Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    An Enterprise Client Accidentally Spent $500 Million on Claude in a Single Month. Every Company Deploying AI Agents Needs to Read This.

    June 3, 2026

    Anthropic Just Surpassed OpenAI in the Private Market. The AI Race Has A New Leader and the Gap Is Widening Fast.

    June 3, 2026

    GitHub Lost 3,800 Internal Repositories to a Poisoned Developer Extension. The Supply Chain Attack Nobody Saw Coming Is Now the Most Dangerous Kind.

    June 2, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      Anthropic Just Surpassed OpenAI in the Private Market. The AI Race Has A New Leader and the Gap Is Widening Fast.

      June 3, 2026

      Trump Backed Down on His AI Executive Order After Big Tech Pushed Back. What the Retreat Reveals About U.S. AI Policy Is More Important Than the Order Itself.

      May 31, 2026

      SpaceX Filed Its IPO Papers and Is Targeting a $1.75 Trillion Valuation. If It Goes Through It Will Be the Largest Public Offering in History and It Will Reshape the Tech Market Permanently.

      May 31, 2026

      Foxconn Got Hit by Ransomware and 11 Million Files Were Stolen. The Nitrogen Attack on the World’s Largest Electronics Maker Has Consequences for Every Big Tech Supply Chain

      May 31, 2026

      Anthropic Is About to Turn a Profit for the First Time. Its Q2 Revenue Is Expected to Hit $10.9 Billion and That Number Changes Everything About the AI Business Model.

      May 28, 2026
    • Crypto

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026

      Coinbase Bets on Stablecoin and On-Chain Growth as Key Market Drivers in 2026 Strategy

      January 10, 2026
    • Gadgets & Smart Tech
      Featured

      Foldable Phones Are No Longer a Gimmick — The Motorola Razr 2026 Is the Latest Sign That Foldables Are Going Mainstream

      By fariehanMay 3, 2026
      Recent

      Foldable Phones Are No Longer a Gimmick — The Motorola Razr 2026 Is the Latest Sign That Foldables Are Going Mainstream

      May 3, 2026

      Meta Raises Quest VR Headset Prices as Component Costs Rise

      May 1, 2026

      Robotics Showcase: China Uses a Half-Marathon to Signal Progress in Humanoid Tech

      April 27, 2026
    • Cybersecurity & Online Safety

      GitHub Lost 3,800 Internal Repositories to a Poisoned Developer Extension. The Supply Chain Attack Nobody Saw Coming Is Now the Most Dangerous Kind.

      June 2, 2026

      Foxconn Got Hit by Ransomware and 11 Million Files Were Stolen. The Nitrogen Attack on the World’s Largest Electronics Maker Has Consequences for Every Big Tech Supply Chain

      May 31, 2026

      A Cybersecurity Firm Just Had Its Own Source Code Stolen. Trellix’s Breach Is the Most Embarrassing Kind and the Most Instructive One.

      May 22, 2026

      Hackers Built a Zero-Day Exploit Using AI and Almost Got Away With It. Google Caught It in Time. Next Time May Be Different.

      May 19, 2026

      275 Million Students Had Their Data Exposed in the Largest Education Cyberattack Ever Recorded. Here Is Exactly What Happened to Canvas

      May 19, 2026
    PhronewsPhronews
    Home»Cybersecurity & Online Safety»Inside the Ransomware Machine: 200,000 Leaked Messages Blow Black Basta Wide Open
    Cybersecurity & Online Safety

    Inside the Ransomware Machine: 200,000 Leaked Messages Blow Black Basta Wide Open

    preciousBy preciousApril 26, 2025Updated:May 3, 2025No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Cyber Security Ransomware Phishing Encrypted Technology

    Over 200,000 messages from Black Basta, a notorious ransomware syndicate operating since 2022 and as a ransomware-as-a-service (RaaS), have been exposed by a member in retaliation to how the syndicate targeted Russian banks. These messages, spanning through a year, contain tactics and secrets the syndicate used in carrying out their ransomware operations.

    In November 2024, the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Health and Human Services (HHS), and the Multi-state Information Sharing and Analysis Center (MS-ISAC) in a joint Cybersecurity Advisory (CSA), announced the activities of Black Basta and called the group “a ransomware variant whose actors have encrypted and stolen data from at least 12 out of 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) Sector.” 

    “Black Basta is considered a ransomware-as-a-service (RaaS) variant and was first identified in April 2022,” says the advisory. “Black Basta affiliates have impacted a wide range of businesses and critical infrastructure in North America, Europe, and Australia. As of May 2024, Black Basta affiliates have impacted over 500 organizations globally.”

