8Base ransomware members snared in global police crackdown
The group is believed to have targeted more than 1,000 organizations around the world
Four Russian nationals have been arrested for their alleged involvement in the 8Base ransomware group after a joint police operation by 14 countries.
The suspects were arrested in Phuket, Thailand, and charged with a number of offenses, potentially carrying decades in prison. At the same time, 27 servers linked to the criminal network were taken down.
The gang was deploying a variant of Phobos ransomware to extort large payments from victims across Europe, the US, and beyond, authorities said.
First detected in December 2018, Phobos ransomware has been widely used in large-scale attacks against businesses and organizations worldwide.
8Base is believed to have targeted more than 1,000 public and private bodies, raking in more than $16 million in ransom payments in all.
"Unlike high-profile ransomware groups that target major corporations, Phobos relies on high-volume attacks against small to medium-sized businesses, which often lack the cybersecurity defences to protect themselves," said Europol.
"Its Ransomware as a Service (RaaS) model has made it particularly accessible to a range of criminal actors, from individual affiliates to structured criminal groups such as 8Base."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
8Base developed its own variant of the ransomware, using its encryption and delivery mechanisms to tailor attacks and cause the biggest impact possible.
Who are 8Base?
It has been particularly aggressive in its use of double extortion techniques, which involve both encrypting victims' data and threatening to publish stolen information unless a ransom is paid.
As a result, the group has been the focus of action by international law enforcement for a while. A key Phobos affiliate was arrested in Italy in 2023, for example, while last summer an administrator was arrested in South Korea and extradited to the US.
Two of the four people arrested this week have now been charged in the US for their part in the group: Roman Berezhnoy, 33, and Egor Nikolaevich Glebov, 39, both of whom are Russian nationals.
They are accused of carrying out ransomware attacks between May 2019 and at least October 2024. Victims are believed to include a children’s hospital, health care providers, and educational institutions.
RELATED WHITEPAPER
"After a successful Phobos ransomware attack, criminal affiliates paid fees to Phobos administrators for a decryption key to regain access to the encrypted files," said the US Department of Justice.
"Each deployment of Phobos ransomware was assigned a unique alphanumeric string in order to match it to the corresponding decryption key, and each affiliate was directed to pay the decryption key fee to a cryptocurrency wallet unique to that affiliate."
The UK's National Crime Agency (NCA) said the group had had a significant impact on the UK and that, as a result of the investigation, it was able to prevent a number of targeted businesses from falling victim to encryption.
MORE FROM ITPRO
- The hidden cost of ransomware is way more painful than many realize
- How to deal with ransomware remediation
- UK firms are dangerously overconfident about paying ransoms
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Thousands of npm packages compromised in ‘Chaindrop’ malware campaignNews The Chaindrop infostealer is a variant of the notorious Shai-Hulud malware strain
-
Cyber resilience 101Sponsored Cyber resilience is now a board-level priority, and solutions like Dell PowerProtect One can help make all the difference
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals