Feds Disrupt Ransomware Group That Targeted Healthcare

A ransomware group that has targeted hospitals and other critical infrastructure entities since 2022 has had some of its infrastructure seized by U.S. law enforcement agencies as part of a coordinated international operation. BlackSuit is a ransomware-as-a-service group that was first identified in the second quarter of 2023; however, its origins go back many years, having rebranded multiple times.

An analysis of the encryptor used by BlackSuit revealed it to be virtually identical to the encryptor used by the Royal ransomware group, leading researchers to the conclusion that the groups were the same. Royal first emerged in 2022 and was the successor to Quantum, which is thought to have been formed by members of the Conti ransomware group. The group’s origins could go back further still, as some security researchers have identified links to the Ryuk and Hermes ransomware groups.

Operating as Royal/BlackSuit, attacks have been conducted on multiple critical infrastructure sectors and private sector businesses, including healthcare, education, critical manufacturing, energy, and the government. Healthcare victims include the blood plasma provider Octapharma, South Africa’s National Health Laboratory Service, Revenetics, and Morris Hospital & Healthcare Centers to name just a few.

The group engages in double-extortion tactics, encrypting data and exfiltrating files, before demanding payment to prevent the release of the stolen data and to provide the decryptor. The group has been highly active, claiming more than 450 victims in the United States alone, amassing more than $370 million in ransom payments. The group was targeted by law enforcement in an operation codenamed Checkmate, which involved the Department of Homeland Security’s Homeland Security Investigations (HSI), U.S. Secret Service, IRS Criminal Investigation (IRS-CI), FBI, and law enforcement agencies in the United Kingdom, Germany, Ireland, France, Canada, Ukraine, and Lithuania.

Details of the operation were announced by the U.S. Department of Justice and HIS this month, confirming that four servers were seized and nine domains used by the group have been taken down, including the domains used for ransom negotiation and data leaks. The DOJ confirmed that laundered cryptocurrency valued at $1,091,453 was also seized – a portion of a $1,445,454.86 ransom payment from a victim in April 2023. The funds had been laundered through a cryptocurrency exchange, which froze the funds in January 2024. A warrant for the seizure of the funds was obtained, which was jointly unsealed by the U.S. Attorney’s Offices for the Eastern District of Virginia and the District of Columbia on August 11, 2025.

“Disrupting ransomware infrastructure is not only about taking down servers — it’s about dismantling the entire ecosystem that enables cybercriminals to operate with impunity,” said Deputy Assistant Director Michael Prado for HSI’s Cyber Crimes Center (C3). “This operation is the result of tireless international coordination and shows our collective resolve to hold ransomware actors accountable.”

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/