FBI brings down massive ransomware gang by “hacking the hackers”

TechSpot is about to celebrate its 25th anniversary. TechSpot means tech analysis and advice you can trust.

What just happened? In what could be described as beautifully ironic, a notorious ransomware-as-a-service (RaaS) gang has been brought down after the FBI infiltrated its systems, disrupted operations, and seized its sites. Or, as the Deputy US Attorney General put it, they “hacked the hackers.”

Speaking at a news conference, US Attorney General Merrick Garland, FBI Director Christopher Wray, and Deputy U.S. Attorney General Lisa Monaco announced that the government secretly infiltrated the Hive ransomware gang’s networks in July 2022 before launching a six-month monitoring operation.

During this infiltration, the government was able to steal more than 300 decryption keys from Hive and distribute them to victims who were under attack, preventing around $130 million in ransom payments, including $5 million from a Texas school district. The feds also distributed over 1,000 additional decryption keys to previous Hive victims.

The FBI used its access to Hive’s infrastructure to warn targets about impending attacks, giving them time to bolster their systems and prepare. Hive’s Tor payment and data leak sites were also seized.

As per Bleeping Computer, the FBI gained access to two dedicated servers and one virtual private server at a hosting provider in California that were leased using email addresses belonging to Hive members. In a coordinated move, Dutch police also gained access to two dedicated backup servers hosted in the Netherlands. Law enforcement confirmed that these servers acted as the main data leak site, negotiation site, and web panels for Hive and its affiliates.

As per the affidavit: “In addition to decryption keys, when the FBI examined the database found on Target Server 2, the FBI found records of Hive communications, malware file hash values, information on Hive’s 250 affiliates, and victim information consistent with the information it had previously obtained through the decryption key operation.”

An FBI message (above) on the seized Hive Tor website notes that many countries were involved in the co-ordinated takedown, including Germany, Canada, France, Lithuania, Netherlands, Norway, Portugal, Romania, Spain, Sweden, and the United Kingdom.

“Using lawful means, we hacked the hackers,” Monaco told reporters. “We turned the tables on Hive.”

Hive, which launched in June 2021, targeted more than 1,500 victims in 80 different countries throughout its existence. As with other RaaS organizations, it rented out the malware to other criminals for a cut of the ransom.

The gang had collected more than $100 million in ransomware payments, and while no arrests have been announced, a department official suggested that would soon change. Unlike other ransomware operators, Hive never stated any intent to avoid targeting hospitals or emergency services.

Masthead credit: Sebastiaan Stam

Read More
Randy Fetzer

Latest

How Does an LLC Work?

An LLC, or Limited Liability Company, combines the advantages of corporations and partnerships, providing personal liability protection for its members. This means your personal assets are shielded from business debts. Moreover, LLCs typically enjoy pass-through taxation, which simplifies how profits and losses are reported on personal tax returns. With flexibility in management structure, LLCs can

Wintermute Launches Armitage DeFi Vault Platform for Institutions

You are here: Home / Cryptocurrency News / Wintermute Launches Armitage DeFi Vault Platform for Institutions Wintermute has announced Armitage, a new DeFi vault curation business for professional investors and institutions. The algorithmic trading firm said the product will support risk management and yield generation in decentralized lending markets through on-chain, non-custodial vaults for users

What Is a Sole Proprietor Business?

A sole proprietor business is a straightforward structure where you’re the sole owner, and there’s no legal distinction between you and your business. This means you have complete control over operations and profits, but it additionally means you bear personal responsibility for any debts or liabilities. With minimal paperwork and simple tax management, it’s an

SUI Price Eyes $1.50 as Ramp Integration Boosts Bullish Momentum

You are here: Home / Cryptocurrency News / SUI Price Eyes $1.50 as Ramp Integration Boosts Bullish Momentum SUI price has gained momentum following Ramp’s announcement to support Sui-based USDC payments, driven by growing optimism around Sui’s expanding payment and utility ecosystem. Stablecoin payment integrations are becoming increasingly important for Layer-1 ecosystems as blockchain networks

Newsletter

Don't miss

How Does an LLC Work?

An LLC, or Limited Liability Company, combines the advantages of corporations and partnerships, providing personal liability protection for its members. This means your personal assets are shielded from business debts. Moreover, LLCs typically enjoy pass-through taxation, which simplifies how profits and losses are reported on personal tax returns. With flexibility in management structure, LLCs can

Wintermute Launches Armitage DeFi Vault Platform for Institutions

You are here: Home / Cryptocurrency News / Wintermute Launches Armitage DeFi Vault Platform for Institutions Wintermute has announced Armitage, a new DeFi vault curation business for professional investors and institutions. The algorithmic trading firm said the product will support risk management and yield generation in decentralized lending markets through on-chain, non-custodial vaults for users

What Is a Sole Proprietor Business?

A sole proprietor business is a straightforward structure where you’re the sole owner, and there’s no legal distinction between you and your business. This means you have complete control over operations and profits, but it additionally means you bear personal responsibility for any debts or liabilities. With minimal paperwork and simple tax management, it’s an

SUI Price Eyes $1.50 as Ramp Integration Boosts Bullish Momentum

You are here: Home / Cryptocurrency News / SUI Price Eyes $1.50 as Ramp Integration Boosts Bullish Momentum SUI price has gained momentum following Ramp’s announcement to support Sui-based USDC payments, driven by growing optimism around Sui’s expanding payment and utility ecosystem. Stablecoin payment integrations are becoming increasingly important for Layer-1 ecosystems as blockchain networks

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand