<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cyberattack Case Library: Ransomware &amp; Extortion Feed</title>
    <link>https://cybercaselibrary.com/ransomware/</link>
    <description>All ransomware incidents, extortion demands, cryptocurrency seizures, and decryption milestones.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:02:15 GMT</lastBuildDate>
    <atom:link href="https://cybercaselibrary.com/feeds/ransomware.xml" rel="self" type="application/rss+xml"/>
    
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Khoroshev et al. (LockBit Ransomware Operation)]]></title>
      <link>https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/</link>
      <guid>https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/</guid>
      <description><![CDATA[Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Tue, 07 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: ALPHV / BlackCat Ransomware Attack on Change Healthcare]]></title>
      <link>https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/</link>
      <guid>https://cybercaselibrary.com/cases/alphv-blackcat-change-healthcare/</guid>
      <description><![CDATA[Devastating ransomware attack and data extortion of Change Healthcare (UnitedHealth Group) that paralyzed medical billing, prescription processing, and healthcare provider reimbursement nationwide.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: Colonial Pipeline DarkSide Ransomware Attack]]></title>
      <link>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/colonial-pipeline-ransomware/</guid>
      <description><![CDATA[DarkSide ransomware extortion against the largest refined petroleum pipeline system in the United States, forcing the shutdown of 5,500 miles of fuel pipelines and triggering widespread East Coast fuel shortages.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Fri, 07 May 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-yakubets-evil-corp-dridex/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-yakubets-evil-corp-dridex/</guid>
      <description><![CDATA[Leader and core administrator of Evil Corp charged with deploying Bugat/Dridex banking malware and ransomware, stealing dozens of millions of dollars from bank accounts of municipalities, school districts, and businesses.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Thu, 14 Nov 2019 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-park-jin-hyok-lazarus/</guid>
      <description><![CDATA[Department of Justice charges North Korean state-sponsored programmer with the 2014 Sony Pictures hack, the 2017 global WannaCry ransomware outbreak, and the $81 million Bangladesh Bank cyber heist.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Fri, 08 Jun 2018 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Vachon-Desjardins (Netwalker Ransomware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-vachon-desjardins-netwalker/</guid>
      <description><![CDATA[Affiliate of Netwalker ransomware responsible for attacking dozens of healthcare systems, universities, and businesses during the COVID-19 pandemic, extorting tens of millions of dollars.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 16 Dec 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-vasinskyi-kaseya-revil/</guid>
      <description><![CDATA[Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 11 Aug 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Anatoly Legkodymov (Bitzlato Cryptocurrency Laundering)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-legkodymov-bitzlato/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-legkodymov-bitzlato/</guid>
      <description><![CDATA[Founder of Hong Kong-registered cryptocurrency exchange Bitzlato charged with laundering over $700 million in ransomware and darknet market illicit proceeds, serving as a primary financial conduit for Hydra Market.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Tue, 17 Jan 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Minh Quoc Nguyen (ChipMixer Cryptocurrency Mixer)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-nguyen-chipmixer/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-nguyen-chipmixer/</guid>
      <description><![CDATA[Operator of ChipMixer, one of the dark web's largest unlicensed cryptocurrency mixing services, charged with laundering more than $3 billion in Bitcoin associated with ransomware, North Korean state hackers, and darknet drug markets.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 15 Mar 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-witte-dunaev-trickbot/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-witte-dunaev-trickbot/</guid>
      <description><![CDATA[Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Thu, 18 Feb 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Marcus Hutchins (Kronos Banking Malware)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-hutchins-kronos-malware/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-hutchins-kronos-malware/</guid>
      <description><![CDATA[British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 12 Jul 2017 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Peter Levashov (Kelihos Botnet)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-levashov-kelihos-botnet/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-levashov-kelihos-botnet/</guid>
