logo
Intel gathered following HSE attack leads to dismantling of ransomware gang

Intel gathered following HSE attack leads to dismantling of ransomware gang

Irish Timesa day ago
Intelligence gathered by
gardaí
following the 2021
HSE
cyberattack has led directly to the dismantling of an international cybercrime crime gang by
US
authorities.
The Garda National Cyber Crime Bureau played a central role in the 'major disruption' operation which took down the critical infrastructure of the BlackSuit Ransomware Group.
The group is responsible for extorting over €300 million in ransom payments since 2022 from victims who were the targets of ransomware attacks.
The BlackSuit gang is a successor to the Conti ransomware group which demanded a ransom from the Irish Government after locking down the systems of the HSE during the Covid-19 pandemic in May 2021.
READ MORE
The incident,
which was the largest attack on a health system in history
, shut down thousands of systems across the country and cost almost €55 million to repair.
In the months after the attack, specialist gardaí gathered large amounts of intelligence on the Conti gang's operations and tactics which were shared with international partners.
'This information directly led to the American-led operation,' said a source.
According to a Garda statement, the operation targeted an international group said to be responsible for 'serious ransomware attacks' globally and was led by the US Immigration and Customs Enforcement (Ice).
It resulted in the seizure and takedown of operational infrastructure used by the BlackSuit group, which was described as a 'major cybercriminal operation' by Ice.
This infrastructure included servers, domains and digital assets used to deploy ransomware, extort victims and launder proceeds, An Garda Síochána said.
Among them was a dark web leaks page, a website maintained on the darknet where the data of victims who refuse to pay a ransom is published.
A victim negotiation site, used by ransomware gangs to communicate with victims and arrange the payment of ransoms, was also taken down.
The BlackSuit ransomware group is an organised crime group responsible for the commission of ransomware and 'other serious cyber criminality internationally', the Garda said.
It emerged in 2023 as a result of the rebranding of the Royal Ransomware Group, which originated from the Conti Ransomware Group. This group was 'responsible for a number of serious ransomware attacks internationally', according to the Garda.
Since 2022, the Royal and BlackSuit ransomware groups have compromised more than 450 known victims in the US, 'including entities in the healthcare, education, public safety, energy and government sectors', Ice's homeland security investigations said.
'Combined, the groups have received more than $370 million (€317.2 million) in ransom payments, based on present-day valuations of cryptocurrency,' it said.
'The case is being prosecuted by the US Attorney's Office for the Eastern District of Virginia, which continues to collaborate with international partners to pursue legal accountability for those involved in the Royal and BlackSuit campaigns,' it added.
Other agencies involved in the operation include the US Department of Homeland Security, the US Secret Service, Europol, Dutch police, German police, the UK National Crime Agency and the Ukrainian Cyber Police. They were assisted by 'private partners', a Garda spokesperson said.
Angela Willis, assistant commissioner for organised and serious crime, said An Garda Síochána will continue to work with international partners to 'identify, target and disrupt' organised crime groups involved in cybercrime.
'Our work to date involving close collaboration with international partners, including this seizure and takedown of key online operational infrastructure, will continue as part of our ongoing effort to keep people safe both on and offline,' she said.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Man charged with carrying 3D printed gun in Dublin granted bail
Man charged with carrying 3D printed gun in Dublin granted bail

Irish Times

timean hour ago

  • Irish Times

Man charged with carrying 3D printed gun in Dublin granted bail

A construction worker stopped in Dublin and charged with carrying a 3D-printed gun and ammunition has been granted bail. Valeriju Voronenko (50), a Lithuanian national with an address at Gardiner Street, Dublin 1, was arrested at Stable Lane in Smithfield on Friday. He appeared before Judge Stephanie Coggans at Dublin District Court on Saturday, charged with four Firearms Act offences. The charges include two counts of unlawful possession of a 3D-printed Harlot pistol and eight rounds of .22 ammunition. The other two charges allege that he had the gun and ammunition in suspicious circumstances. READ MORE Garda Paul O'Reilly alleged the items were found in a sports bag. The offences, on conviction, are punishable by sentences of up to five and 14 years. Following submissions by defence counsel Kevin McCrave, bail was granted subject to strict conditions. Mr Voronenko must surrender his passport, observe an 11pm-8am curfew and provide a phone number to gardaí. He was ordered not to apply for replacement travel documents and remanded on bail in his bond of €500. Mr Voronenko, who has yet to enter a plea, is due to appear again in September, for directions from the Director of Public Prosecutions to be conveyed.

Trio remanded after nearly €1.3m in suspected crime earnings seized
Trio remanded after nearly €1.3m in suspected crime earnings seized

Irish Times

time4 hours ago

  • Irish Times

Trio remanded after nearly €1.3m in suspected crime earnings seized

Three men arrested after gardaí seized €1.28 million in suspected crime earnings in south Dublin this week have been remanded in custody. Chinese national Kwan Wang (36) who lives in Hong Kong, Vladislavs Temmis (54) a Russian speaker from Latvia and 47-year-old Ik Joo Kang, from South Korea, appeared before Judge Stephanie Coggans at Dublin District Court on Saturday. All three held off on moving bail applications. The arrests were part of an operation targeting an organised crime group. Gardaí with the Dublin Crime Response Team stopped and searched a car in Donnybrook, Dublin 4, on Thursday, where they found €197,760 and arrested one man. During follow-up searches in south Dublin, gardaí seized an additional €1,086,175 in cash, bringing the total amount of money recovered in this investigation to €1,283,935. READ MORE Each defendant faces two counts under section 7 of the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 for possessing proceeds of criminal conduct, which carries a maximum 14-year sentence. Mr Temmis allegedly had €197,760 at Donnybrook Road, Dublin 4, and a further €27,500 at an address on Brewery Road, Stillorgan, south Dublin. His two co-defendants are also accused of having the €197,760, but it is alleged they possessed it in a 2025-registered vehicle at Donnybrook Road. According to the charge sheets, Mr Ik and Mr Kwan also had €1,058,675 in a Dublin 2 hotel room. The three men, who do not have stated addresses in the Republic, were dealt with separately and listened to the proceedings with the aid of interpreters. They spoke only to communicate with their legal representatives. Gardaí Sean Tyrell and Karl Byrne said Mr Kwan and Mr Temmis made no reply when charged. However, Mr Ik's response was: 'Yes, I will not accept this.' Solicitor Andrew Walsh said his Hong Kong-based client was not making a bail application at this stage but would give gardaí 48 hours' notice if an application is going to be made. Following a recess to take instructions, barrister Kevin McCrave confirmedhis clients would also defer their applications. The court adjourned ruling on requests to grant free legal aid to the trio after Garda Tyrell said that Mr Kwan was wearing a jacket believed to be worth €500. They were remanded in custody to appear at Cloverhill District Court next week, Mr Ik and Mr Temmis on Tuesday and their co-defendant on Wednesday.

Man (60s) dies in car crash in Co Tipperary
Man (60s) dies in car crash in Co Tipperary

Irish Times

time4 hours ago

  • Irish Times

Man (60s) dies in car crash in Co Tipperary

A man (60s) has died following a single vehicle car crash in Cahir, Co Tipperary on Saturday morning. Gardaí and emergency services responded to the collision on the N24 at Kilmoyler, Cahir at about 10.40am. The driver and sole occupant of the car was pronounced deceased at the scene. His body has been removed to Tipperary University Hospital where a postmortem examination will be carried out. READ MORE Garda Forensic Collision Investigators are currently conducting an examination of the scene and the road remains closed. Local diversions are in place. The Datawrapper link: And the spreadsheet if anyone can add to it when they see fatalities: Gardaí are appealing for any witnesses to come forward. Any road users who may have camera footage and were travelling in the area between 10.30am and 11am are asked to make this available to gardaí. Anyone with any information is asked to contact Cahir Garda station on (052) 7445630, the Garda Confidential Line on 1800 666 111, or any Garda station.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store