Hive Ransomware Group and Interagency Searches

Jordan Lassiter filed this request with the Federal Bureau of Investigation of the United States of America.
Tracking #

A-2023-01191

1585410-000

Status
Rejected

Communications

From: Jordan Lassiter

To Whom It May Concern:

Pursuant to the Freedom of Information Act, I hereby request the following records:

I am writing to request information on the Hive ransomware group as part of a Freedom of Information Act (FOIA) request. According to recent news reports from the Department of Justice, the Hive ransomware group has been responsible for numerous attacks targeting organizations in various sectors, including healthcare, finance, and government. In light of this information, I am interested in obtaining any records, documents, or information that the FBI may have regarding the Hive ransomware group.

Specifically, I am requesting any information that the FBI may have on the Hive ransomware group, including but not limited to:

Any investigations or operations related to the Hive ransomware group
Any intelligence reports or assessments on the Hive ransomware group
Any communications or correspondence with other law enforcement agencies or foreign governments regarding the Hive ransomware group
Any technical information or analysis on the Hive ransomware group's tactics, techniques, and procedures (TTPs)
Any indicators of compromise (IOCs) or other information that could help identify and mitigate Hive ransomware attacks
I am also requesting that interagency searches be conducted for any responsive records, documents, or information that may be held by other government agencies.

Please provide any responsive records, documents, or information that the FBI may have on the Hive ransomware group, including any redacted or partially withheld documents with an explanation of the basis for withholding. This request is being made in the interest of public safety and to help organizations defend against Hive ransomware attacks.

In addition, I am requesting that any information be provided from the FBI's Cyber Division groups, including the Cyber Criminal Section and the Cyber Task Forces.

String keywords: Hive ransomware group, cybercrime, healthcare, finance, government, investigations, intelligence reports, law enforcement, technical information, tactics, techniques, procedures, indicators of compromise, public safety, electronic format, Department of Justice, interagency searches, Cyber Division groups, Cyber Criminal Section, Cyber Task Forces.

"Please note that this FOIA request is being submitted through the MuckRock platform, which operates as a public records repository. All communications related to this request, including the request itself, may be made public on the MuckRock website or through other channels. Therefore, please do not include any confidential or sensitive information in your response to this request. If you have any concerns about the public disclosure of any information related to this request, please contact me directly at obscure.sender(@)proton.me PGP:pub eddsa263/971160b32902eb9c470ef377c0a20f0b8d1bae1a "

The requested documents will be made available to the general public, and this request is not being made for commercial purposes.

In the event that there are fees, I would be grateful if you would inform me of the total charges in advance of fulfilling my request. I would prefer the request filled electronically, by e-mail attachment if available or CD-ROM if not.

Thank you in advance for your anticipated cooperation in this matter. I look forward to receiving your response to this request within 20 business days, as the statute requires.

Sincerely,

Jordan

From: Federal Bureau of Investigation

There are eFOIA files available for you to download.

  • E015d4891bd14efe4c7754c18ce886ce8a5529f77_Q179671_D164938686

From: Federal Bureau of Investigation

The request has been rejected by the agency.

From: Jordan Lassiter

Dear FOIA Officer,

I am writing to appeal the denial of my FOIA request dated March 15, 2023, regarding any investigations or operations related to the Hive ransomware group, intelligence reports or assessments on the Hive ransomware group, communications or correspondence with other law enforcement agencies or foreign governments regarding the Hive ransomware group, technical information or analysis on the Hive ransomware group's tactics, techniques, and procedures (TTPs), and indicators of compromise (IOCs) or other information that could help identify and mitigate Hive ransomware attacks.

Firstly, I would like to clarify that my request was not for general information on ransomware, but specifically for information related to the Hive ransomware group. This information is of great importance to me as I am currently researching the topic for a project and need the latest information available to accurately analyze the situation.

Secondly, I am requesting that interagency searches be conducted for any responsive records, documents, or information that may be held by other government agencies. It is possible that information on the Hive ransomware group may be held by other agencies, and it is imperative that all relevant information is collected and shared to accurately assess the threat posed by this group.

Finally, I would like to point out that the denial of my request was based on the exemption for records that are specifically exempted from disclosure by statute. However, I believe that the public interest in knowing about the activities of the Hive ransomware group outweighs any potential harm that may result from the disclosure of this information.

