
Oct 6, 2026 · 1h 4m
Conti’s rise and collapse reveal ransomware’s corporate machinery
180: Conti
Conti’s story shows how a ransomware gang could professionalize, devastate public services, and survive its own exposure by dispersing its members.
- 1Conti evolved from earlier Russian cybercrime networks into a structured enterprise with recruiters, departments, budgets, and affiliates.
- 2Its attack on Ireland’s health service exposed the human cost of ransomware beyond encrypted files and financial demands.
- 3The ContiLeaks breach fractured the group, but many operatives carried its tools, expertise, and connections into other gangs.
Don't miss
Alex Holden recounts how his team infiltrated the criminal network and mapped its internal communications, departments, and attack plans.
The brief
Geoff White traces Conti’s lineage through earlier Russian cybercrime groups, while recruitment stories show how ordinary job listings could conceal a highly organized criminal enterprise.
A programmer known as Max joined what appeared to be a remote coding company, only to discover that her work supported ransomware—and that poor operational security exposed her identity.
Conti’s attack on Ireland’s health service forced hospitals back onto paper during the COVID-19 pandemic, illustrating how double-dip extortion turns digital disruption into public harm.
Alex Holden describes infiltrating the gang and mapping its departments, budgets, and attack plans, revealing a company-like structure that still targeted hospitals despite supposed internal rules.
Russia’s invasion of Ukraine split Conti, and a Ukrainian specialist’s retaliation released tens of thousands of messages, member details, attack plans, and financial information.
Conti appeared to collapse after the leaks, but affiliates and former members moved elsewhere, making the gang’s downfall less an ending than a redistribution of capability.
Books & mentions
The Conti Files
The episode promotes this related collection for further reporting on Conti’s leaked operations.