Cointime

Download App
iOS & Android

DOJ Disrupts Ransomware Group Attempting to Extort $130M in Crypto Ransom

The DOJ stated that it conducted the operation with the help of German law enforcement (the German Federal Criminal Police and Reutlingen Police Headquarters-CID Esslingen) and the Netherlands National High Tech Crime Unit.

Over $100M Extorted From 1,500 Victims

The department said that since June 2021, the group has targeted more than 1,500 victims worldwide and received over $100 million in crypto ransom payments.

According to the DOJ, the Federal Bureau of Investigation (FBI) executed a months-long disruption campaign against the group and infiltrated Hive’s network in July 2022. The Justice Department added that after successfully infiltrating the group’s network, it captured their decryption keys and offered them to victims worldwide, preventing them from paying the $130 million in crypto ransom demanded.

“Since infiltrating Hive’s network in July 2022, the FBI has provided over 300 decryption keys to Hive victims who were under attack. In addition, the FBI distributed over 1,000 additional decryption keys to previous Hive victims,” the DOJ said.

A Subscription-Based Model

Ransomware is malicious software (malware) that threatens to publish or block access to a victim’s personal data (usually by encrypting it) unless a ransom is paid off.

According to the DOJ, Hive used a subscription-based model called ransomware-as-a-service (RaaS) to “develop a ransomware strain and create an easy-to-use interface with which to operate it and then recruit affiliates to deploy the ransomware against victims.”

“Affiliates identified targets and deployed this readymade malicious software to attack victims and then earned a percentage of each successful ransom payment,” the department added.

Meanwhile, the DOJ announcement comes as revenue from ransomware has significantly reduced. According to a recent report by blockchain analytics firm Chainalysis, ransomware attackers extorted approximately $456.8 million from victims in 2022, down from $765.6 million the year prior.

However, that does not mean ransomware attacks have reduced, or at least not as much as the decline in payments suggests. Instead, “much of the decline is due to victim organisations increasingly refusing to pay ransomware attackers,” the report said.

~ By William A. Frederick ~

Comments

All Comments

Recommended for you

  • BTC Surpasses $67,000

    Market data shows that BTC has surpassed $67,000, currently priced at $67,007.8, with a 24-hour decline of 2.04%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $67,000

    Market data shows that BTC has surpassed $67,000, currently priced at $67,015.44, with a 24-hour decline of 1.94%. The market is highly volatile, so please ensure proper risk management.

  • U.S. Initial Jobless Claims at 202,000 Last Week

    On April 2, the number of initial jobless claims in the U.S. last week was 202,000, estimated at 212,000, with a previous value of 210,000.

  • BTC Falls Below $66,000

    Market data shows that BTC has fallen below $66,000, currently priced at $65,999, with a 24-hour decline of 3.86%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Iran: Enemy Forces Will Be Annihilated in Ground Attack

    On April 2, Iranian Army Chief of Staff Hatami warned that if enemy forces attempt a ground invasion, no enemy soldiers will survive. He urged the military to maintain the highest level of vigilance and skepticism, constantly monitoring enemy movements and actions, and to implement operational plans to counter any enemy attacks at the appropriate time. (CCTV International News)

  • Metaplanet Acquires 5,075 BTC in Q1, Total Holdings Reach 40,177 BTC

    On April 2, Metaplanet CEO Simon Gerovich announced that in the first quarter of 2026, the company purchased 5,075 BTC at an average price of approximately $79,898, with a total investment of around $405.48 million. The year-to-date return on Bitcoin is 2.8%. As of March 31, the company has accumulated a total of 40,177 BTC, with a total cost of approximately $4.18 billion and an average cost of about $104,106.

  • BTC Falls Below $67,000

    Market data shows that BTC has fallen below $67,000, currently reported at $66,960.01, with a 24-hour decline of 1.21%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Drops Below $2100

    Market data shows that ETH has dropped below $2100, currently priced at $2099.91, with a 24-hour decline of 0.04%. The market is highly volatile, so please ensure proper risk management.

  • BTC Falls Below $68,000

    Market data shows that BTC has fallen below $68,000, currently priced at $67,997.84, with a 24-hour decline of 0.37%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Drift Protocol on Solana Ecosystem Attacked, Losses Estimated at Over $200 Million

    On April 2, the derivative trading platform Drift Protocol, based on Solana, experienced a security incident. On-chain data indicates losses of at least approximately $200 million, with some estimates nearing $270 million. The project team reported that they have detected unusual activity and are currently investigating, advising users not to deposit funds into the protocol and emphasizing that 'this is not an April Fool's joke.' The attack involved multiple liquidity pools, including JLP Delta Neutral, SOL Super Staking, and BTC Super Staking. A single transaction involved the transfer of approximately 41.7 million JLP tokens, valued at around $155 million, along with other assets such as SOL, USDC, cbBTC, and wBTC being withdrawn. According to statistics, this incident may become one of the largest DeFi attacks in the Solana ecosystem since the Wormhole bridge exploit.