Cybercrime DB

Conti Group Internal Leaks and Subsequent Investigations

A ransomware gang's leaked chats revealed it operated like a legitimate Fortune 500 company.

Reporter · · 9 min read
Cover illustration for “Conti Group Internal Leaks and Subsequent Investigations”
ransomware groups and operators · August 20, 2026 · 9 min read · 2,089 words

In February 2022, somebody leaked a ransomware gang's group chat, and it read like every other office's group chat. HR complaints, a guy asking about his bonus, an actual employee of the month.

The gang was Conti, one of the most damaging ransomware operations on record. The leak handed the world its first real look inside a criminal enterprise built like a normal business, and three years later, prosecutors and researchers are still working through what it gave them. Some of what follows will sound made up, but it isn't.

How the Ukraine declaration triggered the most consequential data leak in ransomware history

Conti's big mistake in late February 2022 was political. Days after Russia invaded Ukraine, the group posted a statement backing the Kremlin. That post cracked the organization in half, since a chunk of Conti's own people were Ukrainian, had Ukrainian family, or just weren't in the mood to cheer for the invasion of their neighbor.

One of them decided that if Conti wanted to pick a side, fine. They'd pick one too, and started handing the group's internal files to anyone who'd take them.

On February 27, 2022, a Twitter account calling itself @ContiLeaks began posting the gang's private chat logs. Most people believe it was a Ukrainian security researcher who'd already gotten inside Conti's systems, though nobody's confirmed that publicly and probably never will. The material is what mattered, and the material was enormous.

People started calling it the Panama Papers of ransomware, and for once a comparison like that actually holds up. The Panama Papers showed how wealthy people hide money through shell structures nobody outside finance really understood, and the Conti leak did the same job on ransomware. It took a business model everyone assumed was chaotic and improvised, and showed it was neither.

VX-Underground ended up hosting most of it: chat logs running January 2021 through February 2022, thirteen months of daily back-and-forth. Source code for the ransomware itself and for TrickBot, the malware network Conti grew out of, was included as well. Login credentials for command-and-control servers, the admin panel, internal documentation, source for the locker, the decryptor, the builder rounded out the haul. Basically every tool in the shop.

This was the whole filing cabinet, drawers and all.

The corporate operating model the chats exposed

Read enough of the Conti chats and you start to forget you're reading criminal correspondence. People complain about workload, ask for raises, and get recognized for good performance, and yes, the group ran something close to an actual employee-of-the-month program.

The org chart that emerged had layers most companies would recognize immediately. Coders and testers built and QA'd the ransomware, while system administrators kept infrastructure running. Negotiators talked victims down, or up, depending on leverage, and middle managers coordinated all of it. HR handled staffing, because apparently even extortion needs onboarding paperwork.

Some employees reportedly had no idea what they actually worked for. They were told it was an advertising company. Which, in a roundabout way, isn't even a lie: extortion is just marketing with worse customer service.

Hours ran on Moscow business time, five days a week. The boss, known by the handle "Stern," managed a headcount that at one point topped one hundred people, with plans to hire a hundred more. Negotiators worked for a cut of what they brought in, while everyone else got paid every two weeks, salary style. Development ran in scrum sprints, the same framework a mid-size software company uses to ship features on a random Tuesday.

The corporate cosplay went further than internal operations, too. Conti ran fake front companies to book product demos with real security vendors, including attempts to get code-signing certificates from firms like CarbonBlack and Sophos. A ransomware gang, cold-calling cybersecurity vendors, pretending to be a paying customer, trying to get a certificate that would make its own malware look trustworthy: that's sales.

For defenders, this reframes the whole threat. You're up against a staffed organization with turnover, management overhead, and information stuck in departmental silos, the same headaches that slow down any company once it passes a dozen employees.

Venn diagram: Conti Ransomware: Criminal Enterprise vs. Legitimate Business. Compares Conti Operations and Legitimate Business; overlap: Shared Structures.

Financial flows, FSB ties, and what the blockchain and chat logs confirmed together

The leak didn't stop at org charts. It exposed the money too, and money leaves footprints even when the people moving it don't want it to.

Investigators got a primary-source record of ransom negotiations and payments, including from victim companies that quietly paid up and never told anyone. Hundreds of Bitcoin addresses showed up in the chats, giving blockchain analysts an actual map instead of a guess, and Conti's main Bitcoin address reportedly held a sum worth several billion dollars as of late February 2022.

The payment split confirmed something researchers had suspected but couldn't prove: most ransom money went to the affiliates carrying out the attacks, with a smaller cut kept by the core team. That's a franchise, closer to a licensing deal than a chain of command.

On-chain tracing also linked internal Conti payments back to a Ryuk wallet address CrowdStrike had flagged years earlier, connecting Ryuk and Conti through actual transaction records instead of code comparisons. Code similarity can always get argued away as coincidence or copying; money moving between the same wallets is definitive.

Then there's the part that turns this from a crime story into a geopolitics story. A chat exchange between two operators, handles "mango" and "johnyboy77," points to Russian intelligence funding part of Conti's operation. Another message describes Stern as tightly connected to the FSB and working for someone referred to only as "Pu." Separate chats show the FSB specifically wanted files from Bellingcat related to Alexei Navalny, and that request is squarely state intelligence collection.

Worth flagging for anyone doing incident response, by the way: the logs show Conti routinely lied about how much data it stole. The group claimed full exfiltration to scare victims into paying, when it had actually grabbed a fraction of what it threatened to leak, and now there's a paper trail proving it. The chats also confirmed years of coordination with the TrickBot and Emotet networks, down to internal debate over the TrickBot shutdown.

