Cyber Crimes Center, a division of the US DHS, says it has disrupted 500+ ransomware attacks and seized $4.3B in crypto since 2021, including $180M last year
Jeff Stone / Bloomberg :
Context & Ripple Effects
The disclosure adds an enforcement-side measure to a ransomware economy that had already drawn unusually large suspicious-activity reports. Treasury had flagged $590 million in suspected ransomware-related activity in the first half of 2021, while FinCEN later said financial firms processed about $1.2 billion in likely ransomware payments in 2021.
It matters because it makes DHS's Cyber Crimes Center a visible part of the response alongside financial-sector reporting: disruption and crypto seizures target the operational and financial infrastructure around attacks, not only the incident reports that follow them.
First-order effects
- Ransomware operations affected by the center's interventions face immediate interruption, while seized cryptocurrency is removed from the control of the parties from whom it was taken.
- DHS gains a cumulative public record for the Cyber Crimes Center's role in ransomware response, strengthening the center's case for continued operational attention.
Second-order effects
- Financial institutions and crypto-service providers face added pressure to detect and trace flows that may support ransomware, since their reporting can complement government disruption efforts.
- Attackers may need to absorb greater risk around moving or retaining crypto proceeds when law-enforcement interventions can affect both attacks and assets.
Third-order effects
- If disruption and asset seizure become a durable complement to reporting, ransomware defense will increasingly span victims, financial intermediaries, crypto tracing, and federal operational teams rather than incident response alone.
- The long-term test is whether these interventions consistently reduce attackers' ability to monetize attacks; the reported totals show enforcement activity, not by themselves a measure of ransomware's overall decline.
The trend: Ransomware policy is shifting from documenting illicit payments toward disrupting attacks and constraining the crypto-based financial rails behind them.