US announces anti-ransomware measures, including rewards of up to $10M for information about foreign state-sanctioned hackers targeting critical infrastructure
BOSTON (AP) — The State Department will offer rewards up to $10 million for information leading to the identification …
That framing matters because ransomware had escalated from criminal nuisance to national-security problem, prompting Washington to build a multi-pronged response spanning diplomacy, sanctions, and law enforcement. This reward slots into that effort as its intelligence-gathering arm.
First-order effects
Researchers, insiders, and rival intelligence services now have a paid channel — up to $10M per tip — to identify state-backed operatives inside critical-infrastructure intrusions, raising the odds that named individuals surface rather than anonymous units.
Foreign governments sponsoring such attacks lose deniability at the margin: every credible tip converts a covert operator into a sanctioned, chargeable target.
Second-order effects
The bounty works alongside the administration's other levers — the White House ransomware summit where 32 countries pledged information-sharing and disruption of hackers' financial tools, and preparation of sanctions on crypto wallets and exchanges to choke payments — making identification the trigger for financial isolation.
Ransomware crews affiliated with or tolerated by states face higher operating costs: infrastructure they rely on (exchanges, hosting) becomes sanctionable once a reward-funded tip attaches their name.
Third-order effects
If the trajectory holds, cyber bounties harden into a standing countermeasure: the same template was later applied to Babuk suspect Mikhail Matveev (charges, sanctions, and another $10M reward), suggesting individual attribution plus financial punishment is becoming the default US playbook against ransomware ecosystems.
For critical infrastructure operators, the practical shift is toward shared attribution — government-paid informants feeding the same intel pipelines that multilateral pledges committed allies to populate.
The trend: US counter-ransomware policy is converging on paid human intelligence plus financial disruption, turning individual hacker identification into the entry point for multilateral sanctions.
I've been impressed by the Administration's steps to address ransomware, starting with @POTUS confronting Putin to hammer home that attacks on U.S. networks will bring a response. There's much more work to do, but we're headed in the right direction. https://www.politico.com/...
Biden admin doing a bunch of really smart things with ransomware - eg planning to actively disrupt Ransomware operators, stop payment, pay people who provide info on operators etc. https://www.politico.com/...
Some highlights: -More support from @USTreasury implementing money laundering requirements for crypto currencies -FinCEN will announce a new public-private information sharing group -U.S. meeting w/ allies to push for uniform regulations on crypto https://www.cyberscoop.com/...
ahh check it out, USG looking for cyber tips and will provide rewards “Rewards for Justice - Reward Offer for Information on Foreign Malicious Cyber Activity Against U.S. Critical Infrastructure - United States Department of State” https://www.state.gov/...
“Cybersecurity experts say REvil may have decided to drop out of sight and rebrand under a new name, as it and several other ransomware gangs have done in the past to try to throw off law enforcement” https://apnews.com/...
U.S. Government Launches First One-Stop Ransomware Resource at https://stopransomware.gov/ New Website Provides Cybersecurity Resources from Across the Federal Government #StopRansomware https://www.justice.gov/... https://twitter.com/...
Combating ransomware requires teamwork. The #FBI joins our partners in announcing the launch of https://stopransomware.gov/, a one-stop hub for resources to help American businesses and communities #StopRansomware. https://www.justice.gov/... https://twitter.com/...
Smart, they know the talent pool for cyber attribution is much more robust in the private and .... Let's say freelance ... sector https://twitter.com/...
Good thread to keep in mind. When you make uninformed dunks on Bitcoin, you are absolutely carrying water for the authoritarians, the surveillance staters, the War on Terror profiteers, and the Big Bank goons. Whether you like it or not. https://twitter.com/...
741,800,000 rubles would frighten any leader who knew malicious cyber activities were conducted without scrutiny under his authority. https://apnews.com/...
Trump had absolutely no cybersecurity policy in the hope the Russians would once again save his ass in 2020. The size of the mess Biden has to clean up is monumental. https://twitter.com/...
In support of @POTUS' cross-agency effort to defend our nation, @StateDept is offering up to $10 million for info on any person involved in certain foreign malicious cyber activity against critical U.S. infrastructure. https://www.state.gov/...
The Biden administration is launching a cross-government task force to combat ransomware attacks, following a series of high-profile hacks that underscored how digital weaknesses can wreak havoc on American society https://www.politico.com/...
There are a lot of real problems with many cryptocurrencies and a lot of shady / douchey people in the scene, but when you jump in with uninformed dunks on cryptocurrencies as a whole, you're just helping pro-surveillance / pro-Big Bank goons get their way https://www.cyberscoop.…