 1,000 earlier victims.
  • Officials said this prevented around $130m in ransom payments.
  • Law enforcement then seized Hive’s websites and servers, displaying a seizure notice on its leak site.

Why it mattered

The operation showed a new approach to fighting ransomware, in which law enforcement quietly helped victims recover before shutting the group down. Hive had been one of the most active ransomware groups of 2022, operating a ransomware-as-a-service model in which affiliates carried out attacks.

Lessons for organisations

Organisations hit by ransomware should report it to law enforcement early, as agencies may hold decryption keys or intelligence. Reporting routes should be written into incident response plans. Strong backups and segmentation remain essential, because takedowns do not stop other groups.

Source: US Department of Justice

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights