/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Sources: FBI refrained from sharing a ransomware decryptor with businesses for almost three weeks, as it carried out an operation to disrupt the REvil gang

The FBI refrained for almost three weeks from helping to unlock the computers of hundreds of businesses and institutions hobbled …

Washington Post

Context & Ripple Effects

This disclosure lands between two bookends in the REvil saga: the gang's infrastructure and leak sites going dark in mid-July 2021 after the Kaseya attack hit 1,500+ businesses, and the multi-country operation that forced REvil offline again in October. The Washington Post report explains what the FBI was doing in the gap — running an disruption operation while sitting on a decryptor that could have unlocked victims' machines.

The withholding wasn't an anomaly but a template. By the Hive seizure, the FBI had quietly held access to Hive's network since July 2022 before moving, and by the LockBit operation it flipped the playbook entirely — publicly urging victims to claim free decryption from thousands of seized keys. The report captures law enforcement at the point where victim recovery and counter-ransomware operations were still treated as competing objectives.

First-order effects

  • Hundreds of Kaseya-affected businesses and institutions spent those three weeks without a working unlock, paying downtime or negotiating with REvil while the FBI held the decryptor for operational security.
  • REvil gained nearly three extra weeks of leverage over victims who might otherwise have recovered for free once the decryptor was shared.

Second-order effects

  • Victims who paid ransoms during the window effectively funded the very gang the FBI was targeting, tightening the argument for mandatory incident disclosure so agencies can't sit on relief without scrutiny.
  • Rivals like Hive and LockBit faced the same trade-off downstream: the FBI's pattern of holding network access before striking meant their victims too were exposed to delayed recovery until the seized-keys model matured.

Third-order effects

  • If the pattern holds, decryption keys become a managed government asset — the shift visible from the quiet REvil hold to the FBI actively soliciting LockBit victims — forcing policy to reconcile intelligence value against publicized recovery timelines.
  • Sustained state-led disruption plus key redistribution points ransomware economics toward gangs whose affiliates price in seizure risk, pushing the ecosystem toward fewer, more hardened operations rather than many opportunistic ones.

The trend: Law enforcement is evolving from hoarding ransomware decryptors for investigative advantage to distributing seized keys as a public recovery channel, with each major operation — REvil, Hive, LockBit — shifting the balance further toward victim relief.

Discussion

  • @nakashimae Ellen Nakashima on x
    NEW: FBI held back REvil ransomware decryption key from businesses to run operation targeting hackers. My latest w/⁦@rachelerman⁩ https://www.washingtonpost.com/ ...
  • @nakashimae Ellen Nakashima on x
    But apparently it took Emsisoft, the company that built the decryption tool that Kaseya released, a total of 10 minutes to build and test the decryptor. (more)
  • @timinhonolulu @timinhonolulu on x
    I'd be concerned that we have a IC security vulnerability that could be a mole who gave away our plan. FBI held back ransomware decryption key from businesses to run operation targeting hackers https://www.washingtonpost.com/ ...
  • @kendilaniannbc Ken Dilanian on x
    Wray was just asked why and he totally and completely dodged the question. FBI held back ransomware decryption key from businesses to run operation targeting hackers https://www.washingtonpost.com/ ...
  • @nakashimae Ellen Nakashima on x
    If they had not been familiar with REvil ransomware and “if we had to go from scratch,” Emsisoft CTO Fabian Wosar told me, “it would have taken about 4 hours.” Not days. Not weeks. Four hours.
  • @kimzetter Kim Zetter on x
    Fascinating piece revealing complexity of responding to ransomware. Gov obtained REvil decryption key by hacking REvil server but withheld key from victims because it planned an op to disrupt Russian hackers. FBI only shared key w/ Kaseya 19 days after it was hit w/ ransomware. h…
  • @silvermanjacob Jacob Silverman on x
    The FBI had a decryption key for REvil ransomware but withheld it to try to target the group more directly. After 3 weeks, REvil went quiet, but not because of the FBI. (Sounds like a foreign intel agency may have intervened but unclear.) https://www.washingtonpost.com/ ... https…
  • @_intelligencex Intelligence X on x
    Wait, so the FBI had the decryption key, didn't send it to the victims. They could have taken down REvil's site, also didn't do that. So they did... nothing?! FBI is quoted saying it was a “perceived delay”. The victims might disagree with the notion “perceived”... https://twitte…
  • @kevincollier Kevin Collier on x
    Big reporting that fills in lots of blanks here. The FBI obtained the REvil decryption key earlier this summer by hacking them directly, and chose to not help victims so as not spook the gang. But REvil then went offline of their own accord, making the whole thing moot. https://t…
  • @drewharwell Drew Harwell on x
    The FBI had the key to unlock computers bricked by a massive ransomware attack, but waited three weeks because they didn't want to tip the hackers off. Deploying it immediately could have helped schools and hospitals save millions in recovery costs https://twitter.com/...
  • @daviduberti David Uberti on x
    Sen. Gary Peters just asked FBI boss Chris Wray about this WaPo report saying FBI held back the Kaseya decryptor: https://www.washingtonpost.com/ ... Wray said the tools take time to test/deploy. Doesn't comment on reported REvil operation. Added that he can't say much re: ongoin…
  • @wylienewmark @wylienewmark on x
    Balancing offense and defense in counter-ransomware is a grey area, not black and white: “The previously unreported episode highlights the trade-offs law enforcement officials face between trying to damage cyber criminal networks and promptly helping the victims of ransomware...”…
  • @rachelerman Rachel Lerman on x
    really proud of this story with @nakashimae, which examines the forceful effects of ransomware and government's attempts to stop it https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    Per WaPo: The FBI's planned takedown of REvil never happened because in mid-July REvil's platform went offline — without U.S. government intervention — and the hackers disappeared before the FBI had a chance to execute its plan. https://www.washingtonpost.com/ ... https://twitter…