/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An international group of law enforcement agencies, including the US, the EU, and Japan, seizes the dark web portal used by the RagnarLocker ransomware group

An international group of law enforcement agencies have seized the dark web portal used by the notorious RagnarLocker ransomware group, TechCrunch has learned.

TechCrunch Carly Page

Context & Ripple Effects

The RagnarLocker action fits a continuing law-enforcement focus on the public-facing infrastructure ransomware groups use to pressure victims. Earlier, US and Bulgarian authorities had seized a NetWalker data-leak site, establishing a similar operational target.

The approach continued across other major groups: authorities later seized ALPHV’s leak-site infrastructure and disrupted LockBit’s domain network. RagnarLocker is therefore part of a broader multinational enforcement arc rather than an isolated portal seizure.

First-order effects

  • RagnarLocker loses control of a key dark-web channel used to present its operation and communicate its extortion threat, disrupting the group’s immediate public-facing activity.
  • The participating agencies gain a visible disruption point and can use the seized portal to signal the operation is under law-enforcement action.

Second-order effects

  • Victims and organizations facing RagnarLocker pressure may have a temporarily reduced risk of public exposure through that specific portal, though a portal seizure alone does not establish that stolen data or the wider operation has been eliminated.
  • Other ransomware groups have reason to treat their leak sites and related web infrastructure as more vulnerable to coordinated cross-border action, especially as later operations targeted LockBit’s domain network.

Third-order effects

  • Repeated seizures make ransomware infrastructure—not only individual operators—a more durable enforcement target, raising the operational cost of maintaining public extortion channels.
  • If agencies can sustain coordination across jurisdictions, ransomware groups may increasingly need to rebuild or decentralize their infrastructure; the corpus does not show that such disruptions permanently end the underlying groups.

The trend: Cross-border authorities are increasingly targeting the online infrastructure that makes ransomware extortion visible, scalable, and credible.