Sources: FBI refrained from sharing a ransomware decryptor with businesses for almost three weeks, as it carried out an operation to disrupt the REvil gang
The FBI refrained for almost three weeks from helping to unlock the computers of hundreds of businesses and institutions hobbled …
The withholding wasn't an anomaly but a template. By the Hive seizure, the FBI had quietly held access to Hive's network since July 2022 before moving, and by the LockBit operation it flipped the playbook entirely — publicly urging victims to claim free decryption from thousands of seized keys. The report captures law enforcement at the point where victim recovery and counter-ransomware operations were still treated as competing objectives.
First-order effects
Hundreds of Kaseya-affected businesses and institutions spent those three weeks without a working unlock, paying downtime or negotiating with REvil while the FBI held the decryptor for operational security.
REvil gained nearly three extra weeks of leverage over victims who might otherwise have recovered for free once the decryptor was shared.
Second-order effects
Victims who paid ransoms during the window effectively funded the very gang the FBI was targeting, tightening the argument for mandatory incident disclosure so agencies can't sit on relief without scrutiny.
Rivals like Hive and LockBit faced the same trade-off downstream: the FBI's pattern of holding network access before striking meant their victims too were exposed to delayed recovery until the seized-keys model matured.
Third-order effects
If the pattern holds, decryption keys become a managed government asset — the shift visible from the quiet REvil hold to the FBI actively soliciting LockBit victims — forcing policy to reconcile intelligence value against publicized recovery timelines.
Sustained state-led disruption plus key redistribution points ransomware economics toward gangs whose affiliates price in seizure risk, pushing the ecosystem toward fewer, more hardened operations rather than many opportunistic ones.
The trend: Law enforcement is evolving from hoarding ransomware decryptors for investigative advantage to distributing seized keys as a public recovery channel, with each major operation — REvil, Hive, LockBit — shifting the balance further toward victim relief.
NEW: FBI held back REvil ransomware decryption key from businesses to run operation targeting hackers. My latest w/@rachelerman https://www.washingtonpost.com/ ...
But apparently it took Emsisoft, the company that built the decryption tool that Kaseya released, a total of 10 minutes to build and test the decryptor. (more)
I'd be concerned that we have a IC security vulnerability that could be a mole who gave away our plan. FBI held back ransomware decryption key from businesses to run operation targeting hackers https://www.washingtonpost.com/ ...
Wray was just asked why and he totally and completely dodged the question. FBI held back ransomware decryption key from businesses to run operation targeting hackers https://www.washingtonpost.com/ ...
If they had not been familiar with REvil ransomware and “if we had to go from scratch,” Emsisoft CTO Fabian Wosar told me, “it would have taken about 4 hours.” Not days. Not weeks. Four hours.
Fascinating piece revealing complexity of responding to ransomware. Gov obtained REvil decryption key by hacking REvil server but withheld key from victims because it planned an op to disrupt Russian hackers. FBI only shared key w/ Kaseya 19 days after it was hit w/ ransomware. h…
The FBI had a decryption key for REvil ransomware but withheld it to try to target the group more directly. After 3 weeks, REvil went quiet, but not because of the FBI. (Sounds like a foreign intel agency may have intervened but unclear.) https://www.washingtonpost.com/ ... https…
Wait, so the FBI had the decryption key, didn't send it to the victims. They could have taken down REvil's site, also didn't do that. So they did... nothing?! FBI is quoted saying it was a “perceived delay”. The victims might disagree with the notion “perceived”... https://twitte…
Big reporting that fills in lots of blanks here. The FBI obtained the REvil decryption key earlier this summer by hacking them directly, and chose to not help victims so as not spook the gang. But REvil then went offline of their own accord, making the whole thing moot. https://t…
The FBI had the key to unlock computers bricked by a massive ransomware attack, but waited three weeks because they didn't want to tip the hackers off. Deploying it immediately could have helped schools and hospitals save millions in recovery costs https://twitter.com/...
Sen. Gary Peters just asked FBI boss Chris Wray about this WaPo report saying FBI held back the Kaseya decryptor: https://www.washingtonpost.com/ ... Wray said the tools take time to test/deploy. Doesn't comment on reported REvil operation. Added that he can't say much re: ongoin…
Balancing offense and defense in counter-ransomware is a grey area, not black and white: “The previously unreported episode highlights the trade-offs law enforcement officials face between trying to damage cyber criminal networks and promptly helping the victims of ransomware...”…
really proud of this story with @nakashimae, which examines the forceful effects of ransomware and government's attempts to stop it https://twitter.com/...
Per WaPo: The FBI's planned takedown of REvil never happened because in mid-July REvil's platform went offline — without U.S. government intervention — and the hackers disappeared before the FBI had a chance to execute its plan. https://www.washingtonpost.com/ ... https://twitter…