• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    ATM jackpotting-FBI

    ATM Jackpotting Losses Cross $20M as Malware Targets U.S. Cash Machines

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    The Cyber Express Weekly Roundup

    The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape

    French National Bank Authority, FICOBA, CNIL

    French National Bank Authority Breach Exposed 1.2 Million Accounts

    Responsible AI

    What Big Tech Leaders Said On AI’s Future at India AI Impact Summit 2026

    Israel Data Breach

    Two Petabytes Worth Data of Israeli’s Siphoned, Says Cyber Head

    UMMC cyberattack

    Cyberattack Forces Clinic Closures, Surgery Cancellations at University of Mississippi Medical Center

    VS Code extensions

    Critical Security Flaws Discovered in Four VS Code Extensions Affecting Millions

    AI in education

    AI Has Entered Schools—But What About Its Responsible Use?

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Digital Services Act

    X vs EU: Platform Appeals Against €120M Digital Services Act Penalty

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    French National Bank Authority, FICOBA, CNIL

    French National Bank Authority Breach Exposed 1.2 Million Accounts

    AI in education

    AI Has Entered Schools—But What About Its Responsible Use?

    Responsible AI

    Responsible AI at Scale Demands Cyber Readiness, Experts at India AI Impact Summit Warn

    Lockdown Mode, ChatGPT

    OpenAI’s New Enterprise Security Mode Locks Down ChatGPT Against Prompt Injection

    Cyber Essentials

    Think You’re Too Small to Be Hacked? NCSC Says Think Again

    Grok AI, Grok, Elon Musk, Case against X, Platform X,

    Ireland Opens GDPR Probe Into Grok’s AI-Generated Deepfakes of Children

    India AI Impact Summit 2026

    AI a Tool for Inclusion, Jobs and Global Cooperation: India AI Impact Summit 2026

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    ATM jackpotting-FBI

    ATM Jackpotting Losses Cross $20M as Malware Targets U.S. Cash Machines

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    The Cyber Express Weekly Roundup

    The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape

    French National Bank Authority, FICOBA, CNIL

    French National Bank Authority Breach Exposed 1.2 Million Accounts

    Responsible AI

    What Big Tech Leaders Said On AI’s Future at India AI Impact Summit 2026

    Israel Data Breach

    Two Petabytes Worth Data of Israeli’s Siphoned, Says Cyber Head

    UMMC cyberattack

    Cyberattack Forces Clinic Closures, Surgery Cancellations at University of Mississippi Medical Center

    VS Code extensions

    Critical Security Flaws Discovered in Four VS Code Extensions Affecting Millions

    AI in education

    AI Has Entered Schools—But What About Its Responsible Use?

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Digital Services Act

    X vs EU: Platform Appeals Against €120M Digital Services Act Penalty

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    French National Bank Authority, FICOBA, CNIL

    French National Bank Authority Breach Exposed 1.2 Million Accounts

    AI in education

    AI Has Entered Schools—But What About Its Responsible Use?

    Responsible AI

    Responsible AI at Scale Demands Cyber Readiness, Experts at India AI Impact Summit Warn

    Lockdown Mode, ChatGPT

    OpenAI’s New Enterprise Security Mode Locks Down ChatGPT Against Prompt Injection

    Cyber Essentials

    Think You’re Too Small to Be Hacked? NCSC Says Think Again

    Grok AI, Grok, Elon Musk, Case against X, Platform X,

    Ireland Opens GDPR Probe Into Grok’s AI-Generated Deepfakes of Children

    India AI Impact Summit 2026

    AI a Tool for Inclusion, Jobs and Global Cooperation: India AI Impact Summit 2026

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily Dark Web News

The Cat-and-Mouse Game: ALPHV Ransomware vs. FBI – A Cybersecurity Saga Unfolds

The seized website was promptly replaced with a splash page announcing the successful operation, forming part of the FBI's comprehensive campaign.

