DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
Bitcoin

Black Basta Took at Least $107 Million From More Than 90 Ransomware Victims, Researchers Found

A 2023 blockchain investigation found at least $107 million in Black Basta ransom payments from more than 90 victims—but the figure was a lower bound, not a complete or current revenue total.

By TheFinanceBase Team 5 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Elliptic and Corvus Insurance reported on November 29, 2023, that they had identified at least $107 million in Bitcoin ransom payments linked to Black Basta and more than 90 paying victims. That is a credible lower-bound estimate for transactions Elliptic and Corvus could attribute in their November 2023 analysis—not a definitive lifetime revenue figure or a count of all organizations the operation attacked.

The distinction matters: Elliptic identified more than 329 organizations attacked or listed in its 2023 review, while a May 2024 U.S. government advisory said Black Basta affiliates had impacted more than 500 organizations worldwide. Those figures measure different things.

The numbers behind the $100 million headline

Measure Reported figure What it means
Identified ransom payments At least $107 million Bitcoin payments Elliptic linked to Black Basta; a lower bound
Paying victims More than 90 Organizations associated with identified payments
Largest identified payment $9 million Largest transaction in the analysis
Payments above $1 million At least 18 Minimum number identified
Average identified payment About $1.2 million Average reported by Elliptic, not a separate audit of total revenue
Known listed victims appearing to pay At least 35% Comparison of payment data with leak-site listings through the third quarter of 2023

Sources: Elliptic and Corvus Insurance.

What the estimate does—and does not—show

It is identified Bitcoin, not a complete income statement

Elliptic and Corvus counted transactions they could connect to Black Basta with high confidence. Payments can be missed when victims do not disclose wallet information, funds pass through intermediaries, wallets have not been identified, or laundering and chain-hopping obscure the trail. The estimate also predates later incidents. It therefore should be written as “at least $107 million in identified payments,” not “Black Basta made exactly $107 million.”

More than 90 payers is not 90 total victims

Some organizations may have refused to pay, negotiated without a payment, recovered from backups, or never appeared in Elliptic’s payment data. A leak-site claim is not proof that an organization paid, that data was stolen as claimed, or that the posted ransom amount was accurate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The average is not a safe multiplier

The approximately $1.2 million average and the “more than 90” victim count do not necessarily use exactly the same denominator. Multiplying them is not an independent verification of the $107 million total.

How investigators followed the cryptocurrency

Ransomware crews typically use many addresses rather than one permanent wallet. Investigators compare known payment addresses, transaction timing, wallet-clustering patterns and links to exchanges or laundering services. Elliptic also traced some proceeds toward Garantex, a Russian cryptocurrency exchange sanctioned by the United States.

Blockchain evidence is powerful but not infallible. A flow through a service associated with Black Basta does not automatically prove that every transaction belonged to the group. Elliptic also found overlaps with infrastructure associated with Conti, complicating attribution. Its report supports a strong link, not a claim that every related payment can be assigned with certainty.

Methodology: Elliptic’s investigation.

Why victim counts range from 329 to more than 500

Date and source Figure Counting context
November 2023, Elliptic More than 329 Organizations attacked or listed in Elliptic’s 2023 review
May 2024, FBI, CISA, HHS and MS-ISAC More than 500 Organizations globally impacted by Black Basta affiliates

The sources may count different combinations of claimed victims, confirmed compromises, stolen-data incidents, encrypted systems, affiliate activity and corporate groups. Always attach the date and methodology to the number. The federal advisory also said affiliates had encrypted and stolen data from victims in at least 12 of 16 U.S. critical-infrastructure sectors, including healthcare and public health.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: CISA joint advisory and FBI IC3 copy.

How the Black Basta operation worked

Ransomware as a service

Black Basta emerged around April 2022 as a ransomware-as-a-service operation. Core operators supplied malware, negotiation infrastructure, leak sites and payment systems; affiliates obtained access, moved through networks, stole data and deployed the encryptor. Initial-access brokers or other malware operators could supply entry. That structure is why the operation should not be described as a conventional company with a single transparent hierarchy.

