How a Toronto-area police force helped take down a Russian-linked ransomware group
A Toronto-area police force is opening up about how it became involved in the international efforts to legally hack one of the most aggressive ransomware groups in the world.
The contributions by Peel Regional Police are one reason a Canadian flag is among the icons displayed on what used to be the dark website for the Russian-linked ransomware group Hive, along with the logos of the U.S. Department of Justice, the FBI, and a variety of police forces around the world.
Peel’s officers got involved early when a business in the area came to them in 2021, saying their systems were down and a text message on their desktops showed a ransom note, said Detective Const. Karim Hussain in an interview with CTV News Toronto.
“We had one of the first cases in Canada of Hive ransomware,” said Hussain. “It was the first to market. At the time we started gathering evidence, Hive was a fairly new ransomware group. Everything we brought to the table was interesting because no one had seen it before.”
Details of the case matched with other high-profile incidents, including a hospital in Louisiana where hackers accessed data on 270,000 patients, and a hospital in Ohio that was attacked and couldn’t accept new patients even as COVID-19 cases were surging.
Those were among more than 1,500 attacks worldwide that had the digital fingerprints of Hive, a group whose affiliates have netted some $150 million since 2021, police say, as they extort businesses for money in exchange for getting access to their data or their system back.
The attacks are done through a “ransomware as a service” model, meaning a small group of people design malicious software, and then share the tool with many others, rapidly scaling up their attacks before the security holes they exploit can be plugged.
“You have an overarching group that provides everything down to the infrastructure, to lesser-capable cyber criminals, and they provide them the tools to conduct the hack,” Hussain said.
The case brought Peel Police together with other forces wrestling with the impact of Hive, including the RCMP, the FBI, police in France, Germany, Norway, and Lithuania.
Earlier this year, the group struck back, taking control of Hive’s website and replacing it with a landing page bearing the logos of many investigating agencies.
“Simply put, using lawful means, we hacked the hackers,” said U.S. Deputy Attorney General Lisa Monaco in a press conference in January.
She added that the police discovered and then freely distributed decryptor keys that could help anyone who had been attacked recover their data or free their systems on their own.
FBI director Christopher Wray said those actions had stopped some $130 million in ransoms from being paid.
“This cut off the gas that is fueling Hive’s fire,” Wray said.
The investigation is still ongoing, said Hussain, as ransomware continues to surge. Statistics Canada reported that ransomware attacks amounted to 11 per cent of all cyber security incidents in 2021.
“There’s no end in sight to cybercrime right now,” Hussain said.
CTVNews.ca Top Stories
Police ID mom, daughter killed in Old Montreal; video shows person break into building before fatal fire
The identities have been released of the mother and daughter who were killed after a fire tore through a 160-year-old building in Old Montreal on Friday.
Tropical Storm Milton forms in Gulf of Mexico, could intensify as a hurricane threatening Florida
Tropical Storm Milton has formed in the Gulf of Mexico. It is located 220 miles (355 kilometres) north-northeast of Veracruz, Mexico.
'I screamed in shock and horror': Family faces deadly Vancouver hit-and-run driver during sentencing
The sentencing of the man who pleaded guilty in the deadly hit-and-run in Kitsilano two years ago began on Friday.
Frequent drinking of fizzy beverages and fruit juice are linked to an increased risk of stroke: research
New data raises questions about the drinks people consume and the potential risks associated with them, according to researchers at Galway University in Ireland, in partnership with Hamilton’s McMaster University.
Northwestern Ont. woman charged with arson with disregard for human life
A 30-year-old northwestern Ontario woman has been charged with arson following a structure fire Thursday night, police say.
OPP charge driver going 175 km/h on Highway 417 in Ottawa
Ontario Provincial Police have laid stunt charges against a driver caught speeding 75 km/h over the speed limit on Highway 417 in Ottawa's west end.
Looking for cheap flights for the holidays? Here are some tips to remember
Travelling on a budget can be stressful, but there are ways you can ensure you're getting the best deal on flights as the holiday season approaches.
A French judge in a shocking rape case allows the public to see some of the video evidence
A French judge in the trial of dozens of men accused of raping an unconscious woman whose now former husband had repeatedly drugged her so that he and others could assault her decided on Friday to allow the public to see some of the video recordings of the alleged rapes.
The Menendez brothers case is not the only one that's been affected by a true crime documentary
Being an armchair detective has turned into an American obsession, fueled by an abundance of true-crime content in podcasts and television series. But some of those projects have sparked actual legal developments.