Ashish Khaitan by Ashish Khaitan
July 9, 2025
in Dark Web News, Firewall Daily, Main Story
0
BlackCat ransomware gang and FBI
665
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

In an unusual turn of events within the waters of the dark web, the Federal Bureau of Investigation (FBI) found itself entangled in a back-and-forth confrontation with the notorious  

ALPHV/BlackCat ransomware gang. This unexpected clash marked a rare instance of a government agency engaging with a cybercriminal group, challenging the conventional narrative. 

The FBI initiated a decisive move last year, a large scale takedown of the darknet website associated with the infamous ALPHV/BlackCat ransomware gang.

The seized website was promptly replaced with a splash page announcing the successful operation, forming part of the FBI’s comprehensive campaign to hault services offerred by the threat actor.  

The ALPHV ransomware gang, also recognized as BlackCat, retaliated by regaining control over its dark website on multiple occasions. This triggered an intense back-and-forth struggle on the dark web, pitting the criminal syndicate against the formidable U.S. government agency.   

Understanding the Turmoil: FBI’s Infiltration and Seizure 

ALPHV/BlackCat's leak site,
Source: Techcrunch

The Department of Justice, in a statement, disclosed details of its “disruption campaign,” revealing that a confidential source played a pivotal role in helping the FBI access more than 900 public/private key pairs controlling ALPHV ‘s darknet infrastructure.  

report-ad-banner

This operation allowed the FBI to monitor the gang’s activities for months, culminating in the successful seizure of its websites in December. The ALPHV /BlackCat ransomware gang has been a prolific threat, earning $300 million in ransom proceeds from over 1,000 victims worldwide, as reported by the FBI. 

As part of the intervention, the FBI obtained decryption keys, enabling the release of keys for approximately 500 affected organizations. This move facilitated these organizations in regaining control of their data, preventing an estimated $68 million in ransom demands.  

The ALPHV ransomware group, identified as the second most prolific ransomware variant by NCC Group’s leak data statistics, had compromised over 1,000 entities globally, according to the FBI. This number surpassed previous estimates, indicating the extent of the cyber threat posed by the ALPHV gang. 

In a conversation with TCE, vulnerability researcher and exploit developer, Alexandre Borges, shared his take on the effectiveness of law enforcement efforts against ransomware groups like LockBit. In his take, Alexandre says, “I really like the FBI approach because they do everything that is possible and expected according to laws. These criminals must be convicted and punished by their acts, and the only possible approach to extend the coverage is through joint task forces with other countries to condemn and restrict the movement of these criminals.” 

ALPHV ‘s Counteractions and Rule Changes 

In response to the FBI’s actions, the ALPHV /BlackCat ransomware group initiated counteractions, including reclaiming control of its dark website multiple times. Notably, the group altered its rules for ransomware-as-a-service operations, expanding the scope of their attacks to include hospitals and nuclear power plants. This move marked a drastic shift in strategy, raising concerns about the potentially catastrophic consequences of their attacks. 

BlackCat ransomware group
Source: AzAl Security on X

The ALPHV ransomware gang also modified its affiliate program by increasing the cut to 90%, possibly as an incentive for affiliates to remain loyal. Interestingly, reports surfaced of the LockBit ransomware attempting to poach developers and affiliates from the ALPHV /BlackCat group, showcasing the competitive landscape within the cybercriminal ecosystem. 

The Cybersecurity and Infrastructure Security Agency (CISA) highlighted that, as of September 2023, ALPHV ‘s affiliates had compromised over 1,000 entities, with nearly 75% located in the United States. 

The group demanded over $500 million and received almost $300 million in ransom payments. The takedown of ALPHV was part of a broader effort that also targeted other significant cyber threats, including the Kingdom Market and the dismantling of 3,500 online fraudsters. 

Dark Web Conversations and Solidarity Among Cybercriminals 

In follow-up events, dark web conversations between the ALPHV ransomware group and LockBit revealed an unexpected level of professionalism and solidarity. Threat actors from both groups expressed understanding and support for each other, acknowledging the collective threat posed by law enforcement agencies, particularly the FBI. These conversations shed light on the intricate dynamics within the cybercriminal community and the shared challenges they face. 

The takedown of the ALPHV ransomware gang involved a multinational effort, with the FBI collaborating with around a dozen agencies, including the U.S. Department of Justice, the U.S. Secret Service, Europol, and the German Federal Criminal Police Office.  

