The US Department of Justice (DOJ) has announced coordinated disruption actions against the BlackSuit (Royal) ransomware group. The operation, conducted on 24 July 2025, involved the takedown of four servers and nine domains used to deploy ransomware, extort victims and launder proceeds. It forms part of broader efforts to dismantle ransomware ecosystems and address associated financial activity. Approximately $1.09m in virtual currency linked to a 2023 ransom payment was seized following a warrant unsealed by the US Attorney’s Offices for the Eastern District of Virginia and the District of Columbia. The action was led by Homeland Security Investigations, the US Secret Service, IRS Criminal Investigation and the Federal Bureau of Investigation (FBI), in cooperation with law enforcement agencies from the UK, Germany, Ireland, France, Canada, Ukraine and Lithuania.