The full accounting of last week’s BlackSuit takedown has landed, and the numbers are larger than the initial announcement suggested. In an operation executed on July 24, 2026, led by Homeland Security Investigations, authorities seized four servers, nine domains, and cryptocurrency valued at $1,091,453 at the time of seizure. BlackSuit’s primary onion site now serves a law enforcement banner instead of a victim list.
The financial history released alongside the seizure is the part worth pausing on. Since Royal emerged in 2022 and rebranded as BlackSuit, the two identities have compromised more than 450 known victims in the United States and collected over $370 million in ransom payments.
Who Ran It
The operation was led by HSI Washington, D.C., with US participation from the Secret Service, IRS Criminal Investigation, and the FBI. International partners included the United Kingdom, Germany, Ireland, France, Canada, Ukraine, and Lithuania.
IRS-CI’s presence is the tell for how the crypto seizure was built. A seizure warrant for a specific dollar figure — $1,091,453, priced at the moment of execution — is the product of blockchain tracing that followed ransom payments from victim wallets through laundering hops to an address law enforcement could reach. That work predates the takedown by many months.
Royal to BlackSuit: One Crew, Two Names
BlackSuit is not a successor group in any meaningful sense. It is Royal with a new logo, and Royal itself drew personnel from the wreckage of Conti after that operation collapsed in 2022. The lineage is continuous: the same operators, the same tooling, the same targeting logic, renamed each time the brand accumulates too much law enforcement attention.
The victim profile has stayed consistent across both names — manufacturing, government, healthcare and public health, and commercial facilities. This is a group that went after hospitals and municipalities deliberately, on the correct assumption that organizations which cannot tolerate downtime pay faster.
The most notorious Royal-era intrusion remains the City of Dallas attack in May 2023, which took police, courts, and city services offline for weeks. BlackSuit’s later run included the CDK Global outage that paralyzed thousands of North American car dealerships.
What a $1.09 Million Seizure Actually Means
Set the seized amount against the $370 million the group collected and the ratio is unflattering: roughly 0.3% recovered. That gap is the honest measure of where ransomware enforcement stands.
But infrastructure seizures are not primarily about asset recovery, and judging them that way misses the mechanism. Four servers and nine domains are the operational spine of a ransomware-as-a-service business: the leak site that makes extortion credible, the negotiation portals, the affiliate panel, the payment infrastructure. Take those and the affiliates — who are contractors, not employees — lose confidence and move to a competitor. What actually kills these groups is the affiliate exodus, not the confiscated Bitcoin.
The counter-argument writes itself, because we have watched it happen repeatedly. Hive was dismantled in January 2023 and its people surfaced elsewhere. LockBit was disrupted in February 2024 and limped on under LockBitSupp before fragmenting. ALPHV/BlackCat exit-scammed its own affiliates in March 2024 and the talent dispersed into RansomHub. Royal became BlackSuit for exactly this reason.
No Arrests Announced
The takedown announcement disclosed no arrests. That is the structural problem: the seizures are US, UK, German, Irish, French, Canadian, Ukrainian, and Lithuanian, and the operators are very largely not.
Infrastructure and cryptocurrency can be reached across borders through hosting providers and exchanges. Human beings sitting in a non-extraditing jurisdiction cannot. Until that changes, every one of these operations disrupts a business without removing the people who run it — which is why the rebrand cycle continues.
Expect a new name within months, staffed by the same operators, with the same tooling pointed at the same sectors. The useful question for defenders is not whether BlackSuit returns but whether the initial access vectors it favoured — exposed RDP, phished credentials, unpatched edge devices — have been closed in the interval. For most of its 450 victims’ peers, they have not.
Sources
- ICE — HSI Washington, D.C. leads international takedown of BlackSuit ransomware infrastructure
- CyberScoop — BlackSuit, Royal ransomware group hit over 450 US victims before last month’s takedown
- Infosecurity Magazine — US Authorities Seize $1m from BlackSuit Ransomware Group
- IRS — Justice Department announces coordinated actions to disrupt the operations of BlackSuit (Royal) Ransomware
- Dark Reading — BlackSuit Ransomware Takes a Hit From Law Enforcement


