RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 6 May 2022 event · prepared 16 September 2026

A ransomware group's leaked chats followed its public stand on the war

CISA's Conti advisory and a $15 million reward describe a ransomware operation that kept working after its internal chats went public.

Visual for this record: A ransomware group's leaked chats followed its public stand on the war
Visual published by image.theregister.com, shown for identification of the record. Credit: image.theregister.com · source page ↗ Rights: owner-review-pending.

What happened

In September 2021, CISA, the FBI and NSA published a joint advisory on sustained Conti ransomware activity against U.S. and international organizations, then updated it in March 2022 with new indicators of compromise. Conti's operators combined phishing and stolen remote-desktop credentials for initial access, used tools including Cobalt Strike and Mimikatz to move inside a network, and paired encryption with a threat to publish stolen data if a ransom went unpaid. In late February 2022, Conti posted a public statement backing Russia's invasion of Ukraine. Within days, according to contemporaneous reporting, someone with access to the group's internal systems began publishing its Russian-language chat logs and, later, source code and tooling, citing objection to that statement; this desk has not opened a document independently verifying the leaker's identity or motive. CISA's updated advisory, issued shortly afterward, added nearly 100 domain names to its indicators. On 6 May 2022, the State Department's Rewards for Justice program offered up to ten million dollars for information on Conti's leadership and up to five million more for a co-conspirator's arrest, a total reported at fifteen million dollars, following an attack on Costa Rican government systems weeks earlier.

Confidence and limits

The advisory and reward notice are official records of what agencies observed and offered: they establish that Conti was active over more than a year, that the described tactics recurred, and that a reward was authorized at a stated amount. They do not verify who leaked the internal chats or why, beyond a motive that reaches this desk only through reporting. Any victim count or ransom total attributed to Conti traces back to FBI estimates and should be read as reported cases, not a confirmed total.

Why it mattered

The leak was unusual because it came from inside a ransomware operation rather than from a victim, a researcher, or a law-enforcement seizure. It gave defenders an unfiltered look at how a large ransomware-as-a-service group divided its work, and elements fed directly into the government's own indicator updates. The reward offer marked a shift toward treating individual affiliates as identifiable targets, using a mechanism long applied to terrorism and espionage cases rather than ransomware crews as a whole.

Defensive takeaway

Treat indicators tied to one ransomware brand as provisional: domains and infrastructure from a group that nominally disbands are frequently reused or inherited by successors. Confirm that your organization can detect the described initial-access patterns, phishing attachments and exposed remote-desktop access, independent of any feed naming a specific group.

  • Can you detect a phishing-delivered loader or an unusual remote-desktop login attempt today without a named threat-actor match?
  • Are your backups isolated from any account credential that could also be used to encrypt production systems?
  • Would your incident response plan still work if the group behind an attack rebranded overnight?

Conti's operators did not stop working because a war began or a reward was posted. Investigators have since traced former members and infrastructure into several successor ransomware operations. The advisory and reward notice are best read as one dated snapshot of an ecosystem that outlasted the events that made it briefly visible.

Defensive takeaway

Treat indicators tied to one ransomware brand as provisional, since affiliates and infrastructure regularly resurface under new names, and confirm you can detect the advisory's described initial-access patterns independent of any group name.

CISA's advisory and the Rewards for Justice notice are official records of Conti's documented tactics and the government's reward offer. The leak's timing and the leaker's stated motive rest on contemporaneous reporting rather than a document opened for this article, and victim or payment totals are FBI estimates repeated in that reporting.

Sources & reading trail

Conti Ransomware ↗

Records the joint advisory's original September 2021 publication, its March 2022 update, Conti's tactics, and recommended mitigations.

government-primary · Source published: 22 September 2021 · Retrieved: 16 September 2026

Conti – Rewards For Justice ↗

States the up-to-$10-million and up-to-$5-million reward amounts and the named aliases sought.

government-primary · Source published: Not established · Retrieved: 16 September 2026

US offers $15m for help catching Conti ransomware gang ↗

Corroborates the 6 May 2022 announcement date, the combined $15 million reward total, and the FBI's reported victim and payment estimates.

reputable-original-reporting · Source published: 9 May 2022 · Retrieved: 16 September 2026

CISA updates Conti ransomware alert with nearly 100 domain names ↗

Describes the timing and stated motive of the leak of Conti's internal communications and its link to the advisory's updated indicators.

reputable-original-reporting · Source published: 9 March 2022 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.