Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Authorities Seize Sevyware Ransomware Leak Site in International Operation

Authorities Seize Sevyware Ransomware Leak Site in International Operation

By: Morgan Cipher Senior Privacy Journalist

Last updated: July 18, 2026

Human Written
Authorities Seize Sevyware Ransomware Leak Site in International Operation
  • Authorities have seized the leak site linked to the Sevyware ransomware group in a joint international operation.

  • The seizure involved France’s Cybercrime Unit (BL2C), JUNALCO, Ukraine’s SBU Cyber Department, and Europol.

  • Officials have not revealed whether anyone was arrested or if more criminal systems were shut down.

Law enforcement agencies have taken control of the leak site used by the Sevyware ransomware group. The action marks another international effort to disrupt the online tools cybercriminals use to pressure victims.

Anyone visiting the group’s leak site now sees a law enforcement seizure notice. The page no longer displays stolen data or victim names. According to the notice, France’s Cybercrime Unit (BL2C), JUNALCO, Ukraine’s Security Service (SBU) Cyber Department, and Europol worked together on the operation.

Authorities have not shared more details about the case. They have also not said if officers arrested anyone or seized other systems connected to the group. The action shows how countries continue to work together against ransomware gangs.

Instead of only responding after attacks happen, investigators are also targeting the online systems that help these groups operate.

Leak Site Used to Pressure Victims Goes Offline

Ransomware groups do more than lock computers. Many also steal private files before encrypting them. They later threaten to publish those files unless the victims pay a ransom. To do this, many gangs create leak sites on the dark web.

These websites become a powerful tool for extortion. Dark web platforms are also used for drug trafficking. New Zealand police recently arrested 11 people in a major dark web drug syndicate raid.

The sites often list victims, publish stolen files, or warn that more information will be released. This puts extra pressure on organizations to pay.

By taking over the Sevyware leak site, investigators have removed one of the group’s main tools for making those threats. The seizure could also help investigators collect digital evidence. Information stored on the site may help them understand how the group worked. It could also reveal details about affiliates, victims, or other people linked to the operation.

Even when no arrests happen right away, taking down a leak site can still hurt a ransomware group. Criminal gangs rely on these websites to build fear and convince victims that they will publish stolen information. Without that platform, the group’s ability to carry out future extortion campaigns may become weaker.

Officials Keep Investigation Details Secret

Authorities have not confirmed whether they arrested anyone during the operation. They have also not said if investigators seized more servers or other technical systems connected to Sevyware.

Officials have not revealed whether they recovered stolen data. They also have not said if any information could help identify victims or support ongoing investigations. This lack of information is common during international cybercrime cases.

Law enforcement agencies often keep important details private while investigations continue. Doing so helps protect ongoing work and avoids warning other suspects who may still be under investigation.

Cases involving several countries usually take longer to complete. Investigators may continue collecting evidence long after a public seizure takes place. For that reason, agencies sometimes wait before announcing arrests or explaining how they carried out an operation.

International Cooperation Continues to Target Ransomware Networks

Modern ransomware groups often operate across several countries. Their members, servers, and victims may all be located in different parts of the world. That makes international cooperation an important part of cybercrime investigations.

Law enforcement agencies share intelligence, trace online systems, and coordinate operations across borders. This helps investigators identify suspects and disrupt criminal networks.

Europol has continued to support these efforts by helping participating countries exchange intelligence and coordinate joint operations. The participation of Ukraine’s SBU Cyber Department alongside French authorities also reflects the growing number of multinational partnerships targeting ransomware groups.

Governments have increasingly focused on disrupting the wider cybercrime ecosystem instead of only pursuing individual hackers. That approach includes taking over leak sites, shutting down underground forums, disrupting cryptocurrency laundering services, and seizing servers used by criminal groups.

These actions do not eliminate ransomware overnight. However, they can slow criminal operations and force threat actors to rebuild important parts of their infrastructure. Losing trusted systems can also damage a group’s reputation among its partners and affiliates.

Rebuilding that trust often takes time. For now, the seizure of Sevyware’s leak site stands as another example of countries working together against ransomware operations. The seizure notice remains the clearest public sign of the operation.

Authorities have not announced whether more enforcement actions will follow. They are also keeping other operational details private while the investigation continues.

More information is expected after investigators determine that releasing additional details will no longer affect the ongoing case. Until then, the seized leak site serves as the latest reminder that international law enforcement agencies continue to target the online infrastructure behind ransomware attacks.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.