Found an error?
Report now
ILLUSTRATION - A laptop infected with a fictitious encryption Trojan (ransomware) is located in an office. This software encrypts the files on the hard disk without the user's intervention and only releases them again once the user has paid a ransom. Photo: Lino Mirgeler/dpa
Keystone
Almost 200 victims and millions in losses: International investigators have succeeded in striking a blow against globally active cybercriminal blackmailers. The technical infrastructure of the Blacksuit/Royal group has been identified and confiscated, according to the State Criminal Police Office (LKA) of Lower Saxony. By shutting down the servers, the communication, the distribution of the malware and the perpetrators' website were hit.
More than 500 million US dollars in damage
The investigators speak of 184 victims worldwide, some of whom were also registered in Germany. Officials put the amount of damage identified in August 2024 at more than 500 million US dollars (around 430 million euros). Considerable amounts of data were secured at the end of July during the long-term planned operation. This data will be analyzed to clarify the situation and identify those responsible.
"We are thus sending a clear signal in the fight against crime in the digital space," LKA President Thorsten Massinger was quoted as saying in a press release. Attacks on companies, public institutions and private individuals will be countered with all available means. The investigating authorities called on victims to report attacks in order to prevent further acts.
Perpetrators extort twice
According to the investigators' description, the attacks involve double extortion. The attackers not only encrypt data, but also steal it beforehand. This means that the perpetrators have a copy, even if the victims themselves are able to restore their files. They then threaten to publish or sell the data in order to extort a ransom.
Investigators will provide details of the successful search at a press conference in Hanover today (12.30 p.m.).