Free tools Windows power users keep installed
One-click scans. No signup required.
Elliptic and Corvus Insurance reported on November 29, 2023, that they had identified at least $107 million in Bitcoin ransom payments linked to Black Basta and more than 90 paying victims. That is a credible lower-bound estimate for transactions Elliptic and Corvus could attribute in their November 2023 analysis—not a definitive lifetime revenue figure or a count of all organizations the operation attacked.
The distinction matters: Elliptic identified more than 329 organizations attacked or listed in its 2023 review, while a May 2024 U.S. government advisory said Black Basta affiliates had impacted more than 500 organizations worldwide. Those figures measure different things.
The numbers behind the $100 million headline
| Measure | Reported figure | What it means |
|---|---|---|
| Identified ransom payments | At least $107 million | Bitcoin payments Elliptic linked to Black Basta; a lower bound |
| Paying victims | More than 90 | Organizations associated with identified payments |
| Largest identified payment | $9 million | Largest transaction in the analysis |
| Payments above $1 million | At least 18 | Minimum number identified |
| Average identified payment | About $1.2 million | Average reported by Elliptic, not a separate audit of total revenue |
| Known listed victims appearing to pay | At least 35% | Comparison of payment data with leak-site listings through the third quarter of 2023 |
Sources: Elliptic and Corvus Insurance.
What the estimate does—and does not—show
It is identified Bitcoin, not a complete income statement
Elliptic and Corvus counted transactions they could connect to Black Basta with high confidence. Payments can be missed when victims do not disclose wallet information, funds pass through intermediaries, wallets have not been identified, or laundering and chain-hopping obscure the trail. The estimate also predates later incidents. It therefore should be written as “at least $107 million in identified payments,” not “Black Basta made exactly $107 million.”
More than 90 payers is not 90 total victims
Some organizations may have refused to pay, negotiated without a payment, recovered from backups, or never appeared in Elliptic’s payment data. A leak-site claim is not proof that an organization paid, that data was stolen as claimed, or that the posted ransom amount was accurate.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
The average is not a safe multiplier
The approximately $1.2 million average and the “more than 90” victim count do not necessarily use exactly the same denominator. Multiplying them is not an independent verification of the $107 million total.
How investigators followed the cryptocurrency
Ransomware crews typically use many addresses rather than one permanent wallet. Investigators compare known payment addresses, transaction timing, wallet-clustering patterns and links to exchanges or laundering services. Elliptic also traced some proceeds toward Garantex, a Russian cryptocurrency exchange sanctioned by the United States.
Blockchain evidence is powerful but not infallible. A flow through a service associated with Black Basta does not automatically prove that every transaction belonged to the group. Elliptic also found overlaps with infrastructure associated with Conti, complicating attribution. Its report supports a strong link, not a claim that every related payment can be assigned with certainty.
Rank #2
Methodology: Elliptic’s investigation.
Why victim counts range from 329 to more than 500
| Date and source | Figure | Counting context |
|---|---|---|
| November 2023, Elliptic | More than 329 | Organizations attacked or listed in Elliptic’s 2023 review |
| May 2024, FBI, CISA, HHS and MS-ISAC | More than 500 | Organizations globally impacted by Black Basta affiliates |
The sources may count different combinations of claimed victims, confirmed compromises, stolen-data incidents, encrypted systems, affiliate activity and corporate groups. Always attach the date and methodology to the number. The federal advisory also said affiliates had encrypted and stolen data from victims in at least 12 of 16 U.S. critical-infrastructure sectors, including healthcare and public health.
Recommended Free Tools
Sources: CISA joint advisory and FBI IC3 copy.
How the Black Basta operation worked
Ransomware as a service
Black Basta emerged around April 2022 as a ransomware-as-a-service operation. Core operators supplied malware, negotiation infrastructure, leak sites and payment systems; affiliates obtained access, moved through networks, stole data and deployed the encryptor. Initial-access brokers or other malware operators could supply entry. That structure is why the operation should not be described as a conventional company with a single transparent hierarchy.
