US and Bulgarian authorities seize a dark web site used to publish data stolen from victims of NetWalker, which has been among the most rapacious ransomware
U.S. and Bulgarian authorities this week seized the darkweb site used by the NetWalker ransomware cybercrime group to publish data stolen from its victims.
Context & Ripple Effects
NetWalker had spent 2020 establishing itself as a top-tier ransomware-as-a-service operation, with a McAfee report crediting its operators with roughly $25M in ransom payments since March — putting it alongside Ryuk, Dharma, and REvil. The group's double-extortion model depended on this leak site: publish stolen victim data there, and the threat of exposure does the negotiating.
Seizing that publication infrastructure, rather than chasing individual affiliates, is the move U.S. and Bulgarian authorities made here — a template that law enforcement would go on to repeat against RagnarLocker's portal in an international action two years later and against ALPHV's leak site in late 2023.
First-order effects
- NetWalker loses its primary extortion lever mid-campaign: without a working leak site, the group cannot credibly threaten to publish stolen data, weakening negotiations with current victims.
- Victims whose data was staged for publication get a reprieve from exposure on that venue, though the stolen data itself remains in criminal hands.
Second-order effects
- Affiliates renting NetWalker's tooling face downtime and reputational risk, giving them reason to migrate their attacks to rival ransomware brands — the same affiliate churn later visible when hackers dumped LockBit's internal panels and victim chats.
- The seizure validates infrastructure takedowns as a repeatable play, encouraging more multi-country operations like the ones that hit RagnarLocker and ALPHV's sites.
Third-order effects
- If the pattern holds, ransomware groups are pushed toward faster infrastructure rotation and rebranding cycles, raising their operating costs while prosecutions catch up — as with the NetWalker affiliate who received a 20-year prison sentence.
- Leak-site seizures normalize cross-border cyber cooperation between the U.S. and partners like Bulgaria, making joint takedowns a standing feature of ransomware response rather than exceptional events.
The trend: Law enforcement is shifting from arresting individual ransomware actors to seizing the leak-site infrastructure that makes double-extortion profitable, one brand at a time.