U.s. Government Seized $1 Million From Russian Ransomware Gang

Trending 4 weeks ago
Bitcoin coins cryptocurrency connected U.S. dollar banknotes background.Image Credits:alexsl / Getty Images

12:04 PM PDT · August 11, 2025

The U.S. Department of Justice announced connected Monday it has seized nan servers and $1 cardinal successful Bitcoin from nan prolific Russian ransomware pack down nan BlackSuit and Royal malware. 

According to nan property release, a conjugation of world rule enforcement agencies, including from nan U.S., Canada, Germany, Ireland, France, U.K., and others, seized 4 servers and 9 domains connected July 24. In addition, authorities besides seized astir $1 cardinal successful cryptocurrency. 

BlackSuit and Royal are 2 different types of ransomware, believed to beryllium developed by nan aforesaid Russian cybercriminal pack that has targeted captious infrastructure successful nan United States and beyond. 

“BlackSuit actors person demanded complete $500 cardinal USD successful full and nan largest individual ransom request was $60 million,” nan U.S. cybersecurity agency CISA said successful an advisory past year. 

“The BlackSuit ransomware gang’s persistent targeting of U.S. captious infrastructure represents a superior threat to U.S. nationalist safety,” Assistant Attorney General for National Security John A. Eisenberg said successful nan property release. 

According to ICE’s Homeland Security Investigations, which led nan investigation, Royal and BlackSuit person compromised much than 450 victims successful nan U.S., “including entities successful nan healthcare, education, nationalist safety, power and authorities sectors.” And, successful total, nan cybercriminals person earned much than $370 cardinal successful ransom payments since 2022. 

The recovered bitcoin was recovered from a integer rate speech account, whose costs were stiff successful January of past year, according to nan announcement. 

Techcrunch event

San Francisco | October 27-29, 2025

Topics

Bitcoin, BlackSuit, CISA, cybercrime, hackers, ICE, infosec, law enforcement, ransomware, Royal, Security, TC

Lorenzo Franceschi-Bicchierai is simply a Senior Writer astatine TechCrunch, wherever he covers hacking, cybersecurity, surveillance, and privacy.

You tin interaction aliases verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted connection astatine +1 917 257 1382 connected Signal, and @lorenzofb connected Keybase/Telegram.

More