The FBI and international partners disrupted the infrastructure of ALPHV/BlackCat, a major ransomware-as-a-service operation linked to more than 1,000 victims and attacks across U.S. critical infrastructure sectors including healthcare, manufacturing, government, emergency services, schools, and defense-related organizations. U.S. authorities seized multiple ALPHV-operated sites and said an FBI-developed decryptor was provided to more than 500 victims worldwide, helping dozens restore systems and avoid an estimated $68 million in ransom payments. Officials described ALPHV as one of the world’s most prolific ransomware groups, and said the investigation remained active even though no arrests were announced.
Months later, ALPHV appeared to collapse amid allegations that its operators staged an exit scam after receiving a reported $22 million ransom tied to the Change Healthcare attack. A new seizure notice posted on the group’s leak site was disavowed by the U.S. Justice Department, Europol, and the U.K. National Crime Agency, while researchers said it reused elements from the legitimate law-enforcement takedown page. Reporting and affiliate claims indicated the group’s leaders kept the payment, cut off an affiliate, and then announced on a cybercrime forum that they were shutting down and planned to sell the malware source code, reinforcing assessments that affiliates may migrate and the operators could reappear under a new brand.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After the fake seizure notice and affiliate dispute, ALPHV acknowledged on the RAMP cybercrime forum that it was ending operations. The group also said it intended to sell its source code, reinforcing assessments that the public shutdown was self-directed rather than a fresh law-enforcement action.
The U.S. Justice Department, Europol, and the U.K. National Crime Agency said they were not involved in the new seizure-style notice appearing on ALPHV infrastructure. Researchers assessed the group was likely conducting an exit scam and could re-emerge under a different brand.
ALPHV/BlackCat replaced its leak site with a bogus law-enforcement seizure banner that researchers said reused elements from the real December 2023 takedown. Reports indicated the operators shut out an affiliate after receiving the Change Healthcare payment and kept the proceeds, while the affiliate claimed to still hold 4 TB of stolen data.
According to affiliate claims, blockchain analysis, and researcher reporting cited later, ALPHV operators received a $22 million ransom payment connected to the Change Healthcare attack. The dispute over this payment became the trigger for the group's apparent collapse.
The FBI, DOJ, and international partners announced they had disrupted ALPHV/BlackCat by seizing multiple websites used by the ransomware-as-a-service group. Officials said the group had hit more than 1,000 victims over the prior 18 months, including organizations in U.S. critical infrastructure sectors.
During a covert operation preceding the public announcement, the FBI gained access to ALPHV/BlackCat infrastructure and created a decryptor that was later used to help dozens of victims restore systems. Authorities said the tool was made available to more than 500 affected organizations and helped avert about $68 million in ransom payments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourceindustrialcyber.co
Open sourcetherecord.media
Open sourcecybersecuritydive.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.