Double extortion

  1. Attackers stole sensitive files.
  2. They encrypted systems or data.
  3. They demanded payment for decryption and confidentiality.
  4. They threatened to publish the stolen material on a leak site.

Observed access methods included spearphishing, exploitation of known vulnerabilities, valid-account abuse and Qakbot-assisted access. The FBI advisory documented exploitation of ConnectWise vulnerability CVE-2024-1709 beginning in February 2024.

Social engineering and remote tools

An update dated November 8, 2024 described email bombing or spam flooding followed by impersonation of technical support through Microsoft Teams. Victims could be urged to install legitimate remote-access tools such as AnyDesk or Microsoft Quick Assist. The tools themselves are not malware, but an attacker-controlled session can provide a route into an otherwise protected environment.

Sources: November 2024 advisory and FBI advisory.

The Conti connection is significant but not definitive

Elliptic identified wallet and operational similarities supporting the theory that Black Basta was an offshoot, successor or rebrand associated with Conti after Conti’s 2022 shutdown. “Linked to Conti” is supportable; “Black Basta was definitively Conti” is not. Shared personnel, wallets and services can create overlap without proving that every participant or payment belonged to one organization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organizations publicly associated with Black Basta

Contemporary reporting and leak-site claims named Capita, ABB, Dish Network, Thales, Rheinmetall and Maple Leaf Foods. Listing is not independent confirmation of payment. Elliptic reported that neither Capita nor ABB had publicly disclosed whether they paid Black Basta.

See SecurityWeek’s account and BleepingComputer’s explanation.

Timeline of the available evidence

  • April 2022: U.S. government reporting identifies Black Basta as emerging around this period.
  • November 29, 2023: Elliptic publishes the estimate of at least $107 million from more than 90 paying victims.
  • May 10, 2024: FBI, CISA, HHS and MS-ISAC report more than 500 organizations impacted globally.
  • November 8, 2024: The advisory adds email-bombing, Teams impersonation and remote-access-tool techniques.
  • 2025: Justice Department filings allege Qakbot-related access was used in Black Basta deployments, including activity alleged as recently as January 2025.

The Qakbot allegations are indictment and enforcement claims, not a final adjudication of every factual assertion. Sources: DOJ indictment announcement and DOJ Qakbot background.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What ransom notes and payment pressure looked like

The FBI advisory said ransom notes generally did not provide an initial price or payment instructions. Instead, victims received a unique code and an onion URL for contact through Tor. Victims typically had 10 to 12 days to pay before publication was threatened.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Payment does not guarantee complete decryption, deletion of stolen data, an end to extortion or freedom from sanctions and legal exposure. Organizations facing an incident should involve counsel, law enforcement, insurers and qualified incident responders rather than treating payment as a guaranteed recovery service.

Practical lessons for organizations

  • Apply operating-system, software and firmware updates promptly, prioritizing internet-facing systems and known exploited vulnerabilities.
  • Use phishing-resistant multifactor authentication wherever possible, especially for administrators and remote access.
  • Keep offline or otherwise protected backups and test restoration regularly.
  • Train staff to report phishing, unexpected Teams contacts, email floods and unusual support requests.
  • Monitor and restrict remote-access tools according to business need; investigate unexpected AnyDesk or Quick Assist activity.
  • Prepare an incident-response and ransomware-reporting plan, including log preservation, ransom-note collection and wallet evidence.

These controls reduce risk but cannot guarantee immunity. Endpoint detection, managed monitoring, recovery technology, insurance and blockchain investigation services should be evaluated as parts of a coordinated program, not substitutes for one another.

The Bottom Line

The November 2023 finding is best stated precisely: Elliptic and Corvus identified at least $107 million in Bitcoin ransom payments linked to more than 90 Black Basta victims. It was a lower-bound transaction estimate, not a current 2026 revenue total. Black Basta’s broader reach was substantially larger, with more than 329 organizations attacked or listed in Elliptic’s 2023 review and more than 500 organizations reported impacted by May 2024.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.