London Daily

Focus on the big picture.
Sunday, Dec 28, 2025

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Blockchain analytics group tracked 75 BTC payment made by Colonial Pipeline after cyberattack

An analytics firm identified the bitcoin wallet used by the ransomware group behind the Colonial Pipeline attack and the massive payments received from victims.

The gang’s wallet received a 75 BTC (bitcoin) payment, or roughly $5 million, made by Colonial Pipeline on May 8 following the cyberattack on its operations, according to a report from blockchain analytics firm Elliptic.

The Colonial Pipeline shutdown led to widespread fuel shortages in the U.S. and has been described as the worst cyberattack on critical U.S. infrastructure to date. DarkSide, which the FBI confirmed as being behind the attacks, is believed to have originated in Eastern Europe, likely Russia. The group's ransomware was first spotted in August 2020.

Motorists use gas pumps at a refueling station on May 12, 2021 in Benson, North Carolina. Most stations in the area along I-95 were without fuel following the Colonial Pipeline hack. 


The firm also tracked a ransomware bitcoin payment made by Brenntag, a large chemical distribution company in Germany, totaling roughly $ 4.4 million.

The group's wallet has been active since March 4, 2021, and has received 57 payments from 21 different wallets, according to Elliptic.

In total, the DarkSide wallet received Bitcoin transactions since March totaling $17.5 million, Elliptic said. The firm said the majority of the payment was moved out the wallet on May 9.

A portion of the payments was sent to a small group of exchanges. One exchange was identified as Hydra, "the world’s largest darknet marketplace, servicing customers in Russia and neighboring countries," according to Elliptic.

Hydra offers "cash-out services" along with narcotics, hacking tools and fake IDs, the report said.

"These allow Bitcoin to be converted into gift vouchers, prepaid debit cards or cash Rubles. If you’re a Russian cybercriminal and you want to cash-out your crypto, then Hydra is an attractive option," Elliptic said.

Massive payments


DarkSide, which has since claimed it would cease operations, brought in a cool $90 million in just nine months from an estimated 47 victims, according to another report from Elliptic.

So far, 99 organizations have been infected with the DarkSide ransomware, "suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9 million," Elliptic said, citing a tweet by DarkTracer.


Because of the large sums paid out by victims, ransomware has evolved into a big business that mirrors traditional business models.

DarkSide is a prime example of Ransomware as a Service (RaaS), Elliptic said, echoing longstanding legitimate models such as SaaS or Software as a Service.

"In this operating model, the malware is created by the ransomware developer, while the ransomware affiliate is responsible for infecting the target computer system and negotiating the ransom payment with the victim organization," Elliptic said.

"This new business model has revolutionized ransomware, opening it up to those who do not have the technical capability to create malware, but are willing and able to infiltrate a target organization," according to the analytics firm.

