Jaded Security

OPINION · 2026-08-23The Ransomware Takedown Press Release Is Its Own Genre

– Boris Sverdlik

There is a template now, and once you have read one of these you have read all of them. Law enforcement seizes a server, a leak site goes dark or picks up a cheeky replacement banner, and a press release goes out with a verb chosen from a very short list. Disrupted. Dismantled. Taken down. The numbers follow close behind: victims counted in the hundreds or thousands, damages in the hundreds of millions, servers tallied by the dozen. Then a quote from an official about resolve and consequences, a line thanking international partners, and a closing note that the investigation is ongoing. The document is not written for the people who ran the operation. They already know exactly what happened. It is written for everyone else.

The genre is worth reading on its own terms, because the space between what these announcements say and what the record shows a few weeks later is where the interesting part lives. And to be fair up front, the seizures are not nothing. Keys handed back to victims are real, measurable harm reduction. The quarrel here is not with the police work. It is with the language, which is engineered to sound like a verdict when the record keeps showing something closer to a delay.

The cleanest version of the story

Start with Hive, because it is about as tidy as this gets. In January 2023 the Justice Department announced that the FBI had been quietly inside Hive’s network since the previous July, pulling decryption keys as they were minted and handing them to victims before the ransom notes could do their work. The department credited that access with heading off roughly $130 million in demanded payments, against a group that had hit more than 1,500 organizations across some 80 countries. The servers went down in coordination with German police and the Dutch high-tech crime unit. You can read the whole thing in the department’s own words, and it is a genuinely good piece of work.

Notice what the announcement does not contain, though. Arrests. The people who ran Hive were not in a courtroom that day, or any day since under that name. The infrastructure was taken, the victims were helped, and the operators walked. The verb “disrupted” is doing an enormous amount of quiet work there, because it is technically accurate and emotionally misleading at the same time. A reader skimming the headline hears “gang gone.” The record says “gang inconvenienced, then free to rebuild the tooling somewhere the FBI is not.”

The theatrical peak

Then there is Operation Cronos, which in February 2024 turned the genre into performance art. A ten-country task force led by Britain’s National Crime Agency seized 34 servers, grabbed decryption keys, froze more than 200 cryptocurrency accounts, and made two arrests in Poland and Ukraine. Then it did the part everyone remembers: it took over LockBit’s own leak site and repurposed the countdown timers to publish information about the gang, trolling the operators with their own format. It was clever, and it was clearly meant to humiliate. For a group that ran on reputation, humiliation is a legitimate tactic.

The reputation damage was real. The durability was not. Within days LockBit was posting again from fresh infrastructure, complete with a long, aggrieved statement about how the takedown had gone. A few months later the United States, Britain, and Australia named and sanctioned a Russian national, Dmitry Khoroshev, as the person behind the “LockBitSupp” handle, with a 26-count American indictment attached. Brian Krebs walked through how investigators say they got there, and it is a fine piece of attribution. Khoroshev, for his part, remained in Voronezh, disputed that they had the right man, and was never handed over. Naming someone who lives comfortably beyond your extradition reach is a real accomplishment for the historians and a footnote for the victims.

The takedown as cover story

The ALPHV episode, also known as BlackCat, is the one that should have retired the genre entirely. In December 2023 the FBI seized the group’s site and released a decryptor. ALPHV promptly posted an “unseized” notice and kept going, which was embarrassing enough. What came next was worse. Early in 2024 an ALPHV affiliate hit Change Healthcare, the claims-processing spine of a large slice of American medicine, and a payment reported at around $22 million moved. ALPHV took the entire sum, posted a fake law-enforcement seizure banner on its own site to muddy the water, and vanished, stiffing the affiliate who still held the stolen data. That affiliate then went looking for a new brand to re-extort under. The takedown notice, in other words, became a prop in the criminals’ own exit scam. When the fake seizure banner and the real one look identical, the real one has a branding problem.

The brand dies, the people do not

This is the pattern the press release is structured to obscure. What gets taken down is almost always a brand, and brands are cheap. When Conti pledged its loyalty to Russia in early 2022 and promptly had its internal chat logs leaked to the world, the Conti name wound down within months. The people did not retire. They reconstituted under new names, and the security firms tracking them spent the next year drawing lineage diagrams from Conti to Black Basta to Royal and onward. DarkSide became BlackMatter became part of the ALPHV story. The org chart survives the logo change, because the org chart is a loose federation of developers, access brokers, and affiliates who were never dependent on any single storefront.

None of this is new, which is the part the industry keeps forgetting. Go back to March 2012, when the FBI revealed that Hector Monsegur, the LulzSec figure known as Sabu, had been an informant for the better part of a year, and used that cooperation to charge his associates. The announcements framed it as decapitating the crew, and in the narrow sense of that specific crew they were right. But anyone who followed the Stratfor dump and the wider AntiSec season knew the impulse behind it did not live inside five or six people. The names changed. The template for announcing the win did not. If you lined up the LulzSec statements next to the LockBit ones, you would mostly be updating the proper nouns.

Who the document is really for

So who reads a takedown press release and comes away satisfied? Not the operators, who have already migrated. Not the victims, who mostly needed the keys and got them regardless of the adjectives. The audience is the boards that fund the agencies, the legislators who ask why nothing is ever done, the insurers pricing the next policy year, and the public that wants to believe the phenomenon has an off switch. The genre exists to convert a server seizure, which is a real and useful thing, into a story of justice served, which is usually not what happened. Both facts can be true at once, and the honest version of the announcement would say so.

The desk is not asking anyone to stop celebrating the wins. Distributing decryption keys to 1,500 organizations is a better afternoon’s work than most of the security industry manages in a year of conference keynotes. The ask is smaller and more annoying: read the verb, then check the record a month later, and notice how reliably “dismantled” ages into “regrouped under a new name.” The takedown press release is one of the few pieces of security writing with a genuinely consistent house style. It is just worth remembering that the style was chosen, and that it was chosen for an audience that will never read the follow-up.


Jaded Security