/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

REvil's infrastructure and websites are offline, including its data leak sites, less than two weeks after attacking 1,500+ businesses with ransomware via Kaseya

The infrastructure and websites for the REvil ransomware operation have mysteriously gone offline as of last night.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

The outage follows REvil's use of a Kaseya software update to compromise managed service providers, a distribution path that exposed thousands of downstream customer environments. REvil subsequently claimed a $70 million decryptor demand, making the availability of its leak and payment-facing infrastructure central to the pressure campaign.

Later coverage shows the shutdown was not a clean endpoint: REvil's site became reachable again before reports of a multi-country operation that forced the group offline. The sequence matters because it distinguishes disruption of a ransomware operation's public infrastructure from permanent removal of its capability.

First-order effects

  • REvil immediately loses its public data-leak and web infrastructure, interrupting the channels used to publish stolen data and sustain pressure on Kaseya-related victims.
  • Kaseya and affected companies can continue recovery through Kaseya's stated universal decryptor rather than relying on contact with REvil's now-unavailable sites.

Second-order effects

  • The outage reduces the immediacy of REvil's public leak threat for affected businesses, while forcing incident-response teams to rely on Kaseya's recovery process and their own restoration work.
  • The later reappearance of REvil's site means law-enforcement and security teams must treat infrastructure seizures or outages as operational disruptions, not proof that a ransomware group has been eliminated.

Third-order effects

  • The REvil sequence points to ransomware infrastructure as a recurring enforcement target: disrupting payment and leak-site operations can constrain a gang even when its underlying operators may reconstitute services.
  • If multi-country operations increasingly target these services, ransomware groups will face pressure to make their infrastructure more resilient, turning takedowns into an ongoing contest rather than a one-time remedy.

The trend: Ransomware enforcement is increasingly focused on repeatedly disrupting the online infrastructure that turns an intrusion into an extortion business.

Discussion

  • @lawrenceabrams Lawrence Abrams on x
    All REvil sites are down, including the payment sites and data leak site. 🤔 The public ransomware gang represenative, Unknown, is strangely quiet.
  • @zackwhittaker Zack Whittaker on x
    REvil status report: ✅ Nobody knows why it disappeared https://twitter.com/...
  • @vxunderground Vx-Underground on x
    @LawrenceAbrams REvil representative, Unknown, has not said anything on Exploit or XSS since July 8th.
  • @howelloneill Patrick Howell O'Neill on x
    Now that one of the most prolific ransomware gangs of all time is suddenly off the internet, cautiously optimistic experts urge everyone to avoid jumping to conclusions. It's too early to know what's going on. But the timing is impossible to ignore. https://www.technologyreview.c…
  • @techreview @techreview on x
    The ransomware crew known as REvil has existed for years in the booming cybercrime underground. A whopping 42% of all recent ransomware attacks trace back to this gang that suddenly disappeared from the internet Tuesday morning. https://www.technologyreview.com/ ...
  • @jenniferjjacobs Jennifer Jacobs on x
    “I don't have anything further to share on that,” Deputy Press Secretary Karine Jean-Pierre says when asked about REvil's sites suddenly going dark. The Russian ransomware gang was behind hack of JBS beef producers, etc. Unclear if US govt or Putin took them out, or not. https://…
  • @techreview @techreview on x
    New: The shutdown comes one day before US and Russian officials meet to talk about the ransomware crisis. https://www.technologyreview.com/ ...
  • @campuscodi Catalin Cimpanu on x
    Yep. This looks like REvil either went on vacation, they plan to rebrand, or the takedown wasn't particularly legal (if you know what I mean). https://twitter.com/...
  • @kevincollier Kevin Collier on x
    It's early, but REvil is down. Maybe for the count. With no further context, this could mean almost anything: they bit off more than they could chew and are laying low after their big campaign after the 4th, they were pwned by @US_CYBERCOM, the FSB finally shut them down. https:/…
  • @pwnallthethings @pwnallthethings on x
    Your computer have been infected! Your documents, photos, databases and other files encrypted To decrypt your files you need our special software You can do it right now. Follow instructions below CYBERCOM-Decryptor price: > surrender at US embassy https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    LOL... their sites were live and working right before this tweet. I went there to look at the Hx5 leak. Am I the last person who accessed their site? 😅 https://twitter.com/...