Therefore, I respectfully request that you reconsider the denial of my FOIA request and provide me with any and all responsive records, documents, or information related to the Hive ransomware group as soon as possible.

Thank you for your attention to this matter.

Sincerely,

Jordan

From: Federal Bureau of Investigation

There are eFOIA files available for you to download.

You can download the files at:

* [E015d4891bd14efe4c7754c18ce886ce8a5529f77_Q179671_D164949526.pdf](https://efoia.fbi.gov/download-file/submission-015d4891bd14efe4c7754c18ce886ce8a5529f77/myF8nuTXNuW3bKR/E015d4891bd14efe4c7754c18ce886ce8a5529f77_Q179671_D164949526.pdf)

**Please Note:**

The above link(s) are only active for 48hrs. After the link expires you will
have the option to reactivate the link(s) for an additional 48hrs. The max
renewal limit is two (2) times. Thereafter, the links can no longer be
accessed.

You can renew the download files by logging into the efoia system and clicking
the "Renew" button in the file list.

  • E015d4891bd14efe4c7754c18ce886ce8a5529f77_Q179671_D164949526

From: Jordan Lassiter

Dear Sir/Madam,

I am writing in regards to my FOIPA Request No.: 1585410-000 regarding the Hive Ransomware. I received your response stating that the information I requested is located in an investigative file and is exempt from disclosure pursuant to 5 U.S.C. § 552(b)(7)(A) because it could reasonably be expected to interfere with enforcement proceedings.

However, I am concerned about the handling of my FOIPA request as it appears that the FBI has not properly followed the procedures for processing FOIPA requests. Specifically, I was instructed to email another department for questions regarding the FBI's determinations. This is confusing and unclear, and I request that all communication regarding my request be directed to me through the contact information provided in my original request.

Furthermore, I believe that the FBI has not properly applied the exemption cited in your response. As a FOIPA requester, I have a right to challenge the FBI's application of exemptions and to appeal your determination if I believe that an exemption has been applied improperly. I request that the FBI provide a more detailed explanation of why the release of the information could reasonably be expected to interfere with enforcement proceedings and provide me with any non-exempt portions of the records, if any exist.

Lastly, I am also concerned about the improper handling of my FOIPA request by the FBI. I would like to file a complaint regarding this issue and request that the FBI investigate and take appropriate corrective action. Please provide me with information on how to file a complaint.

Thank you for your attention to this matter, and I look forward to your prompt response.

Sincerely,

Jordan

From: Jordan Lassiter

Dear Sir/Madam,

I am writing in regards to my FOIPA Request No.: 1585410-000 regarding the Hive Ransomware. I received your response stating that the information I requested is located in an investigative file and is exempt from disclosure pursuant to 5 U.S.C. § 552(b)(7)(A) because it could reasonably be expected to interfere with enforcement proceedings.

However, I am concerned about the handling of my FOIPA request as it appears that the FBI has not properly followed the procedures for processing FOIPA requests. Specifically, I was instructed to email another department for questions regarding the FBI's determinations. This is confusing and unclear, and I request that all communication regarding my request be directed to me through the contact information provided in my original request.

Furthermore, I believe that the FBI has not properly applied the exemption cited in your response. As a FOIPA requester, I have a right to challenge the FBI's application of exemptions and to appeal your determination if I believe that an exemption has been applied improperly. I request that the FBI provide a more detailed explanation of why the release of the information could reasonably be expected to interfere with enforcement proceedings and provide me with any non-exempt portions of the records, if any exist.

Lastly, I am also concerned about the improper handling of my FOIPA request by the FBI. I would like to file a complaint regarding this issue and request that the FBI investigate and take appropriate corrective action. Please provide me with information on how to file a complaint.

Thank you for your attention to this matter, and I look forward to your prompt response.

Sincerely,

Jordan

  • E015d4891bd14efe4c7754c18ce886ce8a5529f77_Q179671_D164949526

From: Federal Bureau of Investigation

The Office of Information Policy has received your FOIA Appeal.  Please see the attached acknowledgment letter.

From: Federal Bureau of Investigation

The Office of Information Policy has made its final determination on your FOIA Appeal Number A-2023-01191 .  A copy of this determination is enclosed for your review, along with any enclosures, if applicable.  Thank you.

Files

pages

Close