LOGO

US Seizes $1 Million from Russian Ransomware Gang

August 11, 2025
US Seizes $1 Million from Russian Ransomware Gang

Justice Department Seizes Assets from Russian Ransomware Group

The U.S. Department of Justice revealed on Monday the seizure of servers and $1 million worth of bitcoin belonging to a prominent Russian ransomware organization responsible for the BlackSuit and Royal malware.

As detailed in a press statement, an international collaboration of law enforcement bodies – encompassing agencies from the U.S., Canada, Germany, Ireland, France, the U.K., and additional nations – executed the seizure of four servers and nine domains on July 24th.

Details of the Seizure

Alongside the server and domain confiscation, authorities also secured approximately $1 million in cryptocurrency assets.

BlackSuit and Royal represent distinct ransomware variants, but are attributed to a single Russian cybercriminal group. This group has been actively targeting vital infrastructure both within the United States and internationally.

Impact and Financial Gains

CISA reported last year that the BlackSuit ransomware group has collectively sought over $500 million USD in ransom payments, with a single demand reaching as high as $60 million.

Assistant Attorney General for National Security, John A. Eisenberg, emphasized the gravity of the situation, stating that the BlackSuit gang’s repeated attacks on U.S. critical infrastructure pose a significant risk to public safety.

Victims and Ransom Payments

Investigations led by ICE’s Homeland Security Investigations indicate that Royal and BlackSuit have affected over 450 victims across the U.S.

These compromised entities span crucial sectors, including healthcare, education, public safety, energy, and government.

Since 2022, the cybercriminals have amassed more than $370 million through ransom payments.

Recovery of Bitcoin

The recovered bitcoin was traced to an account held at a digital currency exchange. Funds within this account were initially frozen in January of the previous year.

Your input is valuable! We are continually striving to improve, and your feedback on TechCrunch’s coverage and events is greatly appreciated. Please complete this survey to share your thoughts and potentially win a prize!

#ransomware#russian hackers#cybercrime#us government#cryptocurrency seizure#ransomware attack