Is the BlackCat/AlphV ransomware gang self-destructing?

Share post:

The ongoing saga of the BlackCat/AlphV ransomware gang continues, with a news report that the crew has shut down its servers after a controversial hack of an American healthcare services provider.

Bleeping Computer says the gang’s data leak blog shut on Friday and the sites it uses to negotiate ransom payments closed today.

This comes after

— a gang affiliate last month was allegedly paid US$22 million after its data theft and ransomware attack disrupted the services of Change Healthcare, which provides a range of services to hospitals and clinics including processing pharmacy prescriptions and healthcare payments;

— on the heels of that incident, the BlackCat/AlphV operators reportedly plucked that payment back from the affiliate’s digital wallet before shutting down operations.

Got it?

Bleeping Computer says it’s unclear whether the closure is an exit scam or an attempt to rebrand the gang under a different name. BlackCat, the news service points out, is a rebrand of the DarkSide ransomware operation.

All this comes after American cyber authorities in December seized several of the group’s data leak and communications sites and published a decrypter that victim organizations can use to get access back to scrambled data.

It isn’t unknown why BlackCat/AlphV operators struck at one of its partners. Because of the December hit, the gang said it removed all of its rules forbidding affiliates allowed to use its ransomware to attack critical infrastructure like the healthcare sector.

In fact, the attack on Change Healthcare appeared to be a sign that BlackCat/AlphV had bounced back from the December blow.

Rick Pollack, CEO of the American Hospitals Association, called it “the most serious incident of its kind levelled against an U.S. healthcare organization.” According to Change Healthcare, he noted, the company processes 15 billion healthcare transactions annually and touches one in every three American patient records.

The incident is serious enough that, according to Politico, the White House’s National Security Council started looking into ways to provide short-term financial relief to U.S. hospitals. Arguably, attention from the White House is not what a ransomware gang wants.

The post Is the BlackCat/AlphV ransomware gang self-destructing? first appeared on IT World Canada.
Howard Solomon
Howard Solomon
Currently a freelance writer, I'm the former editor of and Computing Canada. An IT journalist since 1997, I've written for and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.


Related articles

FBI rapidly hacks into Trump shooter’s phone, raises privacy concerns

Just two days after the attempted assassination at a Trump rally, the FBI announced it had gained access...

Disney investigating a potential major leak of internal communications

Disney is investigating a significant data breach by the hacking group Nullbulge, which claims to have accessed and...

Kaspersky to shut down its US business due to sanctions

Russian cybersecurity firm Kaspersky Lab announced it will cease its U.S. operations starting July 20, following sanctions from...

Google’s Gemini AI caught scanning private Google Drive documents without permission

Google's Gemini AI has come under fire for scanning private PDF documents in Google Drive without user consent....

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways