ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Europol-led law enforcement operation targeted Ragnar Locker members and infrastructure

The notorious Ragnar Locker ransomware group’s dark web page has been successfully taken down by the Europol, FBI and multiple other law enforcement agencies in Europe.Europol has announced that the Ragnar Locker ransomware group’s dark web page was seized as a result of a joint operation conducted by law enforcement agencies from the US, Europe, Germany, France, Italy, Japan, Spain, Netherlands, Czech Republic, and Latvia.“This service has been seized as part of a coordinated law enforcement action against the Ragnar Locker group,” reads a message on the ransomware group’s now-defunct website.Europol said that the law enforcement operation took place between 16 and 20 October and targeted key members of the Ragnar Locker group in France, Czechia, Spain and Latvia. The authorities succeeded in arresting the “key target” in Paris on 16 October and have produced him before examining magistrates of the Paris Judicial Court.“The ransomware’s infrastructure was also seized in the Netherlands, Germany and Sweden and the associated data leak website on Tor was taken down in Sweden,” Europol said.The law enforcement agency said Ragnar Locker was considered a serious threat as it mainly targeted critical infrastructure and was known to employ a double extortion tactic, demanding extortionate payments for decryption tools as well as for the non-release of the sensitive data stolen.“This investigation shows that once again international cooperation is the key to taking ransomware groups down. Prevention and security are improving, however ransomware operators continue to innovate and find new victims, said Edvardas Šileris,” the Head of Europol’s European Cybercrime Centre.“I hope this round of arrests sends a strong message to ransomware operators who think they can continue their attacks without consequence.”In January this year, the FBI said it disrupted a prolific ransomware group called Hive, a maneuver that allowed the bureau to thwart the group from collecting more than $130 million in ransomware demands from more than 300 victims.At a news conference, U.S. Attorney General Merrick Garland, FBI Director Christopher Wray, and Deputy U.S. Attorney General Lisa Monaco said government hackers broke into Hive’s network and put the gang under surveillance, surreptitiously stealing the digital keys the group used to unlock victim organisations’ data.Commenting on the coordinated law enforcement takedown of Ragnar Locker’s key members, Jake Moore, Global Cybersecurity Advisor, ESET, said, “Any takedown by Europol should be regarded as both significant and impressive but this particular takedown stands out because of its Russian links and the challenges facing the police.“Previously, Ragnar Locker cautioned victims against reaching out to the police or the FBI about their ransom demands, threatening data exposure if they did. Their financial motivations are usually very clear and with no room to negotiate.“However, RagnarLocker is not the typical Ransomware as a Service operator (RaaS). The gang is focusing mostly on data theft, not data encrypting, so they will probably set up a new channel to extort their victims. And without arrest, there’s little doubt that the criminals behind it have all the opportunity to continue in their malicious activities,” Moore added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543