The Costa Rica attack as Conti's operational endgame under its own brand

Costa Rica is where Conti, already bleeding from the leak, doubled down instead of pulling back.

The intrusion into Costa Rican government networks started in early April 2022. Attackers spent several days inside quietly, grabbing data before triggering the encryption. When it hit, it hit wide: nearly thirty government institutions, including the Ministry of Finance, telecom providers, the national meteorological service, and the social security fund.

Costa Rica refused to pay. Conti's response was to raise the price and get louder about it publicly, a strange move for an organization already on fire from a leak, but consistency was never Conti's strong suit at this point. The country's newly inaugurated president declared a national emergency and called it an act of terrorism, the first time a head of state used that word for a ransomware attack. Tax collection stopped, customs processing stopped, and trade slowed to a crawl, with a daily cost to the economy that was steep by any measure.

Then, almost as if the universe wanted to pile on, a separate group called Hive hit the healthcare systems tied to Costa Rica's Social Security Fund. Tens of thousands of medical appointments had to get rescheduled, and hundreds of servers and computers went down.

About ten days into the Costa Rica attack, Conti's leadership started pulling its own infrastructure offline. By late June 2022, the negotiation sites and the leak site were dark for good. Costa Rica was Conti's last major swing under its own name, thrown by a group that already knew the walls were closing in and chose to escalate anyway.

How Conti dissolved into successor groups and why the brand's end did not mean the threat ended

Diagram: Conti's Collapse: From Leak to Diaspora. Visualizes: Visualise the sequential collapse of Conti from the February 27 2022 leak through to its fragmentation into successor groups.

Recorded Future's read on the collapse is worth sitting with: the leak didn't cause Conti's dissolution on its own. It poured gasoline on tensions already smoldering inside the group before a single chat log went public.

The shutdown happened in stages. Exposed servers came down in early March 2022, and the negotiation and leak sites followed in late June. What came out the other side was a scattering.

Members regrouped under new banners: Quantum, Hive, AvosLocker, BlackCat, Hello Kitty, Karakurt, BlackByte, and a group known as BazarCall. Same people, same skills, different letterhead.

This rebrand-and-reconstitute move wasn't new for this crew, either. It's exactly what happened when Ryuk became Conti in the first place, and the chats confirm the pattern was deliberate, not accidental. For defenders, the takeaway is blunt: the brand is disposable, the people endure. Coders keep coding, negotiators keep negotiating, and institutional knowledge travels when a leak site goes dark, carrying forward under a new business card.

Fragmentation made prosecution messier too. Investigators went from chasing one target to chasing a diaspora of overlapping crews, all sharing an infrastructure history but running as separate operations with separate names and, in some cases, separate victims.

The sanctions and indictments the leaked intelligence made possible

The leak turned into legal ammunition fast, and it kept firing for years.

In May 2022, the US State Department's Rewards for Justice program offered a reward for information on Conti's leadership, publicly naming and, for the first time, releasing an image of a Conti operative known by the handle "Target."

By February 2023, the US and UK issued their first joint cyber sanctions, aimed at TrickBot group members. It was also the first designation made under the UK's newly created cyber sanctions authority. Both governments said, plainly, that the individuals named were tied to Russian intelligence services, language backed by the leaked chats rather than assumption.

September 2023 brought three separate federal indictments across three US jurisdictions, charging multiple Russian nationals tied to the TrickBot and Conti schemes. Some named defendants used handles that showed up directly in the leaked logs: Bentley, Buza, Mango, Defender, and others. A separate indictment out of the Southern District of California went after the Conti attack on Scripps Health specifically, proving individual victim incidents could get charged on their own instead of folded into one giant conspiracy case.

There'd already been earlier wins, too. TrickBot developer Alla Witte pleaded guilty and was sentenced, and Vladimir Dunaev was sentenced in early 2024. None of that happens as cleanly without the chat logs mapping handles to real activity, tying financial transactions together, closing the gap between a wallet address and an actual name. The FSB connection documented in the leak gave the sanctions language its backbone too. "Associated with Russian intelligence" wasn't a hedge in these filings. It was a citation.

What the Conti leaks changed about how defenders understand professionalised ransomware

Before this leak, everyone in security assumed ransomware gangs had some kind of internal structure. Reasonable guess, given how consistently these groups operated, but still a guess.

After the leak, it stopped being one. Reading it in the group's own words, rather than suspecting it, is basically the whole story here.

Ransomware crews carry HR overhead, deal with staff turnover, fight internal conflict, and all of that is an actual opening for anyone trying to track or disrupt them. The double-extortion bluff, where Conti claimed total data theft while holding a fraction of what it threatened to leak, changes how seriously incident responders should take a leak-site threat today. And the fake front companies chasing code-signing certificates point at a vendor verification gap that goes well beyond one gang, so if it worked once, somebody will try it again.

The state linkage is probably the biggest shift in how people think about this now. Once the FSB connection had primary-source backing instead of just suspicion, the security community had to treat ransomware as both financially motivated crime and a tool a state intelligence service can direct, fund, or quietly benefit from. Those two categories overlap, and February 2022 made that undeniable.

The leak also made tracking Conti's descendants easier, since analysts now had a known roster of personnel to check against. Handle reuse, code overlap, operational habits carried from one outfit to the next all turned into detectable patterns.

What sticks, years later, is what the leak did to the category itself. A closed criminal operation turned into an open book, and that book is still paying out: in indictments, in sanctions, in the assumptions researchers now bring to the next group that shows up acting suspiciously well-organized.

Sources

  1. rapid7.com
  2. krebsonsecurity.com
  3. cnbc.com
  4. cisecurity.org
  5. techcrunch.com
  6. globalinitiative.net
  7. thehackernews.com

More in ransomware groups and operators