Security1 distinct publisher3 min readUpdated
Cynthia Kaiser says infrastructure operations have pushed some crews off US targets entirely. The numbers are the bureau's own, but the cadence is something defenders can plan around.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The FBI has run more than 30 disruption operations against ransomware infrastructure this year, Cynthia Kaiser, deputy assistant director of the bureau's cyber division, said Wednesday at CyberScoop's CyberTalks event [s1c1][s1c2]. That matters less as a scoreboard than as a tempo: 30-plus operations in a year averages one every 12 days or so [s1d1], which is the first federal ransomware intervention frequent enough for a defender to treat as a planning assumption rather than a headline.
The strategic logic is the extradition problem. Ransomware crews largely operate from safe harbour countries such as Russia, where there is little prospect of bringing anyone to a US courtroom [s1c3]. The Justice Department still names and shames individuals who are unlikely ever to be extradited, but going after the criminal operations' infrastructure has become a second major line of effort [s1c4]. Kaiser put the targeting doctrine plainly: "The FBI emphasizes key services in our disruptions of ransomware groups, targeting the essential services that criminals rely on to conduct their attacks" [s1c5].
February's Operation Cronos is the template. The FBI, the UK's National Crime Agency and other international partners seized servers and disrupted other infrastructure belonging to LockBit, and obtained thousands of decryption keys usable for victim remediation [s1c6][s1c7]. According to Kaiser, the effect on the groups was time: "The groups had to take a long time to re-establish infrastructure in order to continue operations. Sometimes this means that we've seen them stop targeting the U.S. altogether" [s1c8]. She also said the FBI and international allies have saved businesses more than $800 million in recent years through ransomware recovery efforts and additional services [s1c9].
Those are the bureau's figures, self-reported, with no published definition of what counts as a disruption and no baseline for how long re-establishment normally takes. The counterevidence sits in the same remarks: the FBI's Internet Crime Complaint Center still logs a "high" number of ransomware attacks, per Kaiser [s1c10]. Ransomware remains a major national security concern, particularly for critical infrastructure, and a recent report found the attacks are driving an increase in emergency patient care [s1c11][s1c12].
The more interesting wrinkle is that the business model is moving. Kaiser noted variants more focused on data theft than on the file encryption of the older attacks [s1c13], and Microsoft researchers reported earlier this month that they have seen fewer attacks reaching the encryption stage in recent years [s1c14]. If pressure on encryption-era services is part of why crews are shifting to theft and extortion, the win is partial: fewer locked estates, the same stolen data, and a victim population whose leverage is unchanged. Decryption keys, the most concrete deliverable of Cronos [s1c7], are worth nothing to a company whose files were never encrypted.
What to watch. Whether the FBI publishes any methodology behind the 30-plus count [s1c1] and the $800 million figure [s1c9], because without it neither number supports a trend line. Whether the disruptions follow the criminals into the data-theft model, or keep hitting encryption-era infrastructure that matters less each quarter [s1c13][s1c14]. And whether "stopped targeting the U.S." holds for more than one reporting cycle [s1c8], or whether the observed lull is just rebuild time that operators should be budgeting for rather than celebrating.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Cynthia Kaiser, deputy assistant director of the FBI's cyber division, spoke on Wednesday at CyberScoop's CyberTalks event, saying the FBI is seeing progress against ransomware gangs and that disruption operations have in some cases stopped gangs from further targeting the U.S.
Kaiser said: "The groups had to take a long time to re-establish infrastructure in order to continue operations. Sometimes this means that we've seen them stop targeting the U.S. altogether."
The FBI conducted more than 30 disruption operations this year in which officials targeted the infrastructure used by ransomware groups.
Ransomware gangs often operate in safe harbor countries like Russia, where there is little hope for extradition to the U.S.
While the Justice Department continues to name and shame individuals who are not likely to be extradited, targeting the infrastructure of the criminal operations has become another major strategy to curb cyberattacks.
Kaiser said: "The FBI emphasizes key services in our disruptions of ransomware groups, targeting the essential services that criminals rely on to conduct their attacks."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source, agency-attributed figures
Every quantitative claim comes from one article reporting one FBI official's remarks at the publisher's own conference. The operation count, the $800 million savings, and the 'stopped targeting the U.S.' assertion carry no methodology, no operation-by-operation detail, and no independent corroboration. Only Operation Cronos is specified concretely enough to be checked, and the referenced emergency-care report is unnamed.
Real operations, self-reported scale
The strategy is demonstrably in use rather than aspirational: a named, multinational operation against LockBit produced server seizures and decryption keys, and the bureau reports dozens of similar actions plus victim-recovery services. Scale, however, is known only through the agency's own disclosure, and the source concedes IC3 attack volume remains high, so uptake of the tactic is clearer than its measurable effect.
Progress framing outruns the documentation
Positive but modest. 'Progress', gangs that 'stop targeting the U.S. altogether', and $800 million in savings are strong assertions supported only by one official's remarks, and the derived roughly 12-day cadence is arithmetic rather than a disclosed operating rhythm. The overstatement is bounded because the same article publishes deflating context — IC3 volume still high, and extortion migrating to data theft, which means encryption-stage declines may reflect tactic change rather than defeat.
Agency credit-taking on the publisher's own stage
Two reinforcing incentives are visible in the supplied material. The speaker is a serving FBI cyber official presenting the bureau's effectiveness metrics, which supports budget, authority, and cooperation goals. The reporting outlet is also the organizer of CyberTalks, the event generating the claims, and the article carries no disclosure of that relationship or any outside assessment.
Moderate-low
Confidence is capped by the single-source, single-speaker basis and the absence of any methodology, but is not minimal: the attribution is direct and on the record, one operation is named with specific outcomes, and the article itself supplies qualifying counter-evidence rather than pure promotion.
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
security
Levi Strauss lost corporate files through three laptops and no malware1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026