An international group of law enforcement agencies, including the US, the EU, and Japan, seizes the dark web portal used by the RagnarLocker ransomware group
An international group of law enforcement agencies have seized the dark web portal used by the notorious RagnarLocker ransomware group, TechCrunch has learned.
Context & Ripple Effects
The RagnarLocker action fits a continuing law-enforcement focus on the public-facing infrastructure ransomware groups use to pressure victims. Earlier, US and Bulgarian authorities had seized a NetWalker data-leak site, establishing a similar operational target.
The approach continued across other major groups: authorities later seized ALPHV’s leak-site infrastructure and disrupted LockBit’s domain network. RagnarLocker is therefore part of a broader multinational enforcement arc rather than an isolated portal seizure.
First-order effects
- RagnarLocker loses control of a key dark-web channel used to present its operation and communicate its extortion threat, disrupting the group’s immediate public-facing activity.
- The participating agencies gain a visible disruption point and can use the seized portal to signal the operation is under law-enforcement action.
Second-order effects
- Victims and organizations facing RagnarLocker pressure may have a temporarily reduced risk of public exposure through that specific portal, though a portal seizure alone does not establish that stolen data or the wider operation has been eliminated.
- Other ransomware groups have reason to treat their leak sites and related web infrastructure as more vulnerable to coordinated cross-border action, especially as later operations targeted LockBit’s domain network.
Third-order effects
- Repeated seizures make ransomware infrastructure—not only individual operators—a more durable enforcement target, raising the operational cost of maintaining public extortion channels.
- If agencies can sustain coordination across jurisdictions, ransomware groups may increasingly need to rebuild or decentralize their infrastructure; the corpus does not show that such disruptions permanently end the underlying groups.
The trend: Cross-border authorities are increasingly targeting the online infrastructure that makes ransomware extortion visible, scalable, and credible.