      <description><![CDATA[Russian operator (Severa) of the notorious Kelihos botnet, controlling over 100,000 infected computers worldwide used to harvest credentials, distribute ransomware, and blast billions of spam and stock pump-and-dump emails daily.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Fri, 07 Apr 2017 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Rui-Siang Siew (Incognito Market Darknet Extortion)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-siew-incognito-market/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-siew-incognito-market/</guid>
      <description><![CDATA[Owner and operator of Incognito Market who facilitated over $100 million in illicit darknet transactions before orchestrating an exit scam and extorting registered vendors and buyers with doxxing threats.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Maksim Boiko (QQAAZZ Cyber Laundering Network)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-boiko-qqaazz-laundering/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-boiko-qqaazz-laundering/</guid>
      <description><![CDATA[Russian cryptocurrency trader and Instagram influencer who operated as a high-level money launderer for QQAAZZ, an all-in-one cashout network servicing Dridex, Trickbot, and BitPaymer ransomware gangs.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Tue, 15 Sep 2020 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Daniel Rhyne (Industrial Insider Extortion)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-rhyne-insider-ransomware-extortion/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-rhyne-insider-ransomware-extortion/</guid>
      <description><![CDATA[Core infrastructure systems engineer who staged an extortion scheme against his own industrial employer, locking coworkers out of Active Directory domain controllers, changing administrator passwords, and demanding $750,000 in cryptocurrency.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Tue, 16 Apr 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)]]></title>
      <link>https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/</link>
      <guid>https://cybercaselibrary.com/cases/us-v-sikerin-polyanin-revil-affiliates/</guid>
      <description><![CDATA[International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Mon, 08 Nov 2021 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: MGM Resorts Cyberattack (Scattered Spider / ALPHV Vishing Ingress)]]></title>
      <link>https://cybercaselibrary.com/cases/mgm-resorts-scattered-spider/</link>
      <guid>https://cybercaselibrary.com/cases/mgm-resorts-scattered-spider/</guid>
      <description><![CDATA[Sophisticated social engineering and ransomware attack carried out by cybercrime collective Scattered Spider partnering with ALPHV/BlackCat, utilizing a 10-minute phone call to the Okta IT helpdesk to bypass MFA, hijack administrative privileges, and paralyze hotel reservations, digital keys, and casino slot machines.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Thu, 05 Oct 2023 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: Change Healthcare Ransomware Outage (ALPHV / BlackCat)]]></title>
      <link>https://cybercaselibrary.com/cases/change-healthcare-blackcat-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/change-healthcare-blackcat-ransomware/</guid>
      <description><![CDATA[Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: CDK Global BlackSuit Ransomware Incident]]></title>
      <link>https://cybercaselibrary.com/cases/cdk-global-blacksuit-ransomware/</link>
      <guid>https://cybercaselibrary.com/cases/cdk-global-blacksuit-ransomware/</guid>
      <description><![CDATA[Destructive ransomware incident that incapacitated CDK Global, the premier SaaS dealer management platform for approximately 15,000 car dealerships across North America. Attackers deployed BlackSuit ransomware throughout CDK cloud and on-premises data centers, forcing dealership employees into pen-and-paper workarounds for weeks until an estimated $25 million ransom was transferred.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Wed, 19 Jun 2024 00:00:00 GMT</pubDate>
    </item>
  
    <item>
      <title><![CDATA[Ransomware Case: AT&T Cloud Telecom Call and Text Metadata Exfiltration]]></title>
      <link>https://cybercaselibrary.com/cases/att-telecom-metadata-snowflake-breach/</link>
      <guid>https://cybercaselibrary.com/cases/att-telecom-metadata-snowflake-breach/</guid>
      <description><![CDATA[Illegal exfiltration of call and text interaction metadata spanning six months for approximately 110 million AT&T wireless customers. Intrusion stemmed from an illicit access point to a third-party Snowflake cloud environment, leading to a 5.7 Bitcoin extortion fee paid through an intermediary to obtain verified video evidence of dataset deletion.]]></description>
      <category><![CDATA[Ransomware & Extortion]]></category>
      <pubDate>Fri, 12 Jul 2024 00:00:00 GMT</pubDate>
    </item>
  
  </channel>
</rss>