International Cooperation Takes Down Multi-Million Euro HIVE Ransomware Scheme

International Cooperation Takes Down Multi-Million Euro HIVE Ransomware Scheme

Law enforcement authorities from Germany, the Netherlands, and the US, supported by Europol, have dismantled the infrastructure of HIVE ransomware, a notorious cybercrime group responsible for encrypting the data and computer systems of large IT and oil companies in the EU and the USA. The international operation, which involved 13 countries, led to the identification of decryption keys that were shared with many victims, enabling them to regain access to their data without paying the cybercriminals. The HIVE associates executed the cyberattacks, while developers created, maintained and updated the HIVE ransomware. The cybercriminals used the double extortion model of “ransomware-as-a-service,” where they copied the data and encrypted the files, then demanded a ransom to decrypt the files and prevent the stolen data from being published on the Hive Leak Site. The group has targeted a range of businesses, government facilities, telecommunications, manufacturing, IT, healthcare, and public health since June 2021, with victims in over 80 countries worldwide losing almost EUR 100 million in ransom payments.

The successful operation prevented the payment of more than USD 130 million or the equivalent of about EUR 120 million of ransom payments, and Europol played a key role in facilitating information exchange, coordinating the operation, and funding operational meetings in Portugal and the Netherlands. Europol also provided analytical support, linked available data to various criminal cases within and outside the EU, and supported the investigation through cryptocurrency, malware, decryption, and forensic analysis. The Joint Cybercrime Action Taskforce (J-CAT) at Europol, consisting of cybercrime liaison officers from different countries, worked on high-profile cybercrime investigations and supported the operation.

Recommended Posts

No comment yet, add your voice below!


Add a Comment

Your email address will not be published. Required fields are marked *