[Back to the takedown index](https://takedownindex.org/takedowns)

# Radar/Dispossessor ransomware disruption

August 2024, Ransomware
Led by [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation)

Extended pass entry, last reviewed August 21, 2026

What was taken down?

Domains, servers, and IP infrastructure disabled or seized across three countries.

[See what happened](#what-happened)

What happened to the people?

1 publicly wanted named in the public record.
Group accounted for: Members remain at large

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

FBI Cleveland/DOJ, with UK NCA and German authorities, disabled or seized domains, servers, and IP infrastructure in the US, UK, and Germany connected to the Radar/Dispossessor ransomware group.

**Date:** August 2024

**Target:** Radar (also known as Dispossessor), ransomware group

**Activity:** Ransomware

**Operational lead:** FBI

**Partners**

BKA, NCA[[1]](#source-1)

- [Bundeskriminalamt](https://takedownindex.org/organizations/bundeskriminalamt), supporting
- [National Crime Agency](https://takedownindex.org/organizations/national-crime-agency), supporting

**Jurisdiction:** Not established

**Outcome:** Domains, servers, and IP infrastructure disabled or seized across three countries.

**Status:** Completed

**Legal mechanism:** Federal seizure warrant; coordinated UK/German judicial authority.

**Group accounted for:** Members remain at large

## People and accountability

Named in the public record: 1 publicly wanted.

Figures count individuals named in charging documents and official statements, each person once per outcome. People alleged to be involved but not publicly identified are not counted.

#### Unidentified individual known as "Brain"

Alleged operator of Radar/Dispossessor. Current public status: Publicly wanted.

**Charging authority:** Not established in the public record

**Main charges:** Not established in the public record

**Case number:** Not established in the public record

**Arresting authority:** Not established in the public record

**Arrest location:** Not established in the public record

**Extradition status:** Not established in the public record

**Conviction or plea:** Not established in the public record

**Sentence:** Not established in the public record

**Segment:** Core operator

**Sources:** [[1]](#source-1)

**Full record:** [Everything indexed for Unidentified individual known as "Brain"](https://takedownindex.org/people/unidentified-individual-known-as-brain)

Group accounted for: Members remain at large

The alleged operator, known only by the alias 'Brain,' was identified as believed to be in Europe; no arrest was announced.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/radar-dispossessor-ransomware-disruption/organizations)

## What happened afterward

Not established in the public record. No later activity is recorded against this entry.

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[Radar/Dispossessor ransomware infrastructure disabled](https://takedownindex.org/sources/us-doj-fbi-cleveland-radar-dispossessor-ransomware-infrastructure-disabled)

US DOJ / FBI Cleveland, August 12, 2024, Source grade S2

Establishes the disabling of Radar/Dispossessor infrastructure across the US, UK, and Germany, and the 'Brain' alias for the alleged operator.

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Added from deep-research aggregation pass. Not independently re-verified source-by-source to the same standard as the original 38-incident core; source\_quality capped at S2/P2 pending a dedicated verification pass.

Research context

## How this entry was checked

This entry came from a broader aggregation pass and has not been independently verified source by source. Its sources are graded no higher than P2 or S2, and most carry no address yet. Treat the figures as a research lead rather than a settled record.

Source review: Extended pass, not yet verified

Sources cited: 1

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Raptor Train botnet disruption](https://takedownindex.org/takedowns/raptor-train-botnet-disruption)
- [Operation Magnus (RedLine and META infostealers)](https://takedownindex.org/takedowns/operation-magnus-redline-and-meta-infostealers)
- [911 S5 botnet dismantlement](https://takedownindex.org/takedowns/911-s5-botnet-dismantlement)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
