Skip to main content
Back to Hive ransomware infiltration and seizure

Organizations and roles

July 2022, Ransomware
Hive ransomware infiltration and seizure

Last reviewed August 21, 2026

The public record puts 5 organizations on this action. Operational lead: FBI. The table lists the role the cited record assigns each one, in the record's own wording where it gives any.

Why this page names organizations only

Roles on this page describe the agencies that took part. Individuals named in the public record appear on the takedown entry itself, under People and accountability.

Organizations and roles

Emblem Organization Role What the record says
Federal Bureau of Investigation United States , United States Operational lead Covertly penetrated the Hive network, captured decryption keys, and seized the servers and sites.
United States Attorney's Office for the Middle District of Florida United States , United States Prosecuting Obtained the seizure warrants.
Bundeskriminalamt Germany , Germany Infrastructure seizure Participated in the seizure of German-hosted servers.
National High Tech Crime Unit Netherlands , Netherlands Infrastructure seizure Participated in the seizure of Netherlands-hosted servers.
European Union Agency for Law Enforcement Cooperation Supporting Supported the international coordination.

Accountability

Legal authority

US seizure warrants (Middle District of Florida); German and Dutch judicial process; Europol support

Oversight

The record assigns prosecuting or judicial roles to USAO-MDFL.

Ongoing investigation

Group accounted for: Partial. Infrastructure was seized and victims protected, but no operator was charged or arrested and a technically related operation appeared within months.

This page records organizational involvement as the cited sources state it. Where a role carries no description, the record gives none.

Last reviewed August 21, 2026