An FBI-developed decryption tool for the ALPHV/Blackcat ransomware is being offered to more than 500 victims around the world, allowing them to restore their systems.
The FBI tracked the ALPHV/Blackcat operations for months, collecting decryption keys along the way and seizing several websites the group operated. The tool that was subsequently developed has, to date, saved multiple victims approximately $68 million in ransom demands from the gang which, over the past 18 months, has emerged as the second most prolific ransomware-as-a-service in the world.
To reach this level, the gang has demanded more than US$500 million in ransom payments and receiving nearly $300 million from 1,000+ victims, such as government facilities, emergency services, schools, defence industrial base companies, critical manufacturing, healthcare and public health facilities. The losses include not only ransom payments, but destruction and theft of proprietary data, and costs associated with incident response.
“In disrupting the BlackCat ransomware group, the Justice Department has once again hacked the hackers,” said Deputy Attorney General Lisa O. Monaco. "Businesses and schools were able to reopen, and health care and emergency services were able to come back online."
The ALPHV/Blackcat gang isn't new on the scene. The FBI stated in April, 2022, that several developers and money launderers for BlackCat had links to two defunct ransomware groups, one being DarkSide, which gained infamy following its attack on Colonial Pipeline.




