Skip to main content
Back to the takedown index

ALPHV/BlackCat disruption

December 2023, Ransomware
Led by Federal Bureau of Investigation

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Leak-site and negotiation infrastructure disrupted; decryption keys/tooling provided to victims.

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Partial

See people and accountability

Did it stay down?

After this action the service returned under the same operators, first seen December 2023. No later seizure of the replacement is recorded. Medium confidence in the link between the two.

See what happened afterward

DOJ/FBI announced a disruption of the ALPHV/BlackCat ransomware-as-a-service operation and offered an FBI-developed decryption capability to more than 500 victims.

Date
December 2023
Target
ALPHV/BlackCat, ransomware group
Activity
Ransomware
Operational lead
FBI
Partners
DOJ[1]
Jurisdiction
Not established
Outcome
Leak-site and negotiation infrastructure disrupted; decryption keys/tooling provided to victims.
Status
Completed
Legal mechanism
Court-authorized technical operation; federal criminal process.
Group accounted for
Partial

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

No core-operator arrests were announced in the initial disruption; the group reasserted control of some infrastructure shortly afterward.

See the organizations and roles behind this action

After this action the service returned under the same operators, first seen December 2023. No later seizure of the replacement is recorded. Medium confidence in the link between the two.

  1. December 2023

    ALPHV/BlackCat infrastructure reassertion. Same operators. Confidence: Medium. No later seizure recorded.[1]

    Group operators reasserted control of some leak-site infrastructure shortly after the FBI's technical disruption.

December 2023

ALPHV/BlackCat infrastructure reassertion. Same operators. Confidence: Medium. No later seizure recorded.[1]

Group operators reasserted control of some leak-site infrastructure shortly after the FBI's technical disruption.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Justice Department disrupts ALPHV/BlackCat ransomware

    US DOJ, December 19, 2023, Source grade P1

    Establishes the FBI's disruption of ALPHV/BlackCat infrastructure and the decryption-key offer.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.