Irish police seize Conti domains used in HSE ransomware attack
The Garda’s cyber crime unit confirmed that it had disrupted the hacking gang's IT infrastructure
Ireland’s Garda National Cyber Crime Bureau has announced that it had “seized several domains” used in the ransomware attack on the Irish Health Service Executive (HSE) earlier this year.
The attack, which took place in mid-May, forced the national health and social services provider to shut down its entire IT system, which lead to appointments being delayed or cancelled. The Irish Department of Health was also targeted but managed to prevent Conti from encrypting its network.
On Sunday, almost four months after the attack, the Garda’s cyber crime unit confirmed that it had disrupted the IT infrastructure of the Conti hacking group, which had claimed responsibility for the attack. Thought to be deployed by a Russian group known as Wizard Spider, Conti functions as a type of ransomware as a service (RaaS) operation.
“The Garda National Cyber Crime Bureau have seized several domains used in this and other ransomware attacks,” a Garda spokesperson told IT Pro, adding that the seizure “has directly prevented a large number of further ransomware attacks across the world”.
The Bureau has also notified potential victims of the ransomware gang and is working with Europol and Interpol to ensure that other states are aware of the systems targeted by Conti.
RELATED RESOURCE
The ultimate law enforcement agency guide to going mobile
Best practices for implementing a mobile device program
A Garda spokesperson described the operation as “crime prevention”, adding that to date there had been “a total of 753 attempts (...) made by ICT systems across the world to connect to the seized domains”.
“In each instance, the seizure of these domains by the GNCCB investigation team is likely to have prevented a Conti Ransomware Attack on the connecting ICT system, by rendering the initially deployed malware on the victims system, as ineffective,” they said.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
HSE wasn’t the only healthcare provider targeted by the Conti ransomware group. Days after the attack was reported, the US Federal Bureau of Investigations (FBI) found that the gang had also attempted to breach 16 US services, including law enforcement agencies, 911 dispatch services and municipalities, with the attempted attacks all taking place since May 2020.
The FBI Cyber Division stated that the targeted healthcare and first responder networks were “among the more than 400 organisations worldwide victimised by Conti”, out of which “over 290” are based in the US.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
SecurityHQ names Aaron Hambleton as product and services chiefNews Industry veteran will lead product and service innovation across the provider's cybersecurity portfolio
-
Cisco teams up with DSIT to drive digital skills adoptionNews Partnership supports the government's TechFirst program to provide one million secondary school students with access to digital learning experiences
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti
-
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitationNews A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation
-
Security leaders overconfident about ransomware recoveryNews Few manage to recover all their data, and many experience business disruption
-
German authorities want your help finding the hackers behind GandCrab and REvilNews Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes
-
The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in lifeNews With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion
