LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
Critical🔐 Ransomware

Conti Ransomware — The Corporate Ransomware Gang

Conti ransomware-as-a-service shut down Ireland's national health service in 2021 and attacked 1,000+ victims worldwide using double extortion and data theft.

Published: 20 May 2026Last updated: 10 February 2026

What Is This Threat?

Conti was one of the most prolific and damaging ransomware groups in history, operating from approximately 2020 to 2022 as a Ransomware-as-a-Service (RaaS) business. Like a franchise, Conti's core developers leased their ransomware code and infrastructure to affiliate hackers who conducted attacks, keeping 70% of the ransom while Conti took 30%.

Conti pioneered double extortion: not only encrypting victims' files but also exfiltrating sensitive data and threatening to publish it on a public leak site if the ransom was not paid. This doubled the pressure on victims and made backups alone insufficient as a defence.

How It Operated

Initial Access — Getting In:

  • Phishing emails with malicious attachments (often using TrickBot or BazarLoader malware as a first-stage dropper)
  • Exploiting unpatched VPN vulnerabilities (Fortinet, Citrix)
  • Purchasing access from initial access brokers on dark web marketplaces
  • Lateral Movement — Taking Over the Network:

  • Once inside, attackers used Cobalt Strike (a legitimate penetration testing tool) to move across the network
  • They would spend days or weeks mapping the network, identifying backup systems, and stealing data before deploying ransomware
  • Backup servers were deliberately targeted and destroyed first
  • The Ransom:

  • Typical demands ranged from $1 million to $25 million
  • Victims who paid received a decryption tool; those who refused saw their data published on Conti's "Conti News" leak site
  • Real-World Impact

  • Ireland's Health Service Executive (HSE), May 2021: Conti's most devastating attack. Ireland's entire national healthcare IT system was shut down. Hospitals reverted to paper records. Cancer screenings, radiology, and outpatient services were suspended across the country. Recovery took weeks and cost an estimated €100 million. The Irish government refused to pay the ransom.
  • Costa Rica Government, April–May 2022: Conti attacked 27 Costa Rican government agencies simultaneously. President Rodrigo Chaves declared a national emergency — the first time a government declared a state of emergency solely due to a ransomware attack. Conti demanded $20 million.
  • Waikato District Health Board (New Zealand), May 2021: Patient data including surgical records and staff information was published after the health board refused to pay.
  • Over 1,000 organizations attacked across the US, UK, Europe, and beyond. FBI estimated Conti cost US victims alone over $150 million.
  • The Conti Leaks (February–March 2022):

    After Conti publicly declared support for Russia following the invasion of Ukraine, an anonymous Ukrainian researcher leaked over 170,000 internal Conti chat messages and their source code. The leaks revealed Conti operated like a modern tech company: HR departments, performance reviews, salary structures (developers earned $1,500–$2,000/month), management hierarchies, and detailed attack playbooks. The exposure effectively destroyed the group by mid-2022, with members disbanding into successor groups including BlackBasta, Royal, and Akira.

    Why It Matters Today

    Conti's successors continue operating. The tactics, techniques, and tools Conti developed — double extortion, RaaS affiliate models, targeting healthcare — are now standard across the ransomware ecosystem.

    Red Flags for Organizations

  • Unusual scheduled tasks, new admin accounts, or disabled security software detected overnight.
  • Large volumes of data being copied to external IPs or cloud storage unexpectedly.
  • Cobalt Strike beacons detected by endpoint protection.
  • Dark web intelligence showing your organization's credentials being sold.
  • How to Protect Yourself

    • Implement multi-factor authentication (MFA) on all remote access, VPN, and admin accounts — Conti frequently entered via stolen VPN credentials
    • Maintain offline backups that are completely disconnected from the network — Conti specifically sought and destroyed connected backup systems before deploying ransomware
    • Patch VPN appliances and internet-facing systems immediately — Conti exploited known Fortinet and Citrix vulnerabilities that had available patches
    • Deploy endpoint detection and response (EDR) tools that can detect Cobalt Strike and lateral movement patterns
    • Segment your network so that compromise of one system cannot lead to full network takeover

    What to Do If Affected

    1. 1.Activate your incident response plan immediately — isolate affected systems without shutting down entirely to preserve forensic evidence
    2. 2.Contact a specialist ransomware incident response firm before deciding whether to negotiate or restore from backups
    3. 3.Report to your national cybersecurity authority (Austria: cert.at, Germany: BSI, Ukraine: CERT-UA) and law enforcement
    4. 4.Do not pay the ransom without taking legal and expert advice — payment does not guarantee data deletion, and in some jurisdictions paying ransomware groups may violate sanctions laws
    5. 5.Check the No More Ransom project (nomoreransom.org) — free Conti decryptors may be available due to the leaked source code
    #Conti#ransomware#RaaS#Russia#Ireland HSE#Costa Rica#double extortion#healthcare