The FBI says the Hive ransomware gang has extorted ~$100M from 1,300+ organizations, including government facilities and public health entities, since June 2021
The Federal Bureau of Investigation (FBI) said today that the notorious Hive ransomware gang has successfully extorted roughly $100 million …
Context & Ripple Effects
This FBI advisory fits a pattern from late 2021: the bureau publicly tallying ransomware crews' hauls against US targets, as it did when it attributed at least $43.9M to Cuba ransomware actors hitting 49 critical-infrastructure organizations, alongside joint NSA-CISA-FBI warnings on BlackMatter. The Hive numbers — roughly $100M from 1,300+ organizations including government facilities and public health entities — made Hive one of the most damaging crews the FBI had quantified.
What the advisory did not say is that the FBI was already inside: per later coverage, the bureau had access to Hive's network since July 2022, which became the basis for a multinational seizure of Hive's site and decryption keys weeks after this report, and for handing victims 300+ keys that avoided an estimated $130M in payments.
First-order effects
- Government facilities and public health entities in Hive's crosshairs get actionable indicators from the FBI advisory, while the 1,300+ already-extorted organizations see their cases folded into an active federal investigation.
- Hive's disclosed ~$100M take puts it in the same public-accounting frame the FBI used for Cuba, raising the crew's profile with both affiliates hunting payouts and investigators building cases.
Second-order effects
- A quantified target on Hive's back invites affiliate churn — ransomware crews live on reputation for paying out, so FBI scrutiny pressures partners toward less-scrutinized brands.
- The FBI's advisory-then-infiltration sequence sets expectations for victims: with 300+ decryption keys generated from Hive's servers and distributed free, paying attackers looks weaker against waiting for law enforcement.
Third-order effects
- The arc from this advisory to the seizure of Hive's site and decryption keys marks a structural shift: ransomware defense migrating from victim-side negotiation and insurance payouts toward law-enforcement disruption funded by covert network access.
- If the FBI keeps pairing public damage tallies with inside access, ransomware groups face a durable cost — operational secrecy — that changes how they recruit affiliates and pick targets like hospitals and government facilities.
The trend: US ransomware response is evolving from FBI advisories that merely quantify gang revenues into covert-access operations that end in seizures and free decryption for victims.