/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Europol says it has detained 12 suspects that were orchestrating ransomware attacks that hit 1,800+ victims across 71 countries since 2019

Europol said it detained 12 suspects this week it believes were part of a professional criminal group that orchestrated a long string of ransomware attacks … Source: Europol .

The Record Catalin Cimpanu

Context & Ripple Effects

This week's detention of 12 suspected ransomware orchestrators is the middle beat of a fast-moving enforcement arc: days earlier Europol had announced the arrest of two alleged gang members in Ukraine with US and French help, and within two weeks a Romanian-led investigation would add seven suspects accused of supporting over 7,000 cyberattacks tied to REvil and GandCrab. The scale cited here — 1,800-plus victims across 71 countries since 2019 — marks the target as a professional operation rather than a lone crew.

First-order effects

  • The detained organizers are removed from active operations, disrupting attack coordination for whatever affiliate network depended on them while investigations across 71 affected countries gain named suspects.

Second-order effects

  • Rival crews face pressure to harden their own operational security and travel patterns, while affiliates orphaned by the detentions migrate toward surviving brands like those targeted in the related REvil and GandCrab probes.

Third-order effects

The trend: International law enforcement is shifting from episodic ransomware takedowns to a continuous multinational campaign against the operators and enablers at the top of the affiliate model.

Discussion

  • @europol @europol on x
    12️ suspects have been targeted in 🇺🇦🇨🇭 for carrying out aggressive #ransomware attacks against critical infrastructure. 🌐1800 high-stake victims in 71 countries 🚔 6 #Europol specialists deployed to Ukraine to assist @CyberpoliceUA 👉 https://ow.ly/... #EMPACT https://twitter.com/…
  • @itsreallynick Nick Carr on x
    12 suspects interrogated & assets seized in an 8 country @Europol operation. Threat actors were running Cobalt Strike / Empire C2 - deploying LockerGoga, MegaCortex, and Dharma ransomware deployment - and mixing/laundering cryptocurrency. https://twitter.com/...
  • @mariegmoe Marie Moe on x
    Kudos to the Norwegian National Cybercrime Center (NC3) that participated in this investigation including the ransomware attack against Norsk Hydro 🙌 https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    A reminder (again) that not all ransomware operators are in Russia. https://twitter.com/...
  • @kennwhite Kenn White on x
    “Suspects are considered high-value targets...The group would spend months probing for weaknesses in order to move laterally...[deploying] malware such as TrickBot, or post-exploitation frameworks such as Cobalt Strike or PowerShell Empire, to stay undetected & gain further acces…
  • @campuscodi Catalin Cimpanu on x
    Breaking: Europol detained 12 suspects behind more than 1,800 ransomware attacks on large companies across 71 countries -Europol said they used ransomware strains such as LockerGoga, MegaCortex, and Dharma -Group was linked to the Norsk Hydro 2019 attack https://therecord.media/.…