/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Europol says it has detained 12 suspects for orchestrating ransomware attacks that hit 1,800+ victims across 71 countries since 2019

Catalin Cimpanu / The Record :

The Record Catalin Cimpanu

Context & Ripple Effects

This detention wave lands ten days after Europol announced the arrest of two alleged ransomware gang members in Ukraine with US and French help, and within a week it was followed by a Romanian-led operation that netted seven suspects accused of supporting REvil and GandCrab across more than 7,000 cyberattacks since early 2019. Read together, October–November 2021 marks a shift from chasing ransomware brands to sweeping up the people who run them.

The 12 suspects here are accused of orchestrating attacks on over 1,800 victims in 71 countries since 2019 — a scale that makes them operators rather than foot soldiers, and makes the case a template for the multinational actions that followed, including the disruption of the DoppelPaymer-deploying gang by German, US, FBI, and Ukrainian forces.

First-order effects

  • Twelve suspected operators are off the board, and the attack chain behind 1,800+ victims in 71 countries loses its coordinators — immediate relief for targeted organizations and a live evidence base for prosecutors in multiple jurisdictions.
  • Europol gains a publicized win that strengthens its pitch to national police forces for joining future joint ransomware operations.

Second-order effects

  • The follow-on Romanian-led arrests show takedowns expanding from orchestrators to the support cast — affiliates and helpers around REvil and GandCrab — forcing remaining crews to treat every partner as an arrest risk.
  • With operators and helpers being picked off, pressure migrates downstream to money movement, the lane later targeted when Europol dismantled the AudiA6 mixing service accused of laundering over $380M for ransomware actors.

Third-order effects

  • The recurring cast — Europol plus the US, Ukraine, France, Romania, Norway — points toward standing multinational disruption campaigns aimed at ransomware's division of labor rather than single-brand takedowns, a structure visible again in the 2023 Ukraine arrests of a group linked to attacks in 71 countries.
  • Arrests displace rather than delete capability: if the pattern holds, ransomware groups respond by hardening opsec and rotating personnel, keeping law enforcement in a permanent attrition contest instead of delivering a decisive blow.

The trend: Ransomware enforcement is evolving from isolated arrests into continuous multinational campaigns that target the entire criminal supply chain — operators, affiliates, and launderers alike.

Discussion

  • @europol @europol on x
    12️ suspects have been targeted in 🇺🇦🇨🇭 for carrying out aggressive #ransomware attacks against critical infrastructure. 🌐1800 high-stake victims in 71 countries 🚔 6 #Europol specialists deployed to Ukraine to assist @CyberpoliceUA 👉 https://ow.ly/... #EMPACT https://twitter.com/…
  • @sophoslabs @sophoslabs on x
    Two years later, law enforcement is taking down the threat actors behind ransomware attacks involving Dharma, Megacortex, and LockerGoga. Our initial coverage of Megacortex from May, 2019: https://news.sophos.com/... https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    The math of 12 suspects to 1,800 victims in 71 countries may not be the whole picture but it's still a pretty wild illustration of impact https://twitter.com/...
  • @itsreallynick Nick Carr on x
    12 suspects interrogated & assets seized in an 8 country @Europol operation. Threat actors were running Cobalt Strike / Empire C2 - deploying LockerGoga, MegaCortex, and Dharma ransomware deployment - and mixing/laundering cryptocurrency. https://twitter.com/...
  • @mariegmoe Marie Moe on x
    Kudos to the Norwegian National Cybercrime Center (NC3) that participated in this investigation including the ransomware attack against Norsk Hydro 🙌 https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    A reminder (again) that not all ransomware operators are in Russia. https://twitter.com/...
  • @kennwhite Kenn White on x
    “Suspects are considered high-value targets...The group would spend months probing for weaknesses in order to move laterally...[deploying] malware such as TrickBot, or post-exploitation frameworks such as Cobalt Strike or PowerShell Empire, to stay undetected & gain further acces…
  • @joetidy Joe Tidy on x
    Europol tells me the 12 individuals are in custody in Ukraine and Switzerland. Sounds like they are affiliates of multiple ransomware gangs. Some allegedly used LockerGoga - famously the strain of ransomware that brought Norsk Hydro to its knees in 2019: https://www.bbc.com/... h…
  • @campuscodi Catalin Cimpanu on x
    Breaking: Europol detained 12 suspects behind more than 1,800 ransomware attacks on large companies across 71 countries -Europol said they used ransomware strains such as LockerGoga, MegaCortex, and Dharma -Group was linked to the Norsk Hydro 2019 attack https://therecord.media/.…