Beautiful Virgin Islands

Saturday, Feb 28, 2026

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Blockchain analytics group tracked 75 BTC payment made by Colonial Pipeline after cyberattack

An analytics firm identified the bitcoin wallet used by the ransomware group behind the Colonial Pipeline attack and the massive payments received from victims.

The gang’s wallet received a 75 BTC (bitcoin) payment, or roughly $5 million, made by Colonial Pipeline on May 8 following the cyberattack on its operations, according to a report from blockchain analytics firm Elliptic.

The Colonial Pipeline shutdown led to widespread fuel shortages in the U.S. and has been described as the worst cyberattack on critical U.S. infrastructure to date. DarkSide, which the FBI confirmed as being behind the attacks, is believed to have originated in Eastern Europe, likely Russia. The group's ransomware was first spotted in August 2020.

Motorists use gas pumps at a refueling station on May 12, 2021 in Benson, North Carolina. Most stations in the area along I-95 were without fuel following the Colonial Pipeline hack. 


The firm also tracked a ransomware bitcoin payment made by Brenntag, a large chemical distribution company in Germany, totaling roughly $ 4.4 million.

The group's wallet has been active since March 4, 2021, and has received 57 payments from 21 different wallets, according to Elliptic.

In total, the DarkSide wallet received Bitcoin transactions since March totaling $17.5 million, Elliptic said. The firm said the majority of the payment was moved out the wallet on May 9.

A portion of the payments was sent to a small group of exchanges. One exchange was identified as Hydra, "the world’s largest darknet marketplace, servicing customers in Russia and neighboring countries," according to Elliptic.

Hydra offers "cash-out services" along with narcotics, hacking tools and fake IDs, the report said.

"These allow Bitcoin to be converted into gift vouchers, prepaid debit cards or cash Rubles. If you’re a Russian cybercriminal and you want to cash-out your crypto, then Hydra is an attractive option," Elliptic said.

Massive payments


DarkSide, which has since claimed it would cease operations, brought in a cool $90 million in just nine months from an estimated 47 victims, according to another report from Elliptic.

So far, 99 organizations have been infected with the DarkSide ransomware, "suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9 million," Elliptic said, citing a tweet by DarkTracer.


Because of the large sums paid out by victims, ransomware has evolved into a big business that mirrors traditional business models.

DarkSide is a prime example of Ransomware as a Service (RaaS), Elliptic said, echoing longstanding legitimate models such as SaaS or Software as a Service.

"In this operating model, the malware is created by the ransomware developer, while the ransomware affiliate is responsible for infecting the target computer system and negotiating the ransom payment with the victim organization," Elliptic said.

"This new business model has revolutionized ransomware, opening it up to those who do not have the technical capability to create malware, but are willing and able to infiltrate a target organization," according to the analytics firm.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
When the State Replaces the Parent: How Gender Policy Is Redefining Custody and Coercion
Bill Clinton Denies Knowing Woman in Hot Tub Photo During Closed-Door Epstein Deposition
Former U.S. President Bill Clinton Testifies on Ties to Jeffrey Epstein Before Congressional Oversight Committee
Dyson Reaches Settlement in Landmark UK Forced Labour Case
Barclays and Jefferies Shares Fall After UK Mortgage Lender Collapse Rekindles Credit Market Concerns
Play Exploring Donald Trump’s Rise to Power by ‘Lehman Trilogy’ Author to Premiere in the UK
Man Arrested After Churchill Statue Defaced in Central London
Keir Starmer Faces Political Setback as Labour Finishes Third in High-Profile By-Election
UK Assisted Dying Bill Set to Fall Short in Parliament as Regional Initiatives Gain Ground
UK Defence Ministry Clarifies Position After Reports of Imminent Helicopter Contract
Independent Left-Wing Plumber Secures Shock Victory as Greens Surge in UK By-Election
Reform UK Refers Alleged ‘Family Voting’ Incidents in By-Election to Police
United Kingdom Temporarily Withdraws Embassy Staff from Iran Amid Heightened Regional Tensions
UK Government Reaches Framework Agreement on Release of Mandelson Vetting Files
UK Police Contracts With Israeli Surveillance Firms Spark Debate Over Ethics and Oversight
Spain to Conduct Border Checks on Gibraltar Arrivals Under New Post-Brexit Framework
Engie Shares Jump After $14 Billion Agreement to Acquire UK Power Grid Assets
BNP Paribas Overtakes Goldman Sachs in UK Investment Banking League Tables
Geothermal Project to Power Ten Thousand Homes Marks UK Renewable Energy Milestone
UK Visa Grants Drop Nineteen Percent in 2025 as Migration Controls Tighten
Barclays and Jefferies Among Banks Exposed to Collapse of UK Mortgage Lender MFS
UK Asylum Applications Edge Down in 2025 Despite Rise in Small Boat Crossings
Jefferies Reports Significant Exposure After Collapse of UK Lender MFS
FTSE 100 Reaches Fresh Record Highs as Major Share Buybacks and Earnings Lift London Stocks
So, what's happened is, I think, government policy, not just under Labour, but under the Conservatives as well, has driven a lot of small landlords out of business.
Larry Summers, the former U.S. Treasury Secretary, is resigning from Harvard University as fallout continues over his ties to Jeffrey Epstein.
U.S. stocks ended higher on Wednesday, with the Dow gaining about six-tenths of a percent, the S&P 500 adding eight-tenths of a percent, and the tech-heavy Nasdaq climbing roughly one-and-a-quarter percent.
From fears of AI-fuelled unemployment to Big Tech's record investment, this is AI Weekly.
Apple just dropped iOS 26.4.
US Lawmakers Seek Briefing from UK Over Reported Encryption Order Directed at Apple
UK Business Secretary Calls on EU to Remove Trade Barriers Hindering Growth
Legal Pathways for Removing Prince Andrew from Britain’s Line of Succession Examined
PM Netanyahu welcome India PM Narendra Modi to Israel
Shadow Diplomacy: How Harry and Meghan’s Jordan Trip Undermines the Monarchy
Britain’s Channel Crisis: Paying Billions While the Boats Keep Coming
Downing Street’s Veteran Deception Scandal
UK HealthCare Expands ‘Food as Health’ Initiative Statewide to Tackle Chronic Illness in Kentucky
Leonardo Chief Says UK Set to Decide on New Medium Helicopter Programme
UK Slows Chagos Islands Agreement After Concerns Raised in Washington
European and UK Stock Markets Reach Fresh Highs as Banks and Miners Lead Rally
UK Government Insists Chagos Islands Negotiations Continue After Minister’s ‘Pause’ Remark
No Confirmed Deal for Engie to Acquire UK Power Networks Amid Market Speculation
UK Reaffirms Updated Entry Requirements for Travellers as of February 25, 2026
Lord Mandelson Condemns Arrest as Driven by ‘Baseless Suggestion’ He Would Flee Abroad
Former UK Ambassador Released on Bail Following Arrest in Epstein-Linked Investigation
UK Parliament Orders Release of Former Prince Andrew’s Government Vetting Files
Reddit Fined £14 Million by UK Regulator Over Failures in Age Verification Controls
UK Moves to Tighten Regulation of Netflix, Disney+ and Prime Video Under New Media Rules
British Woman Who Reported Rape in Hong Kong Faces Possible Prosecution
UK Sanctions New Zealand Insurer Maritime Mutual Following Allegations Over Russian Oil Cover
×