Skip to content

Security1 publisher3 min readPublished Updated

FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing

Cynthia Kaiser says infrastructure operations have pushed some crews off US targets entirely. The numbers are the bureau's own, but the cadence is something defenders can plan around.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing
Photo: halcyon.ai

What happened

  • The FBI conducted more than 30 disruption operations this year in which officials targeted the infrastructure used by ransomware groups.
  • Cynthia Kaiser, deputy assistant director of the FBI's cyber division, spoke on Wednesday at CyberScoop's CyberTalks event, saying the FBI is seeing progress against ransomware gangs and that disruption operations have in some cases stopped gangs from further targeting the U.S.
  • Ransomware gangs often operate in safe harbor countries like Russia, where there is little hope for extradition to the U.S.
  • While the Justice Department continues to name and shame individuals who are not likely to be extradited, targeting the infrastructure of the criminal operations has become another major strategy to curb cyberattacks.
  • Kaiser said: "The FBI emphasizes key services in our disruptions of ransomware groups, targeting the essential services that criminals rely on to conduct their attacks."

Compiled by The WatchSomething wrong?How this is made

Why it matters

The FBI has run more than 30 disruption operations against ransomware infrastructure this year, Cynthia Kaiser, deputy assistant director of the bureau's cyber division, said Wednesday at CyberScoop's CyberTalks event [s1c1][s1c2]. That matters less as a scoreboard than as a tempo: 30-plus operations in a year averages one every 12 days or so [s1d1], which is the first federal ransomware intervention frequent enough for a defender to treat as a planning assumption rather than a headline.

The strategic logic is the extradition problem. Ransomware crews largely operate from safe harbour countries such as Russia, where there is little prospect of bringing anyone to a US courtroom [s1c3]. The Justice Department still names and shames individuals who are unlikely ever to be extradited, but going after the criminal operations' infrastructure has become a second major line of effort [s1c4]. Kaiser put the targeting doctrine plainly: "The FBI emphasizes key services in our disruptions of ransomware groups, targeting the essential services that criminals rely on to conduct their attacks" [s1c5].

February's Operation Cronos is the template. The FBI, the UK's National Crime Agency and other international partners seized servers and disrupted other infrastructure belonging to LockBit, and obtained thousands of decryption keys usable for victim remediation [s1c6][s1c7]. According to Kaiser, the effect on the groups was time: "The groups had to take a long time to re-establish infrastructure in order to continue operations. Sometimes this means that we've seen them stop targeting the U.S. altogether" [s1c8]. She also said the FBI and international allies have saved businesses more than $800 million in recent years through ransomware recovery efforts and additional services [s1c9].

Those are the bureau's figures, self-reported, with no published definition of what counts as a disruption and no baseline for how long re-establishment normally takes. The counterevidence sits in the same remarks: the FBI's Internet Crime Complaint Center still logs a "high" number of ransomware attacks, per Kaiser [s1c10]. Ransomware remains a major national security concern, particularly for critical infrastructure, and a recent report found the attacks are driving an increase in emergency patient care [s1c11][s1c12].

The more interesting wrinkle is that the business model is moving. Kaiser noted variants more focused on data theft than on the file encryption of the older attacks [s1c13], and Microsoft researchers reported earlier this month that they have seen fewer attacks reaching the encryption stage in recent years [s1c14]. If pressure on encryption-era services is part of why crews are shifting to theft and extortion, the win is partial: fewer locked estates, the same stolen data, and a victim population whose leverage is unchanged. Decryption keys, the most concrete deliverable of Cronos [s1c7], are worth nothing to a company whose files were never encrypted.

What to watch. Whether the FBI publishes any methodology behind the 30-plus count [s1c1] and the $800 million figure [s1c9], because without it neither number supports a trend line. Whether the disruptions follow the criminals into the data-theft model, or keep hitting encryption-era infrastructure that matters less each quarter [s1c13][s1c14]. And whether "stopped targeting the U.S." holds for more than one reporting cycle [s1c8], or whether the observed lull is just rebuild time that operators should be budgeting for rather than celebrating.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories