Law enforcement release

# International Investigation Leads to Shutdown of Ransomware Group

Federal Bureau of Investigation, Cleveland Field Office, August 12, 2024. Radar/Dispossessor disruption announced by FBI Cleveland on 12 August 2024: three U.S. servers, three United Kingdom servers, 18 German servers, eight U.S.-based criminal domains and one German-based criminal domain dismantled, and the partner roles of the U.K. National Crime Agency, the Bamberg Public Prosecutor's Office and the Bavarian State Criminal Police Office.

**Source type:** Law enforcement release

**Published:** August 12, 2024

**Research grade:** P1

**Used in entries:** 4

## Bibliographic record

**Publisher:** Federal Bureau of Investigation, Cleveland Field Office

**Published:** August 12, 2024

**Source type:** Law enforcement release

**Research grade:** Source grade P1

**Language:** English

**Official record:** Official publication

**Address:** [https://www.fbi.gov/contact-us/field-offices/cleveland/news/international-investigation-leads-to-shutdown-of-ransomware-group](https://www.fbi.gov/contact-us/field-offices/cleveland/news/international-investigation-leads-to-shutdown-of-ransomware-group)

**What it supports:** Radar/Dispossessor disruption announced by FBI Cleveland on 12 August 2024: three U.S. servers, three United Kingdom servers, 18 German servers, eight U.S.-based criminal domains and one German-based criminal domain dismantled, and the partner roles of the U.K. National Crime Agency, the Bamberg Public Prosecutor's Office and the Bavarian State Criminal Police Office

**Dataset id:** src\_usfbi\_cleveland\_dispossessor\_2024

## Research notes

- Subtitle on the page: '“Radar/Dispossessor” servers and domains successfully dismantled'.
- Read via an Internet Archive capture because fbi.gov returns HTTP 403 to automated clients.

How this source is used

Cited 4 times across 3 record types.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.

## Cited by

### Takedown records

1 citation

Cited on the takedown record itself.

-
[Radar/Dispossessor ransomware disruption](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)

Ransomware, August 2024

Supporting source

### Organization roles

1 citation

Cited for an organization's recorded role in a takedown.

-
[Bayerisches Landeskriminalamt](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)

Supporting, Radar/Dispossessor ransomware disruption

Primary source

### Infrastructure

2 citations

Cited for infrastructure recorded as acted on.

-
[24 servers](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)

Servers disabled, Radar/Dispossessor ransomware disruption

Primary source
-
[9 domains](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption)

Domains seized, Radar/Dispossessor ransomware disruption

Primary source

[All sources](https://takedownindex.org/sources)
