The U.S. State Department offers rewards of up to $10 million for information that could help locate, identify, or arrest members of the Hive ransomware gang.
The FBI says this ransomware group had extorted roughly $100 million from over 1,300 companies across more than 80 countries between June 2021 and November 2022.
In January 2023, the U.S. government also announced rewards of up to $10 million for tips that could help link Hive ransomware with foreign governments.
The State Department has previously announced bounties of up to $15 million for location information on members of the Clop, Conti [1, 2], REvil, and Darkside ransomware operations.
These rewards are offered through the Transnational Organized Crime Rewards Program, with over $135 million paid for helpful tips since 1986.
The offer comes after an international law enforcement operation led to the seizure of Hive ransomware's Tor websites in January 2023.
As part of this joint action, FBI agents infiltrated Hive servers at a hosting provider in California in July 2022 and secretly monitored the gang's activity for six months.
The FBI also discovered Hive communication records, malware file hashes, and information on 250 affiliates.
The Hive ransomware-as-a-service operation surfaced in June 2021, and its operators are known for breaching organizations via phishing campaigns, exploiting vulnerabilities in internet-exposed devices, and using purchased credentials.
Unlike other ransomware groups that avoid targeting emergency services and healthcare entities, Hive does not discriminate and will breach and encrypt any target.
US announces visa ban on those linked to commercial spyware.
Water services giant Veolia North America hit by ransomware attack.
Hospitals ask courts to force cloud storage firm to return stolen data.
FBI: Play ransomware breached 300 victims, including critical orgs.
Norton Healthcare discloses data breach after May ransomware attack.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 08 Feb 2024 18:00:53 +0000