The National Crime Agency (NCA), working with SUVAT, the FBI, Europol and law enforcement agencies from eleven countries, has successfully disrupted a major ransomware-as-a-service operation known as "DarkVault". The platform had been used since at least mid-2024 to launch ransomware attacks against targets in the United Kingdom and internationally.
The operation, codenamed Operation STORMBREAK, resulted in the seizure of 22 command-and-control servers, the arrest of five individuals across three countries, and the recovery of decryption keys that will allow some victims to restore their data without paying a ransom.
Background
SUVAT's Analysis Directorate first identified DarkVault malware samples in October 2024 during routine analysis of suspicious email campaigns reported to SUVAT. The ransomware was distributed via phishing emails containing weaponised document attachments targeting UK SMEs and NHS trusts.
SUVAT analysts reverse-engineered the malware, mapped the command-and-control infrastructure and identified links to at least 47 confirmed ransomware incidents affecting UK organisations. This intelligence was referred to the NCA's National Cyber Crime Unit, which initiated a formal investigation in December 2024.
SUVAT's role. SUVAT provided specialist malware analysis, infrastructure mapping and threat data to support the NCA's criminal investigation. SUVAT does not exercise law enforcement powers; our contribution was limited to analytical and technical support.
Outcome
- 22 servers seized across the UK, Netherlands, Germany and the United States
- 5 arrests — two in England, one in Romania, two in Ukraine — under applicable cybercrime legislation
- Approximately 340 UK organisations identified as confirmed or likely victims of DarkVault ransomware
- Decryption keys recovered — enabling some victims to restore encrypted data. SUVAT is working with the NCSC to make keys available to affected organisations
- DarkVault infrastructure permanently disrupted — affiliate panels, payment portals and data leak sites taken offline
The investigation remains ongoing. SUVAT continues to provide analytical support to the NCA and international partners. Further charges are anticipated.
Director General's statement
"Ransomware remains one of the most serious cyber threats facing the United Kingdom. This operation demonstrates the value of SUVAT's analytical capabilities working in partnership with the NCA and our international allies. By combining technical analysis with law enforcement action, we have disrupted a platform that caused significant harm to UK businesses, hospitals and public services. I commend the work of everyone involved."
— Catherine Langford, Director General, SUVAT
Advice for organisations
SUVAT recommends all organisations review the following guidance:
- Ransomware: prevention, response and recovery (SUVAT/GD/2025/014)
- NCSC guidance on mitigating malware and ransomware attacks
- Ensure offline backups are maintained and regularly tested
- Report suspected ransomware incidents to SUVAT and Action Fraud
Notes to editors
- SUVAT is the Spam & Unwanted Virus Analysis Team, an independent cyber threat analysis organisation based in the United Kingdom.
- SUVAT provides independent threat analysis to support the effort against cybercrime. It does not exercise law enforcement powers.
- The National Crime Agency is the UK's lead agency for combating serious and organised crime, including cybercrime.
- Media enquiries: media@suvat.uk or the NCA Press Office.