London Daily

Focus on the big picture.
Thursday, Jun 11, 2026

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Firm tracked DarkSide gang ransomware payments and the massive sums paid

Blockchain analytics group tracked 75 BTC payment made by Colonial Pipeline after cyberattack

An analytics firm identified the bitcoin wallet used by the ransomware group behind the Colonial Pipeline attack and the massive payments received from victims.

The gang’s wallet received a 75 BTC (bitcoin) payment, or roughly $5 million, made by Colonial Pipeline on May 8 following the cyberattack on its operations, according to a report from blockchain analytics firm Elliptic.

The Colonial Pipeline shutdown led to widespread fuel shortages in the U.S. and has been described as the worst cyberattack on critical U.S. infrastructure to date. DarkSide, which the FBI confirmed as being behind the attacks, is believed to have originated in Eastern Europe, likely Russia. The group's ransomware was first spotted in August 2020.

Motorists use gas pumps at a refueling station on May 12, 2021 in Benson, North Carolina. Most stations in the area along I-95 were without fuel following the Colonial Pipeline hack. 


The firm also tracked a ransomware bitcoin payment made by Brenntag, a large chemical distribution company in Germany, totaling roughly $ 4.4 million.

The group's wallet has been active since March 4, 2021, and has received 57 payments from 21 different wallets, according to Elliptic.

In total, the DarkSide wallet received Bitcoin transactions since March totaling $17.5 million, Elliptic said. The firm said the majority of the payment was moved out the wallet on May 9.

A portion of the payments was sent to a small group of exchanges. One exchange was identified as Hydra, "the world’s largest darknet marketplace, servicing customers in Russia and neighboring countries," according to Elliptic.

Hydra offers "cash-out services" along with narcotics, hacking tools and fake IDs, the report said.

"These allow Bitcoin to be converted into gift vouchers, prepaid debit cards or cash Rubles. If you’re a Russian cybercriminal and you want to cash-out your crypto, then Hydra is an attractive option," Elliptic said.

Massive payments


DarkSide, which has since claimed it would cease operations, brought in a cool $90 million in just nine months from an estimated 47 victims, according to another report from Elliptic.

So far, 99 organizations have been infected with the DarkSide ransomware, "suggesting that approximately 47% of victims paid a ransom, and that the average payment was $1.9 million," Elliptic said, citing a tweet by DarkTracer.


Because of the large sums paid out by victims, ransomware has evolved into a big business that mirrors traditional business models.

DarkSide is a prime example of Ransomware as a Service (RaaS), Elliptic said, echoing longstanding legitimate models such as SaaS or Software as a Service.

"In this operating model, the malware is created by the ransomware developer, while the ransomware affiliate is responsible for infecting the target computer system and negotiating the ransom payment with the victim organization," Elliptic said.

"This new business model has revolutionized ransomware, opening it up to those who do not have the technical capability to create malware, but are willing and able to infiltrate a target organization," according to the analytics firm.

Newsletter

Related Articles

0:00
0:00
Close
Office for National Statistics Adopts Supermarket Checkout Data for Inflation Measurement
Applied Atomics Launches With $500 Million Space Infrastructure Order Book
BYD Plans Nationwide Rollout of Ultra-Fast EV Charging Network
UK House Prices Unexpectedly Fall in May
CBI Warns UK Growth Is Becoming Increasingly Dependent on Public Spending
Makerfield By-Election Fuels Speculation Over Labour’s Future Leadership
Britain Declines to Join EU SAFE Defence Fund
UK Unveils 2040 Emissions Target Despite Strong Political Opposition
Government Orders Full Review of Palantir’s NHS Data Contract
UK Borrowing Costs Climb as Markets Price in Further Bank of England Rate Rises
Resident Doctors Confirm Five-Day NHS Strike Across England
Violent Anti-Immigrant Riots in Belfast Spark Political and Diplomatic Tensions
United Kingdom Sees Recovery in Horizon Europe Research Funding Share to 9.3 Percent
UK Inflation Holds at 2.8 Percent as Office for Budget Responsibility Flags Persistent Price Pressures
United Kingdom Launches National Anti-Fraud Framework to Combat Rising Pension Scam Losses
United Kingdom Expands Sanctions on Israeli Groups While Funding Palestinian Authority Salaries and Gaza Mine Clearance
United Kingdom Issues Three-Month Ultimatum to Major Technology Firms Over Child Online Safety Controls
United Kingdom Government Moves Toward Blanket Social Media Ban for Children Under Sixteen
Widespread Anti-Immigration Rioting Erupts Across Belfast After Knife Attack Linked to Asylum Seeker
Farmers Warn of Crop Losses Following Months of Unseasonal Rainfall
Civil Aviation Authority Launches Review of Regional Airport Operations
Met Office Issues Heat-Health Alert Across Parts of England
National Grid Introduces New Measures to Protect Winter Energy Supply
Northern England Rail Upgrades Receive Additional Government Funding
Wales Advances Green Hydrogen Strategy to Decarbonize Heavy Industry
UK Expands Recruitment Incentives to Address Shortage of STEM Teachers
High Court Opens Door to Climate Liability Claims Against Major Industrial Emitters
Police Service of Northern Ireland Investigates Major Personnel Data Breach
Defense Ministry Overhauls Procurement System to Accelerate AUKUS Submarine Program
Net Migration Remains Above Government Expectations, New Data Shows
UK and Scottish Governments Agree Framework for Expanded North Sea Wind Development
UK Treasury Launches New Tax Incentives to Boost AI and Semiconductor Investment
Bank of England Signals Continued Caution on Interest Rate Cuts
UK Unveils £10 Billion NHS Digital Modernization Plan Centered on AI Integration
Nebius Opens Major Robotics and Physical AI Laboratory in London
Bank of England Data Shows Strong Rise in New Mortgage Approvals
Network Rail Completes Landmark Upgrade of Severn Tunnel Rail Infrastructure
East West Rail Passenger Services Between Oxford and Milton Keynes Set for December Launch
GlaxoSmithKline Reportedly Pursues £7 Billion Acquisition of US Cancer Drug Developer Nuvalent
Bank of England Signals Interest Rates Likely to Remain Unchanged Despite Energy Market Risks
NHS Trusts Launch Job-Cutting Programmes as Financial Pressures Intensify Across England
More Than 130 Labour MPs Urge Ban on Trade With Israeli Settlements
Keir Starmer Orders Technology Firms to Introduce Smartphone Nudity Controls for Under-18s
UK Unveils £400 Million National AI Supercomputer Fund and New Economics Institute
Japanese Technology Firm Fujitsu Launches Advanced Artificial Intelligence Tool for Corporate Disclosures
South Africa Officially Launches Nationwide Campaign for Highly Contested Local Government Elections
United Kingdom Commits Additional Funding for Unexploded Ordnance Clearance in Laos
Singapore Announces Stringent New Greenhouse Gas Regulations for Commercial Cooling Systems
Cambodia and Thailand Hold High-Level Border Security Talks at United Nations Headquarters
Myanmar Military Government and China Sign Major Agreement to Upgrade Media and Cultural Cooperation
×