Double extortion
- Attackers stole sensitive files.
- They encrypted systems or data.
- They demanded payment for decryption and confidentiality.
- They threatened to publish the stolen material on a leak site.
Observed access methods included spearphishing, exploitation of known vulnerabilities, valid-account abuse and Qakbot-assisted access. The FBI advisory documented exploitation of ConnectWise vulnerability CVE-2024-1709 beginning in February 2024.
Social engineering and remote tools
An update dated November 8, 2024 described email bombing or spam flooding followed by impersonation of technical support through Microsoft Teams. Victims could be urged to install legitimate remote-access tools such as AnyDesk or Microsoft Quick Assist. The tools themselves are not malware, but an attacker-controlled session can provide a route into an otherwise protected environment.
Sources: November 2024 advisory and FBI advisory.
The Conti connection is significant but not definitive
Elliptic identified wallet and operational similarities supporting the theory that Black Basta was an offshoot, successor or rebrand associated with Conti after Conti’s 2022 shutdown. “Linked to Conti” is supportable; “Black Basta was definitively Conti” is not. Shared personnel, wallets and services can create overlap without proving that every participant or payment belonged to one organization.
Organizations publicly associated with Black Basta
Contemporary reporting and leak-site claims named Capita, ABB, Dish Network, Thales, Rheinmetall and Maple Leaf Foods. Listing is not independent confirmation of payment. Elliptic reported that neither Capita nor ABB had publicly disclosed whether they paid Black Basta.
Rank #4
See SecurityWeek’s account and BleepingComputer’s explanation.
Timeline of the available evidence
- April 2022: U.S. government reporting identifies Black Basta as emerging around this period.
- November 29, 2023: Elliptic publishes the estimate of at least $107 million from more than 90 paying victims.
- May 10, 2024: FBI, CISA, HHS and MS-ISAC report more than 500 organizations impacted globally.
- November 8, 2024: The advisory adds email-bombing, Teams impersonation and remote-access-tool techniques.
- 2025: Justice Department filings allege Qakbot-related access was used in Black Basta deployments, including activity alleged as recently as January 2025.
The Qakbot allegations are indictment and enforcement claims, not a final adjudication of every factual assertion. Sources: DOJ indictment announcement and DOJ Qakbot background.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What ransom notes and payment pressure looked like
The FBI advisory said ransom notes generally did not provide an initial price or payment instructions. Instead, victims received a unique code and an onion URL for contact through Tor. Victims typically had 10 to 12 days to pay before publication was threatened.
Payment does not guarantee complete decryption, deletion of stolen data, an end to extortion or freedom from sanctions and legal exposure. Organizations facing an incident should involve counsel, law enforcement, insurers and qualified incident responders rather than treating payment as a guaranteed recovery service.
Practical lessons for organizations
- Apply operating-system, software and firmware updates promptly, prioritizing internet-facing systems and known exploited vulnerabilities.
- Use phishing-resistant multifactor authentication wherever possible, especially for administrators and remote access.
- Keep offline or otherwise protected backups and test restoration regularly.
- Train staff to report phishing, unexpected Teams contacts, email floods and unusual support requests.
- Monitor and restrict remote-access tools according to business need; investigate unexpected AnyDesk or Quick Assist activity.
- Prepare an incident-response and ransomware-reporting plan, including log preservation, ransom-note collection and wallet evidence.
These controls reduce risk but cannot guarantee immunity. Endpoint detection, managed monitoring, recovery technology, insurance and blockchain investigation services should be evaluated as parts of a coordinated program, not substitutes for one another.
The Bottom Line
The November 2023 finding is best stated precisely: Elliptic and Corvus identified at least $107 million in Bitcoin ransom payments linked to more than 90 Black Basta victims. It was a lower-bound transaction estimate, not a current 2026 revenue total. Black Basta’s broader reach was substantially larger, with more than 329 organizations attacked or listed in Elliptic’s 2023 review and more than 500 organizations reported impacted by May 2024.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




