Europol says it has detained 12 suspects that were orchestrating ransomware attacks that hit 1,800+ victims across 71 countries since 2019
Europol said it detained 12 suspects this week it believes were part of a professional criminal group that orchestrated a long string of ransomware attacks … Source: Europol .
Context & Ripple Effects
This week's detention of 12 suspected ransomware orchestrators is the middle beat of a fast-moving enforcement arc: days earlier Europol had announced the arrest of two alleged gang members in Ukraine with US and French help, and within two weeks a Romanian-led investigation would add seven suspects accused of supporting over 7,000 cyberattacks tied to REvil and GandCrab. The scale cited here — 1,800-plus victims across 71 countries since 2019 — marks the target as a professional operation rather than a lone crew.
First-order effects
- The detained organizers are removed from active operations, disrupting attack coordination for whatever affiliate network depended on them while investigations across 71 affected countries gain named suspects.
Second-order effects
- Rival crews face pressure to harden their own operational security and travel patterns, while affiliates orphaned by the detentions migrate toward surviving brands like those targeted in the related REvil and GandCrab probes.
Third-order effects
- The cadence — Ukraine-based arrests recurring across 2021 and again in the 2023 multinational operation spanning Norway, the US, and Ukraine — suggests ransomware enforcement is consolidating into standing joint operations aimed at the people running attacks, not just their infrastructure.
The trend: International law enforcement is shifting from episodic ransomware takedowns to a continuous multinational campaign against the operators and enablers at the top of the affiliate model.