Logos from the national police forces of Australia, Spain, Estonia, Austria’s Directorate of State Security and Intelligence, the United Kingdom’s National Crime Agency, and the Eastern Region Special Operations Unit were featured on the splash page. The U.S. Rewards for Justice Program’s logo, offering rewards for information contributing to national security, was also prominently displayed. 

The ALPHV /BlackCat ransomware gang, notorious for its scale and impact, has evolved its techniques to elude defense systems. The FBI and CISA revealed that the group employs advanced social engineering techniques and open-source research to gain initial access to a target’s network. Affiliates pose as company IT or helpdesk staff, using phone calls or SMS messages to obtain credentials. The group utilizes live chat to convey demands and initiate processes for restoring encrypted files. 

Decline in Ransom Payments and the Changing Nature of Cybercrime 

The decline in ransom payments to cybercriminal organizations like ALPHV is attributed to multiple factors. Organizations are increasingly unwilling to pay criminals residing in certain countries or associated with sanction lists. Additionally, the dishonest and unscrupulous behavior of affiliates has further deterred victims from complying with extortion demands. The landscape of ransomware attacks is shifting, with organizations opting not to pay and restoring systems from backups becoming the norm.  

The LockBit ransomware group recently expressed their perspective on the ALPHV situation and acknowledged the threat posed by the FBI. LockBit highlighted the vulnerability of its own dashboard and emphasized the need for enhanced security measures. The administrators affirmed their commitment to continue operations under the LockBit brand, even in the event of a hypothetical FBI hack. 

Talking about taking a stand against ransomware groups, Alexandre said, “Ransomware groups, and LockBit in special, explore typical system failures such as employees using weak passwords, absent of MFA, vulnerable and unpatched operating system and programs, excess of privilege for daily applications, non-segmented networks, and misconfigured defense products.” 

“The usual recommendation for Windows systems would be adopt measures as VBS and Credential Guard, reduce privileges of applications, use resources like AppLocker, have an efficient logging configuration including auditing and ETW, restrict exposed services on the Internet (RDP and SMB are obvious, but there are other ones), perform continuous scanning on the corporate network to detect possible vulnerabilities and exposed services, have a proven-effective real backup policies implemented and, the most important actions, provide employees with awareness training to prevent them been victimized by phishing attacks”, added Alexandre. 

The takedown of the ALPHV /BlackCat ransomware gang by the FBI highlights the challenges faced by law enforcement agencies in combating these notorious hacker groups. As cyber criminals adapt and evolve, law enforcement agencies face the challenge of staying ahead in the cat-and-mouse game. The intricate dynamics among cybercriminal groups, as revealed in dark web conversations, provide insights into the motivations and challenges within the underground ecosystem. 

Conclusion 

The FBI’s takedown of the ALPHV /BlackCat ransomware gang marks a significant step in the ongoing battle against cybercrime. The collaborative effort involving multiple international agencies highlights the global nature of ransomware groups and the combined cybercrime market.

The evolving strategies of ransomware groups and the changing realm of ransom payments emphasize the need for continuous vigilance and adaptive cybersecurity measures to protect organizations and individuals from these malicious threats.  

Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: ALPHV /BlackCat groupBlackCat Ransomware GangFBIThe Cyber ExpressThe Cyber Express News
Previous Post

Navigating the API Minefield: Top Security Risks and How to Defuse Them

Next Post

AI for Cybersecurity Resilience: Navigating Challenges in the Digital Age

Next Post
Artificial Intelligence cybersecurity challenges

AI for Cybersecurity Resilience: Navigating Challenges in the Digital Age

Upcoming Webinar

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

ATM jackpotting-FBI
Cyber News

ATM Jackpotting Losses Cross $20M as Malware Targets U.S. Cash Machines

February 23, 2026
Digital Services Act
Cyber Essentials

X vs EU: Platform Appeals Against €120M Digital Services Act Penalty

February 23, 2026
Terrorist Cyberattacks, UAE Cyber Security Council
Cyber Warfare

UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

February 23, 2026
The Cyber Express Weekly Roundup
Firewall Daily

The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape

February 20, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information