Another ransomware gang is in U.S. crosshairs, with authorities moving against the BlackSuit group, active since 2022 and linked to more than $370 million in ransom demands. On Monday, the Justice Department said it seized four servers, nine domains, and…Another ransomware gang is in U.S. crosshairs, with authorities moving against the BlackSuit group, active since 2022 and linked to more than $370 million in ransom demands. On Monday, the Justice Department said it seized four servers, nine domains, and…

U.S. seizes servers and $1.09m in crypto linked to BlackSuit ransomware gang

2025/08/13 17:24
3 min read

Another ransomware gang is in U.S. crosshairs, with authorities moving against the BlackSuit group, active since 2022 and linked to more than $370 million in ransom demands.

Summary
  • U.S. authorities have seized four servers, nine domains, and $1.09 million in cryptocurrency tied to the BlackSuit ransomware group.
  • BlackSuit has targeted critical infrastructure in the U.S. since 2022.
  • It emerged as a spinoff of the Royal ransomware gang.

On Monday, the Justice Department said it seized four servers, nine domains, and about $1.09 million in cryptocurrency tied to BlackSuit, working with U.S. and international partners to carry out the raid.

The July 24 takedown drew in a broad coalition of agencies, from Homeland Security Investigations and the Secret Service to IRS Criminal Investigation and the FBI, alongside law enforcement from the United Kingdom, Germany, Ireland, France, Canada, Ukraine, and Lithuania.

Officials also unsealed a federal warrant to seize the cryptocurrency, which an unnamed exchange had frozen earlier this year.

BlackSuit’s targeted critical U.S. infrastructure

BlackSuit, active since at least 2022, emerged as a spinoff of the Royal ransomware gang, a group already known for large-scale extortion campaigns against critical infrastructure. Investigators say the group began operating under the BlackSuit name in 2023 and was found to be using many of Royal’s tactics, techniques, and tools.

Over time, it built its own reputation in the cybercrime world for targeting large organizations with ransom demands ranging from $1 million to $10 million, and in one case, as high as $60 million. 

The group also operated a portal on the darknet where it listed sensitive stolen data set to be released to the public if victims did not pay the ransom.

By late 2023, the FBI and the Cybersecurity and Infrastructure Security Agency warned in a joint advisory that BlackSuit had the tools and tactics to hit sectors where an attack could cause the most disruption.

BlackSuit has struck critical infrastructure within the U.S., often hitting healthcare providers, government facilities, manufacturing plants, and commercial operators. Victims usually found themselves locked out of vital systems while facing the threat of sensitive data leaks.

In 2023, an unnamed organization paid 49.3 Bitcoin, worth about $1.44 million at the time, to regain control of its systems after a BlackSuit breach, according to the DOJ.

A portion of that ransom payment became the $1.09 million that was seized during the takedown after months of investigation. Authorities estimate that since 2022, BlackSuit has compromised over 450 known victims in the United States alone.

US moves against ransomware gangs

The U.S. has been actively fighting back against ransomware attacks through sanctions and enforcement actions, describing this in today’s announcement as a “disruption-first” approach.

As previously reported by crypto.news, earlier this year the U.S., UK, and Australia jointly sanctioned Russian hosting provider Zservers and its operators for offering bulletproof hosting to the LockBit ransomware gang.

Last month, the Justice Department filed a forfeiture action to recover $2.3 million in Bitcoin from a member of the Chaos ransomware group after the FBI’s Dallas division seized 20 BTC from a Chaos-linked address the same month.

Market Opportunity
Moonveil Logo
Moonveil Price(MORE)
$0.0004908
$0.0004908$0.0004908
-32.63%
USD
Moonveil (MORE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50
Morgan Stanley Files For Bank Charter To Offer Crypto Custody And Staking Services — Report

Morgan Stanley Files For Bank Charter To Offer Crypto Custody And Staking Services — Report

The post Morgan Stanley Files For Bank Charter To Offer Crypto Custody And Staking Services — Report appeared on BitcoinEthereumNews.com. Morgan Stanley
Share
BitcoinEthereumNews2026/02/28 19:18
Taiko Makes Chainlink Data Streams Its Official Oracle

Taiko Makes Chainlink Data Streams Its Official Oracle

The post Taiko Makes Chainlink Data Streams Its Official Oracle appeared on BitcoinEthereumNews.com. Key Notes Taiko has officially integrated Chainlink Data Streams for its Layer 2 network. The integration provides developers with high-speed market data to build advanced DeFi applications. The move aims to improve security and attract institutional adoption by using Chainlink’s established infrastructure. Taiko, an Ethereum-based ETH $4 514 24h volatility: 0.4% Market cap: $545.57 B Vol. 24h: $28.23 B Layer 2 rollup, has announced the integration of Chainlink LINK $23.26 24h volatility: 1.7% Market cap: $15.75 B Vol. 24h: $787.15 M Data Streams. The development comes as the underlying Ethereum network continues to see significant on-chain activity, including large sales from ETH whales. The partnership establishes Chainlink as the official oracle infrastructure for the network. It is designed to provide developers on the Taiko platform with reliable and high-speed market data, essential for building a wide range of decentralized finance (DeFi) applications, from complex derivatives platforms to more niche projects involving unique token governance models. According to the project’s official announcement on Sept. 17, the integration enables the creation of more advanced on-chain products that require high-quality, tamper-proof data to function securely. Taiko operates as a “based rollup,” which means it leverages Ethereum validators for transaction sequencing for strong decentralization. Boosting DeFi and Institutional Interest Oracles are fundamental services in the blockchain industry. They act as secure bridges that feed external, off-chain information to on-chain smart contracts. DeFi protocols, in particular, rely on oracles for accurate, real-time price feeds. Taiko leadership stated that using Chainlink’s infrastructure aligns with its goals. The team hopes the partnership will help attract institutional crypto investment and support the development of real-world applications, a goal that aligns with Chainlink’s broader mission to bring global data on-chain. Integrating real-world economic information is part of a broader industry trend. Just last week, Chainlink partnered with the Sei…
Share
BitcoinEthereumNews2025/09/18 03:34