How a Toronto-area police force helped take down a Russian-linked ransomware group
A Toronto-area police force is opening up about how it became involved in the international efforts to legally hack one of the most aggressive ransomware groups in the world.
The contributions by Peel Regional Police are one reason a Canadian flag is among the icons displayed on what used to be the dark website for the Russian-linked ransomware group Hive, along with the logos of the U.S. Department of Justice, the FBI, and a variety of police forces around the world.
Peel’s officers got involved early when a business in the area came to them in 2021, saying their systems were down and a text message on their desktops showed a ransom note, said Detective Const. Karim Hussain in an interview with CTV News Toronto.
“We had one of the first cases in Canada of Hive ransomware,” said Hussain. “It was the first to market. At the time we started gathering evidence, Hive was a fairly new ransomware group. Everything we brought to the table was interesting because no one had seen it before.”
Details of the case matched with other high-profile incidents, including a hospital in Louisiana where hackers accessed data on 270,000 patients, and a hospital in Ohio that was attacked and couldn’t accept new patients even as COVID-19 cases were surging.
Those were among more than 1,500 attacks worldwide that had the digital fingerprints of Hive, a group whose affiliates have netted some $150 million since 2021, police say, as they extort businesses for money in exchange for getting access to their data or their system back.
The attacks are done through a “ransomware as a service” model, meaning a small group of people design malicious software, and then share the tool with many others, rapidly scaling up their attacks before the security holes they exploit can be plugged.
“You have an overarching group that provides everything down to the infrastructure, to lesser-capable cyber criminals, and they provide them the tools to conduct the hack,” Hussain said.
The case brought Peel Police together with other forces wrestling with the impact of Hive, including the RCMP, the FBI, police in France, Germany, Norway, and Lithuania.
Earlier this year, the group struck back, taking control of Hive’s website and replacing it with a landing page bearing the logos of many investigating agencies.
“Simply put, using lawful means, we hacked the hackers,” said U.S. Deputy Attorney General Lisa Monaco in a press conference in January.
She added that the police discovered and then freely distributed decryptor keys that could help anyone who had been attacked recover their data or free their systems on their own.
FBI director Christopher Wray said those actions had stopped some $130 million in ransoms from being paid.
“This cut off the gas that is fueling Hive’s fire,” Wray said.
The investigation is still ongoing, said Hussain, as ransomware continues to surge. Statistics Canada reported that ransomware attacks amounted to 11 per cent of all cyber security incidents in 2021.
“There’s no end in sight to cybercrime right now,” Hussain said.
CTVNews.ca Top Stories

Speaker's Nazi veteran invite 'profoundly embarrassing' Trudeau says, as Rota faces calls to resign
Tensions flared in the Commons on Monday over opposition calls for House Speaker Anthony Rota to resign after apologizing to Parliament for inviting, recognizing and leading the chamber in a standing ovation for a man who fought for a Nazi unit during the Second World War.
Poster advertising 'whites-only' children's playtime sparks outrage in B.C. community
Police have launched an investigation into a poster inviting "proud parents of European children" to participate in racially segregated playtime in B.C.'s Lower Mainland.
Canadian air force investigating 'inappropriate and unapproved' call sign broadcast on U.K. flight
The Royal Canadian Air Force (RCAF) is investigating an ‘inappropriate and unapproved’ call sign that was transmitted electronically from one of its aircraft on Monday.
Vaccination during pregnancy safe, effective and recommended, CMAJ says
The most up-to-date guidelines from the Canadian Medical Association Journal recommend the COVID-19 vaccine for anyone who is pregnant in order to reduce the risk of serious illness to themselves and the children they carry.
Canadian Sikhs stage protests against Indian government over murder
Canadian Sikhs staged small protests outside India's diplomatic missions on Monday, a week after Prime Minister Justin Trudeau said there may be a link between New Delhi and the murder of a Sikh separatist advocate in British Columbia.
Canada approves Ebola virus vaccine for adults exposed to the deadly disease
Canada has approved a vaccine to prevent Ebola in non-pregnant and otherwise healthy adults aged 18 and older.
We carry DNA from extinct cousins like Neanderthals. Science is now revealing their genetic legacy
Using the new and rapidly improving ability to piece together fragments of ancient DNA, scientists are finding that traits inherited from Neanderthals are still with us now, affecting our fertility, our immune systems, even how our bodies handled the COVID-19 virus.
Toronto woman hospitalized overseas with botulism
A Toronto woman has been hospitalized in France with a severe case of botulism after eating improperly preserved sardines at a Bordeaux wine bar.
Canada travel advisory to India updated to include protests, 'negative sentiments'
Canada has updated its travel advisory for India to include warnings about protests and 'negative sentiments' towards Canadians in light of a recent breakdown in Canada-India relations.