How a Toronto-area police force helped take down a Russian-linked ransomware group
A Toronto-area police force is opening up about how it became involved in the international efforts to legally hack one of the most aggressive ransomware groups in the world.
The contributions by Peel Regional Police are one reason a Canadian flag is among the icons displayed on what used to be the dark website for the Russian-linked ransomware group Hive, along with the logos of the U.S. Department of Justice, the FBI, and a variety of police forces around the world.
Peel’s officers got involved early when a business in the area came to them in 2021, saying their systems were down and a text message on their desktops showed a ransom note, said Detective Const. Karim Hussain in an interview with CTV News Toronto.
“We had one of the first cases in Canada of Hive ransomware,” said Hussain. “It was the first to market. At the time we started gathering evidence, Hive was a fairly new ransomware group. Everything we brought to the table was interesting because no one had seen it before.”
Details of the case matched with other high-profile incidents, including a hospital in Louisiana where hackers accessed data on 270,000 patients, and a hospital in Ohio that was attacked and couldn’t accept new patients even as COVID-19 cases were surging.
Those were among more than 1,500 attacks worldwide that had the digital fingerprints of Hive, a group whose affiliates have netted some $150 million since 2021, police say, as they extort businesses for money in exchange for getting access to their data or their system back.
The attacks are done through a “ransomware as a service” model, meaning a small group of people design malicious software, and then share the tool with many others, rapidly scaling up their attacks before the security holes they exploit can be plugged.
“You have an overarching group that provides everything down to the infrastructure, to lesser-capable cyber criminals, and they provide them the tools to conduct the hack,” Hussain said.
The case brought Peel Police together with other forces wrestling with the impact of Hive, including the RCMP, the FBI, police in France, Germany, Norway, and Lithuania.
Earlier this year, the group struck back, taking control of Hive’s website and replacing it with a landing page bearing the logos of many investigating agencies.
“Simply put, using lawful means, we hacked the hackers,” said U.S. Deputy Attorney General Lisa Monaco in a press conference in January.
She added that the police discovered and then freely distributed decryptor keys that could help anyone who had been attacked recover their data or free their systems on their own.
FBI director Christopher Wray said those actions had stopped some $130 million in ransoms from being paid.
“This cut off the gas that is fueling Hive’s fire,” Wray said.
The investigation is still ongoing, said Hussain, as ransomware continues to surge. Statistics Canada reported that ransomware attacks amounted to 11 per cent of all cyber security incidents in 2021.
“There’s no end in sight to cybercrime right now,” Hussain said.
CTVNews.ca Top Stories
Here's how some of Canada's wildfires compare in size to cities, lakes
Fires across the country are burning millions of hectares of land but what does that really look like? CTVNews.ca compared the blazes to some cities and lakes in the country showing just how big they have gotten.

Donald Trump described Pentagon plan of attack and shared classified map, indictment says
Former U.S. president Donald Trump is facing 37 felony charges related to the mishandling of classified documents, according to an indictment unsealed Friday that alleges that he described a Pentagon 'plan of attack' and shared a classified map related to a military operation.
BREAKING | Boris Johnson quits as U.K. lawmaker after being told he will be sanctioned for misleading Parliament
Former U.K. Prime Minister Boris Johnson shocked Britain on Friday by quitting as a lawmaker after being told he will be sanctioned for misleading Parliament.
Reactive to proactive: A push for a national campaign on wildfire education in Canada
Despite the alarming facts and figures, experts say Canada is far more reactive than it is proactive when it comes to wildfires and they’re calling for a national campaign on wildfire education to better prepare for the future.
Three people charged in alleged abduction of N.L. teen after Amber Alert issued
Police in Newfoundland and Labrador say three people are facing charges following the alleged abduction of a 14-year-old girl.
Eyes on the weather as residents pack and flee from fierce wildfire in northeast B.C.
Showers are predicted Saturday over the aggressive wildfire threatening Tumbler Ridge, but forecasters say thunderstorms could sweep through the parched region without bringing any rain.
Air Canada walks back compensation denials after thousands delayed due to tech issues
Air Canada says it made a mistake in rejecting some compensation claims from the thousands of travellers affected by delayed flights due to computer malfunctions.
Corrections defends Bernardo's privacy, as it faces calls to detail transfer reason
The Correctional Service of Canada is defending Paul Bernardo's privacy rights after the public safety minister said they should be waived.
What is Temu? Shopping app that didn't exist 4 months ago now a source of privacy concerns
A shopping app that didn’t exist four months ago is making quite the splash for online shoppers. But experts warn of potential data dangers for Canadian customers.