Phobos/8Base ransomware disruption
Extended pass entry, last reviewed August 21, 2026
What happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Partial
Did it stay down?
Not established in the public record. No later activity is recorded against this entry.
See what happened afterwardA multinational coalition disrupted more than 100 servers connected to the Phobos ransomware-as-a-service operation and the affiliated 8Base group, accompanied by arrests.
- Date
- February 2025
- Target
- Phobos and 8Base, ransomware group
- Activity
- Ransomware
- Operational lead
- Not established
- Partners
- Europol[1]
- European Union Agency for Law Enforcement Cooperation , coordinator
- Jurisdiction
- Not established
- Outcome
- More than 100 servers disrupted.
- Status
- Completed
- Legal mechanism
- Coordinated national judicial/search-and-seizure authority.
- Group accounted for
- Partial
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Partial
The cited record does not say how large the group was or whether everyone involved has been identified.
Not established in the public record. No later activity is recorded against this entry.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
Law enforcement disrupts Phobos ransomware and 8Base group
Establishes the disruption of more than 100 servers connected to Phobos/8Base.