Seven suspected hackers linked to ransomware attacks that have targeted thousands of victims have been arrested since last February as part of a global cybercrime crackdown, European law enforcement authorities announced Monday.
The FBI and the Justice Department were expected to announce criminal charges tied to ransomware later Monday as well as the seizure of $6 million, according to a U.S. official, who was not authorized to discuss the matter by name ahead of a news conference and spoke on the condition of anonymity.
None of the arrested hackers was identified by name, but Europol said two suspected hackers believed to be linked to the ransomware gang known as REvil were arrested last week for involvement in attacks that yielded about $580,000 in ransom payments. Authorities in Kuwait arrested another accused hacker last week, and South Korean authorities have arrested three since last February. A seventh was arrested last month in Europe.
Code Name; GoldDust
The arrests were part of a law enforcement investigation called GoldDust that involved the United States and 16 other countries. REvil, also known as Sodinokibi, has been linked in recent months to ransomware targeting the world's largest meat processor, JBS SA, as well as a Fourth of July weekend attack that snarled businesses around the world.
Deputy Attorney General Lisa Monaco appeared to foreshadow Monday's announcement in an interview with The Associated Press last week, saying that “in the days and weeks to come, you're going to see more arrests" as well as seizures of ransomware proceeds.
The Justice Department has tried multiple ways to address a ransomware wave that it regards as a national security and economic threat. Arrests of foreign hackers are significant for the Justice Department since many of them operate in the refuge of countries that do not extradite their own citizens to the U.S. for prosecution.
Attorney General Merrick Garland, Monaco and FBI Director Christopher Wray were expected to appear at a Monday afternoon news conference at the Justice Department to make what officials said would be a "significant" law enforcement announcement.
The Justice Department in June seized $2.3 million in cryptocurrency from a payment made by Colonial Pipeline following a ransomware attack that caused the company to temporarily halt operations, creating fuel shortages in parts of the country.
Editor's Note: This is an update of an earlier story, "Suspected Hackers Arrested in Global Ransomware Crackdown."
© Copyright 2022 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.