Global law enforcement takes down ransomware group that targeted US hospitals, schools

A coalition of international law enforcement agencies has disrupted one of the most destructive strains of ransomware in recent history, Lockbit, which cybercriminals frequently use to attack American hospitals and schools.

In one of the largest cybercrime takedowns to date, agencies from the United States, United Kingdom and 12 other countries dismantled Lockbit’s infrastructure and replaced its dark web site with a list of agency press releases and resources for victims.

Brett Leatherman, deputy assistant director of the FBI Cyber Division, said in a press conference Tuesday that the takedown was “several years in the making.”

Attorney General Merrick Garland said in a YouTube video Tuesday that the action against Lockbit’s purveyors was “taking away the keys to their criminal operation.”

Ransomware is a type of cybercrime in which hackers use malicious software to encrypt a network of computers, usually belonging to a business or critical service, and demand a cryptocurrency payment for a promise to fix the problem. Such attacks routinely cripple operations at American hospitals, public schools, businesses and police departments.

The issue has become an epidemic, with victims sending their attackers a record $1 billion last year.

While the cybercrime underworld is littered with ransomware strains, Lockbit has been the most prolific in recent years, in part because its developers offer it to practically any would-be cybercriminal, said Allan Liska, a ransomware analyst at the cybersecurity firm Recorded Future.

“Anyone who pays to join is accepted with little or no vetting,” he said. That lack of scruples helps explain why it’s so frequently used to hack hospitals, he said.

At least five alleged members of the Lockbit operation have been named or arrested as part of the action. Two affiliates were arrested in Ukraine and Poland, respectively, at the request of French law enforcement, a Europol announcement said.

Many ransomware hackers are located in Russia, which has enabled a thriving cybercriminal scene and does not extradite its own citizens, frustrating authorities in countries where victims reside.

global law enforcement takes down ransomware group that targeted us hospitals, schools

Mikhail Pavlovich Matveev, a Russian National, is allegedly a prolific ransomware affiliate currently based in Russia (FBI)

The Justice Department issued indictments for Russian nationals Artur Sungatov and Ivan Kondratyev, who have been named for the first time publicly, and said that an at-large alleged Russian cybercriminal, Mikhail Matveev, was also involved with Lockbit. Last year, the State Department offered a $10 million reward for information that leads to his arrest.

With those core suspects seemingly still free to operate in Russia, there’s little doubt that they could rebuild Lockbit’s empire, said Don Smith, vice president of threat intelligence at the cybersecurity company SecureWorks.

“I’m sure the rebuild wouldn’t take long but much of this operation has been about eroding trust in the criminal ecosystem,” he said.

This article was originally published on NBCNews.com

News Related

OTHER NEWS

Lawsuit seeks $16 million against Maryland county over death of pet dog shot by police

A department investigator accused two of the officers of “conduct unbecoming an officer” for entering the apartment without a warrant, but the third officer was cleared of wrongdoing, the suit says. Read more »

Heidi Klum shares rare photo of all 4 of her and Seal's kids

Heidi Klum posted a rare picture with husband Tom Kaulitz and her four kids: Leni, 19, Henry, 18, Johan, 17, and Lou, 14, having some quality family time. Read more »

European stocks head for flat open as markets struggle to find momentum

This is CNBC’s live blog covering European markets. European markets are heading for a flat open Tuesday, continuing lackluster sentiment seen at the start of the week in the region ... Read more »

Linda C. Black Horoscopes: November 28

Nancy Black Today’s Birthday (11/28/23). This year energizes your work and health. Faithful domestic routines provide central support. Shift directions to balance your work and health, before adapting around team ... Read more »

Michigan Democrats poised to test ambitious environmental goals in the industrial Midwest

FILE – One of more than 4,000 solar panels constructed by DTE Energy lines a 9.37-acre swath of land in Ann Arbor Township, Mich., Sept. 15, 2015. Michigan will join ... Read more »

Gaza Is Falling Into ‘Absolute Chaos,’ Aid Groups Say

A shaky cease-fire between Israel and Hamas has allowed a surge of aid to reach Palestinians in Gaza, but humanitarian groups and civilians in the enclave say the convoys aren’t ... Read more »

Bereaved Israeli and Palestinian families to march together in anti-hate vigil

Demonstrators march against the rise of antisemitism in the UK on Sunday – SUSANNAH IRELAND/REUTERS Bereaved Israeli and Palestinian families will march together as part of an anti-hate vigil on ... Read more »
Top List in the World