Government release

# U.S. Department of Justice Disrupts Hive Ransomware Variant

United States Department of Justice, January 26, 2023. Covert network access from July 2022, more than 300 decryption keys to victims under attack and more than 1,000 to previous victims, approximately 130 million USD in ransom demands averted, German and Dutch server seizures.

**Source type:** Government release

**Published:** January 26, 2023

**Research grade:** P1

**Used in entries:** 9

## Bibliographic record

**Publisher:** United States Department of Justice

**Published:** January 26, 2023

**Source type:** Government release

**Research grade:** Source grade P1

**Language:** English

**Official record:** Official publication

**Address:** No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

**What it supports:** Covert network access from July 2022, more than 300 decryption keys to victims under attack and more than 1,000 to previous victims, approximately 130 million USD in ransom demands averted, German and Dutch server seizures

**Dataset id:** src\_doj\_hive\_2023

## Research notes

- URL not re-verified in this pass.

How this source is used

Cited 9 times across 4 record types.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 20, 2026. Addresses recorded after that date are not reflected here.

## Cited by

### Takedown records

1 citation

Cited on the takedown record itself.

-
[Hive ransomware infiltration and seizure](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Ransomware, July 2022

Primary source

### Organization roles

4 citations

Cited for an organization's recorded role in a takedown.

-
[Federal Bureau of Investigation](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Operational lead, Hive ransomware infiltration and seizure

Primary source
-
[United States Attorney's Office for the Middle District of Florida](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Prosecuting, Hive ransomware infiltration and seizure

Primary source
-
[Bundeskriminalamt](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Infrastructure seizure, Hive ransomware infiltration and seizure

Primary source
-
[National High Tech Crime Unit](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Infrastructure seizure, Hive ransomware infiltration and seizure

Primary source

### Infrastructure

3 citations

Cited for infrastructure recorded as acted on.

-
[Server](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Server seized, Hive ransomware infiltration and seizure

Primary source
-
[approximately 2 onion services](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Onion services seized, Hive ransomware infiltration and seizure

Primary source
-
[1 admin panel](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Admin panel taken over, Hive ransomware infiltration and seizure

Primary source

### Later activity

1 citation

Cited for activity recorded after the takedown.

-
[Hunters International](https://takedownindex.org/takedowns/hive-ransomware-infiltration-and-seizure)

Rebrand, Hive ransomware infiltration and seizure

Primary source

[All sources](https://takedownindex.org/sources)
