RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Enforcement

Enforcement / From the archive · 19 December 2023 event · prepared 16 September 2026

An FBI takedown slowed ALPHV but did not end its affiliate model

A CISA advisory and later reporting show the 2023 disruption degraded BlackCat without stopping ransomware as a service.

Visual published with the cited source for this record: An FBI takedown slowed ALPHV but did not end its affiliate model
Visual published with the cited source, shown for identification of the record. Credit: cisa.gov · source page ↗ Rights: owner-review-pending.

What happened

In December 2023, law enforcement took action against the infrastructure of ALPHV, also known as Blackcat, a ransomware-as-a-service operation. The FBI, CISA and the Department of Health and Human Services subsequently issued a joint cybersecurity advisory, first published 19 December 2023, describing ALPHV Blackcat's affiliate model and noting that the group's administrators responded to the operational action by encouraging affiliates to target hospitals. The advisory's February 2024 update recorded that, since mid-December 2023, nearly seventy leaked victims had been posted, with healthcare the most commonly targeted sector.

Two months after the disruption, on the morning of 21 February 2024, a ransomware attack identified by UnitedHealth Group's chief executive in Senate testimony as ALPHV or BlackCat encrypted Change Healthcare's systems. Independent reporting from security journalist Brian Krebs described a cryptocurrency address linked to BlackCat receiving a transaction of approximately 22 million dollars on 1 March 2024, followed by an affiliate's public claim of being denied a promised share, and the group's dark web sites subsequently going dark.

Confidence and limits

The advisory and the Senate record are official documents describing, respectively, the group's tactics and the fact that the same ransomware brand struck again after the disruption; both support the conclusion that the operation degraded rather than eliminated the group. The ransom figure and the exit-scam narrative rest on blockchain tracing and forum posts reported by a named security journalist, using hedged language such as apparent, and have not been confirmed here through a court filing or regulatory action naming the responsible individuals.

Why it mattered

The sequence illustrates a structural feature of ransomware-as-a-service: seizing a leak site or issuing a decryptor removes visible infrastructure but does not necessarily remove the people, code or affiliate relationships behind it. An administrator who can plausibly abscond with a ransom payment, as reported here, exposes a fault line within the criminal business model itself, since affiliates depend on the operator's honesty to get paid. That same fragility can drive affiliates toward newer brands, which is part of why a rotating cast of ransomware-as-a-service names keeps reappearing under different labels.

Defensive takeaway

Treat a disruption announcement as a reason to increase vigilance for the tactics described in the advisory, not a reason to stand down, since the same affiliates and techniques can resurface under a new or unchanged brand within weeks.

  • Do we track indicators associated with ransomware-as-a-service affiliates generally, rather than only by brand name, since affiliates move between operations?
  • Have we reviewed the mitigations in the joint advisory, including phishing-resistant multifactor authentication on remote access tools, regardless of whether ALPHV specifically targets our sector?
  • If we were extorted, do we have a plan for verifying a criminal group's claims that data would be deleted, given the reported history of unreliable conduct even toward affiliates?

The gap between a law-enforcement announcement and a group's actual capability is where defenders can be misled twice: once by assuming a disrupted brand is gone, and again by assuming a criminal operator's promises to its own affiliates, let alone its victims, are reliable.

Defensive takeaway

Do not assume a ransomware brand is finished after a law-enforcement disruption; keep monitoring for the tactics the advisory describes even after a takedown is announced.

CISA's joint advisory and the Senate Finance Committee's hearing record confirm law enforcement action against ALPHV Blackcat's infrastructure in December 2023 and confirm the same ransomware variant struck Change Healthcare in February 2024; the widely reported account of an affiliate being cheated out of a ransom share and the group's shutdown rests on hedged security-journalism sourcing not confirmed here by a court or regulatory document.

Sources & reading trail

#StopRansomware: ALPHV Blackcat (AA23-353A) ↗

Joint FBI/CISA/HHS advisory on ALPHV Blackcat ransomware as a service, noting operational action against the group's infrastructure in December 2023 and a subsequent shift toward targeting hospitals.

government-primary · Source published: 19 December 2023 · Retrieved: 16 September 2026

Testimony of Andrew Witty, Chief Executive Officer, UnitedHealth Group, Before the Senate Finance Committee ↗

Identifies the ransomware deployed against Change Healthcare on 21 February 2024, weeks after the December 2023 disruption, as ALPHV or BlackCat.

company-primary · Source published: 1 May 2024 · Retrieved: 16 September 2026

BlackCat Ransomware Group Implodes After Apparent $22M Ransom Payment by Change Healthcare ↗

Reports, with hedged language, that a BlackCat-linked address received about $22 million on 1 March 2024 and that an affiliate publicly accused the group of an exit scam before its sites went dark.

reputable-original-reporting · Source published: 5 March 2024 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.