Skip to main content
Back to the takedown index

Radar/Dispossessor ransomware disruption

August 2024, Ransomware
Led by Federal Bureau of Investigation

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Domains, servers, and IP infrastructure disabled or seized across three countries.

See what happened

What happened to the people?

1 publicly wanted named in the public record.
Group accounted for: Members remain at large

See people and accountability

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

See what happened afterward

FBI Cleveland/DOJ, with UK NCA and German authorities, disabled or seized domains, servers, and IP infrastructure in the US, UK, and Germany connected to the Radar/Dispossessor ransomware group.

Date
August 2024
Target
Radar (also known as Dispossessor), ransomware group
Activity
Ransomware
Operational lead
FBI
Partners
BKA, NCA[1]
Jurisdiction
Not established
Outcome
Domains, servers, and IP infrastructure disabled or seized across three countries.
Status
Completed
Legal mechanism
Federal seizure warrant; coordinated UK/German judicial authority.
Group accounted for
Members remain at large

1
publicly wanted

Named in the public record: 1 publicly wanted.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

Person Role Current public status
Alleged operator of Radar/Dispossessor Publicly wanted
Charging authority
Not established in the public record
Main charges
Not established in the public record
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Unidentified individual known as "Brain"

Alleged operator of Radar/Dispossessor. Current public status: Publicly wanted.

Charging authority
Not established in the public record
Main charges
Not established in the public record
Case number
Not established in the public record
Arresting authority
Not established in the public record
Arrest location
Not established in the public record
Extradition status
Not established in the public record
Conviction or plea
Not established in the public record
Sentence
Not established in the public record
Segment
Core operator
Sources
[1]

Rows expand to show charging authority, case identifiers, custody status, and sources.

Group accounted for: Members remain at large

The alleged operator, known only by the alias 'Brain,' was identified as believed to be in Europe; no arrest was announced.

See the organizations and roles behind this action

Not established in the public record. No later activity is recorded against this entry.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    Radar/Dispossessor ransomware infrastructure disabled

    US DOJ / FBI Cleveland, August 12, 2024, Source grade S2

    Establishes the disabling of Radar/Dispossessor infrastructure across the US, UK, and Germany, and the 'Brain' alias for the alleged operator.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source_quality capped at S2/P2 pending a dedicated verification pass.