news

BlackSuit dismantled

International law enforcement dismantles BlackSuit, heir of Royal/Conti, after causing $500M in damages through double-extortion ransomware operations.

Samuel Samuel · 1757936925 · 1 min read · 537
BlackSuit dismantled

BlackSuit dismantled: how one of the most active ransomware groups was brought down

On July 25, the international operation Checkmate (involving Europol, the FBI, HSI, and the Ukrainian cyber police) seized the darknet portals of BlackSuit, a ransomware group linked to Royal and Conti.

Why is this important?

BlackSuit had extorted tens of millions of dollars, causing an estimated $500 million in damage. Its double extortion model (encrypt + threaten to leak) was rendered powerless after its infrastructure was seized. Without Tor portals or communication channels, the group lost its ability to pressure victims.

🔍 A key detail: BlackSuit was not just a “group similar” to Royal... it was its direct heir, with a 98-99% match in its code base.

📊 Analyzing all entries in the BlackSuit group's victim list on Breach House, 154 cases with a defined country were identified:

  • The United States accounts for the absolute majority with around 65% of victims.

  • It is followed by the United Kingdom (6%), Canada (4%), and several European countries with smaller percentages.

This case demonstrates how ransomware evolves, mutates, and resurfaces under new names. Today it is BlackSuit, yesterday it was Royal and Conti... and tomorrow?

At Darkeye Industries, we follow them closely, collecting and updating the data leaked by these groups in real time.

Because understanding the history of ransomware is not just curiosity: it is anticipating what is to come.

Discover all attacks and leaks and check if your data has been compromised at:

📌 Breach House 🔎 HaveIbeenransomed?

Share //
Samuel

Darkeye Research Team

Samuel

Tracking ransomware crews, breach disclosures and the tooling that matters — field notes from the Darkeye desk.

Intel briefing

Get breach reports before they trend

Ransomware intel and breach disclosures in your inbox. Signal only, no noise.

Read next //

Recent notable cases in 2025
news

Recent notable cases in 2025

Recent ransomware attacks in 2025 affected hospitals, governments, banks, and companies worldwide. BlackSuit, Royal, and other groups caused massive data breaches and financial losses. Early detection

Samuel · 1757939622

Keep investigating //

Discussion (0)

Sign in to join the discussion

Share your take with the Darkeye community.

No comments yet. Be the first to weigh in.