Ransomware

US Offers $10 Million for Information on BlackCat Ransomware Leaders

The US announces a $10 million reward for information on key members of the Alphv/BlackCat ransomware group.

The US announces a $10 million reward for information on key members of the Alphv/BlackCat ransomware group.

Two months after taking down the Alphv/BlackCat ransomware operation, the US announced a $10 million reward for information on the cybergang’s key members.

Operating since late 2021 under the ransomware-as-a-service business model, BlackCat has made over 1,000 victims worldwide, including organizations such as MGM Resorts, NCR, Reddit, Swissport, and Western Digital.

In early December 2023, the group’s Tor-based website went offline following a presumed law enforcement takedown that was officially confirmed roughly two weeks later, when the FBI also released a free decryption tool for the ransomware’s victims.

The takedown was possible after the FBI obtained credentials providing access to the panels the group’s members were using for communication.

In response, the cybergang briefly “unseized” its domain and announced lifting all restrictions imposed on affiliates, allowing them to target any type of organization in any country.

The group also claimed that the decryption tool was only good for roughly 400 organizations, but that more than 3,000 other victims would never recover their data.

Advertisement. Scroll to continue reading.

According to the FBI, the decryption tool has helped dozens of victims restore their systems, saving them from paying up approximately $99 million in ransom demands.

Now, the US is offering a reward of up to $10 million for information that would help law enforcement identify or locate the BlackCat group leaders, and up to $5 million for information leading to the arrest or conviction of any group affiliate.

The US has set up a tip line that can be accessed using the Tor browser, and encourages interested parties to provide information using that portal, via local FBI offices, or via US embassies.

Last week, the US announced a $10 million reward for information on the leaders of the Hive ransomware, which was disrupted in January 2023.

Related: Ransomware Attack Knocks 100 Romanian Hospitals Offline

Related: Ransomware Payments Surpassed $1 Billion in 2023: Analysis

Related: The Ransomware Threat in 2024 is Growing: Report

Related Content

Cyberwarfare

The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version