Newsletter

Related Articles

0:00
0:00
Close
UK Plans Royal Diplomacy with King Charles and Prince William to Reinvigorate Trade Talks with US
King Charles and Prince William Poised for Separate 2026 US Visits to Reinforce UK-US Trade and Diplomatic Ties
Apple Moves to Appeal UK Ruling Ordering £1.5 Billion in Customer Overcharge Damages
King Charles’s 2025 Christmas Message Tops UK Television Ratings on Christmas Day
The Battle Over the Internet Explodes: The United States Bars European Officials and Ignites a Diplomatic Crisis
Princesses Beatrice and Eugenie Join Royal Family at Sandringham Christmas Service
Fine Wine Investors Find Little Cheer in Third Year of Falls
UK Mortgage Rates Edge Lower as Bank of England Base Rate Cut Filters Through Lending Market
U.S. Supermarket Gives Customers Free Groceries for Christmas After Computer Glitch
Air India ‘Finds’ a Plane That Vanished 13 Years Ago
Caviar and Foie Gras? China Is Becoming a Luxury Food Powerhouse
Hong Kong Climbs to Second Globally in 2025 Tourism Rankings Behind Bangkok
From Sunniest Year on Record to Terror Plots and Sports Triumphs: The UK’s Defining Stories of 2025
Greta Thunberg Released on Bail After Arrest at London Pro-Palestinian Demonstration
Banksy Unveils New Winter Mural in London Amid Festive Season Excitement
UK Households Face Rising Financial Strain as Tax Increases Bite and Growth Loses Momentum
UK Government Approves Universal Studios Theme Park in Bedford Poised to Rival Disneyland Paris
UK Gambling Shares Slide as Traders Respond to Steep Tax Rises and Sector Uncertainty
Starmer and Trump Coordinate on Ukraine Peace Efforts in Latest Diplomatic Call
The Pilot Barricaded Himself in the Cockpit and Refused to Take Off: "We Are Not Leaving Until I Receive My Salary"
UK Fashion Label LK Bennett Pursues Accelerated Sale Amid Financial Struggles
U.S. Government Warns UK Over Free Speech in Pro-Life Campaigner Prosecution
Newly Released Files Shed Light on Jeffrey Epstein’s Extensive Links to the United Kingdom
Prince William and Prince George Volunteer Together at UK Homelessness Charity
UK Police Arrest Protesters Chanting ‘Globalise the Intifada’ as Authorities Recalibrate Free Speech Enforcement
Scambodia: The World Owes Thailand’s Military a Profound Debt of Gratitude
Women in Partial Nudity — and Bill Clinton in a Dress and Heels: The Images Revealed in the “Epstein Files”
US Envoy Witkoff to Convene Security Advisers from Ukraine, UK, France and Germany in Miami as Peace Efforts Intensify
UK Retailers Report Sharp Pre-Christmas Sales Decline and Weak Outlook, CBI Survey Shows
UK Government Rejects Use of Frozen Russian Assets to Fund Aid for Ukraine
UK Financial Conduct Authority Opens Formal Investigation into WH Smith After Accounting Errors
UK Issues Final Ultimatum to Roman Abramovich Over £2.5bn Chelsea Sale Funds for Ukraine
Rare Pink Fog Sweeps Across Parts of the UK as Met Office Warns of Poor Visibility
UK Police Pledge ‘More Assertive’ Enforcement to Tackle Antisemitism at Protests
UK Police Warn They Will Arrest Protesters Chanting ‘Globalise the Intifada’
Trump Files $10 Billion Defamation Lawsuit Against BBC as Broadcaster Pledges Legal Defence
UK Says U.S. Tech Deal Talks Still Active Despite Washington’s Suspension of Prosperity Pact
UK Mortgage Rules to Give Greater Flexibility to Borrowers With Irregular Incomes
UK Treasury Moves to Position Britain as Leading Global Hub for Crypto Firms
U.S. Freezes £31 Billion Tech Prosperity Deal With Britain Amid Trade Dispute
Prince Harry and Meghan’s Potential UK Return Gains New Momentum Amid Security Review and Royal Dialogue
Zelensky Opens High-Stakes Peace Talks in Berlin with Trump Envoy and European Leaders
Historical Reflections on Press Freedom Emerge Amid Debate Over Trump’s Media Policies
UK Boosts Protection for Jewish Communities After Sydney Hanukkah Attack
UK Government Declines to Comment After ICC Prosecutor Alleges Britain Threatened to Defund Court Over Israel Arrest Warrant
Apple Shutters All Retail Stores in the United Kingdom Under New National COVID-19 Lockdown
US–UK Technology Partnership Strains as Key Trade Disagreements Emerge
UK Police Confirm No Further Action Over Allegation That Andrew Asked Bodyguard to Investigate Virginia Giuffre
Giuffre Family Expresses Deep Disappointment as UK Police Decline New Inquiry Into Andrew Mountbatten-Windsor Claims
Transatlantic Trade Ambitions Hit a Snag as UK–US Deal Faces Emerging Challenges
×