The US Justice Department announced that the FBI, working with German and Dutch authorities, had disrupted the Hive ransomware network. Investigators had secretly been inside Hive’s systems since July 2022.
What happened
- Hive had targeted more than 1,500 victims worldwide, including hospitals and schools, and received over $100m in ransom payments.
- The FBI provided decryption keys to more than 300 victims under attack and over 1,000 earlier victims.
- Officials said this prevented around $130m in ransom payments.
- Law enforcement then seized Hive’s websites and servers, displaying a seizure notice on its leak site.
Why it mattered
The operation showed a new approach to fighting ransomware, in which law enforcement quietly helped victims recover before shutting the group down. Hive had been one of the most active ransomware groups of 2022, operating a ransomware-as-a-service model in which affiliates carried out attacks.
Lessons for organisations
Organisations hit by ransomware should report it to law enforcement early, as agencies may hold decryption keys or intelligence. Reporting routes should be written into incident response plans. Strong backups and segmentation remain essential, because takedowns do not stop other groups.
Source: US Department of Justice
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.