/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

The FBI, the UK, Denmark, Germany, Spain, and Australia seize ransomware gang ALPHV's dark web leak website; the US also seized “several websites” run by ALPHV

An international group of law enforcement agencies have seized the dark web leak site of the notorious ransomware gang known as ALPHV, or BlackCat.

TechCrunch Carly Page

Context & Ripple Effects

This operation extends a run of cross-border ransomware takedowns: agencies previously seized Hive’s website and obtained decryption keys, then moved against RagnarLocker’s portal in a separate international portal seizure.

It matters because ALPHV’s leak site was part of the public-pressure mechanism behind ransomware extortion. The action shows the same multinational model being applied to another major operation’s visible infrastructure.

First-order effects

  • ALPHV loses a public channel used to expose or threaten to expose victim data, while the US seizure of additional sites further interrupts its web presence.
  • Victims facing ALPHV-related extortion may get temporary relief from the immediate threat of publication through the seized leak site.

Second-order effects

  • Other ransomware operators are likely to treat publicly reachable leak portals as more exposed infrastructure and shift or duplicate those services, raising their operational overhead.
  • The participating agencies gain another practical template for coordinated infrastructure seizures, building on the Hive disruption that also yielded decryption keys.

Third-order effects

  • If repeated, these actions can make ransomware operations more dependent on replaceable, distributed infrastructure rather than stable public-facing brands and portals.
  • The pattern favors persistent multinational disruption over one-off arrests: seizures can constrain extortion operations, but their durability depends on whether investigators can continue reaching operators and their replacement infrastructure.

The trend: Ransomware enforcement is increasingly targeting the infrastructure that enables extortion and publicity through recurring cross-border operations.

Discussion

  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    Justice Department and Europol confirm their involvement in the operation.  —  According to the government's search warrant, the FBI said it engaged with a “confidential human source” close to the ransomware gang, who provided agents with credentials to access ALPHV/BlackCat's af…
  • @vxunderground @vxunderground on x
    ALPHV ransomware group administrative group has contacted us to inform us they have moved their servers and blogs. *Image translated from Russian to English [image]
  • @vxunderground @vxunderground on x
    ALPHV ransomware groups website has been seized Information via @AlvieriD [image]
  • @azalsecurity @azalsecurity on x
    After today's FBI seizure and release of the decryptor key, ALPHV/Blackcat is offering a 10% profit sharing (below their normal) to attract affiliates. Looks like the ship is sinking and sending out the distress calls, while of course the rats are fleeing. RIP ALPHV! [image]
  • @uuallan @uuallan on x
    Love this! Giving victims options so they don't have to pay! Justice Department Disrupts Prolific ALPHV/Blackcat Ransomware Variant https://www.justice.gov/...
  • @sosintel @sosintel on x
    ALPHV / Blackcat blog is still up. If their Onion got Seized, it's their old(original alphvmmm27) onion. [image]
  • @dojcrimdiv @dojcrimdiv on x
    Justice Department Disrupts Prolific ALPHV/Blackcat Ransomware Variant FBI Offers Decryption Tool to Over 500 Victims Around the World, Additional Victims Encouraged to Come Forward https://www.justice.gov/... [image]
  • @bushidotoken Will on x
    🎯 FBI disrupted the BlackCat / ALPHV ransomware gang! -FBI's decryption tool helped over 500 victims ⛑️ -It stopped victims paying ransoms and cost BlackCat approximately $68 million 💪 -They gained access to their servers and seized several websites ⚠️ https://www.justice.gov/...…