Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

In December 2023, the FBI disrupted the ALPHV/BlackCat ransomware operation, seized several of its websites and provided a decryption tool to victims through law-enforcement channels. The tool helped many victims recover, but it was not a public download and was not guaranteed to work on every affected system.

What the FBI did to BlackCat

On December 19, 2023, the U.S. Department of Justice announced that the FBI had gained visibility into ALPHV’s computer network, seized several websites used by the group and developed a decryption tool. The FBI distributed the tool through its field offices and international law-enforcement partners.

Deputy Attorney General Lisa O. Monaco described the action this way: “In disrupting the BlackCat ransomware group, the Justice Department has once again hacked the hackers.” The operation was a law-enforcement disruption, not a claim that the ransomware threat had permanently ended.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How many victims were affected, and what did recovery achieve?

The Justice Department said in 2023 that ALPHV/BlackCat had targeted more than 1,000 victims worldwide since the group began operating. Its targets included U.S. critical infrastructure—among it government facilities, emergency services, defense industrial-base companies, critical manufacturing, healthcare and public-health facilities—as well as other corporations, government entities and schools.

At the time of the December 2023 announcement, the FBI said its tool had helped more than 500 affected victims restore systems and had spared victims ransom demands totaling approximately $68 million. A later Justice Department update in 2025 put the amount of ransom payments avoided through the same December 2023 effort at approximately $99 million. The figures reflect different reporting dates; the later figure is an updated accounting, not a separate recovery campaign. The Justice Department inspector general’s audit also records the FBI’s ALPHV/BlackCat decryption capability and approximately $99 million in avoided ransom demands.

How BlackCat’s ransomware operation worked

A ransomware-as-a-service model

BlackCat operated as ransomware-as-a-service. Its developers created and updated the ransomware and maintained the criminal infrastructure, while affiliates sought out and attacked high-value organizations. Developers and affiliates shared ransom proceeds.

Data theft as well as encryption

BlackCat affiliates used multiple forms of extortion. They could steal sensitive data before encrypting systems, demand payment for a decryption key and threaten to publish stolen material on a dark-web leak site if a victim refused to pay. A victim could therefore face exposure of stolen information even if systems were restored from other means.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can the FBI decrypt a BlackCat attack now?

The FBI’s tool was an assistance capability delivered through law-enforcement offices and partners, not a generally downloadable consumer application. The official announcements do not establish that every BlackCat-encrypted system can be decrypted, nor do they promise that the tool remains available for every case. A victim should contact a local FBI field office to ask what assistance may be available for their incident.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What a BlackCat victim should do

  1. Contact the local FBI field office. The Justice Department specifically encouraged BlackCat victims to do this to determine what assistance may be available.
  2. Consult the joint FBI, CISA and HHS #StopRansomware advisory. It provides known indicators, tactics, techniques and mitigations relevant to defenders.
  3. Report through official channels. The advisory directs organizations to report to the FBI and other official channels. Follow the reporting directions that apply to your organization and incident.

Availability of assistance depends on the case; the 2023 disruption does not by itself show that the group or its techniques can no longer pose a threat.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.