    Ascension Health, one of the leading non-profit providers of health services in the US was a victim of one of Black basta’s cyberattacks during this period. 

    Thomas Roccia, a Senior Threat Researcher at Microsoft, using python and generative AI to work independently through the leaked data made a post on X (fka Twitter) to share his findings: His analysis shows that Black Basta runs a highly professional Ransomware-as-a-service operation where the group develops and maintains its ransomware tool, as well as rigorously vets affiliates to carry out the attacks.

    The chats, according to his analysis, revealed a dual extortion tactic – where victims risk both their data (sensitive information) being encrypted and the threat of the release of said data if ransom is not paid. Roccia also found a structured revenue-sharing model where payment is split between the developers and the affiliates.

    Patrick Garrity, in his research, also explains that the group references 62 distinct vulnerabilities – 50 of which are known to have been exploited, with 44 flagged in CISA’s Known Vulnerabilities list. The leaked chats show Black Basta’s focusing on widely used platforms like Windows, Office, and NetScaler, and prioritizing those with available proof-of-concept exploits.

    This approach gives them a clear course to then infiltrate organizations in sectors such as healthcare, finance, and manufacturing.

    Important to note that the Russian-populated group is reported to have been paid over $100 million for ransomware by their victims, according to a research done by Elliptic in November 2023. 

    Right from the inception of Black Basta in 2022, researchers hinted that it might be an offshoot of Conti, a notorious ransomware group that was widely known for its particularly large-scale attacks on critical infrastructure sectors in healthcare. It also suffered the same fate as Black Basta, where leaked internal communications and the activities of law enforcement agencies forced the group to disband in early 2022.

    However, while Black Basta immediately seized their operations since the group’s data was leaked, Cybersecurity researchers are taking it upon themselves to continue analyzing the leaked logs in order to gain better insights into potential future threats.

    Black Basta affiliates Black Basta payment Black Basta ransomware Black Basta ransomware leak Black Basta vulnerabilities CISA Black Basta CISA known vulnerabilities Conti ransomware offshoot critical infrastructure ransomware cyber extortion cybersecurity research cybersecurity threat analysis data encryption threat dual extortion tactic Elliptic ransomware payment FBI cybersecurity advisory healthcare ransomware attack Microsoft threat researcher RaaS ransomware attack ransomware attack impact ransomware attack on hospitals ransomware attack targets ransomware group tactics ransomware in finance ransomware in healthcare ransomware leak ransomware leak analysis ransomware revenue sharing ransomware tools ransomware-as-a-service Russian ransomware group
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    precious
    • LinkedIn

    I’m Precious Amusat, Phronews’ Content Writer. I conduct in-depth research and write on the latest developments in the tech industry, including trends in big tech, startups, cybersecurity, artificial intelligence and their global impacts. When I’m off the clock, you’ll find me cheering on women’s footy, curled up with a romance novel, or binge-watching crime thrillers.

    Related Posts

    GitHub Lost 3,800 Internal Repositories to a Poisoned Developer Extension. The Supply Chain Attack Nobody Saw Coming Is Now the Most Dangerous Kind.

    June 2, 2026

    Foxconn Got Hit by Ransomware and 11 Million Files Were Stolen. The Nitrogen Attack on the World’s Largest Electronics Maker Has Consequences for Every Big Tech Supply Chain

    May 31, 2026

    A Cybersecurity Firm Just Had Its Own Source Code Stolen. Trellix’s Breach Is the Most Embarrassing Kind and the Most Instructive One.

    May 22, 2026

    Comments are closed.

    Top Posts

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Artificial Intelligence & The Future

    An Enterprise Client Accidentally Spent $500 Million on Claude in a Single Month. Every Company Deploying AI Agents Needs to Read This.

    By preciousJune 3, 2026

    An unnamed enterprise racked up roughly $500 million in charges on Anthropic’s Claude in a…

    Anthropic Just Surpassed OpenAI in the Private Market. The AI Race Has A New Leader and the Gap Is Widening Fast.

    June 3, 2026

    GitHub Lost 3,800 Internal Repositories to a Poisoned Developer Extension. The Supply Chain Attack Nobody Saw Coming Is Now the Most Dangerous Kind.

    June 2, 2026

    Trump Backed Down on His AI Executive Order After Big Tech Pushed Back. What the Retreat Reveals About U.S. AI Policy Is More Important Than the Order Itself.

    May 31, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.