01Overview

Every major disruption operation against the RU/CIS ransomware ecosystem since 2019, scored 1-5 for what it actually achieved: neutralization, degradation, displacement, or nothing. The question this page answers: which authorities' actions degrade the ecosystem, and which just move it. Source of truth: data/scoreboard.json; methodology in section 06.

02Authority Scorecard

Average effectiveness of each authority's operations. Co-led operations credit every named authority; averages exclude too-recent (TBD) actions. Rows with fewer than 3 scored actions carry a small-sample flag.

Avg score ↕ Authority Actions ↕ Neutralized Failures Signature action Pattern
4.0+ reliably neutralizes targets 3.0-3.9 degrades more than displaces <3.0 actions displaced or absorbed * fewer than 3 scored actions
03Degrade vs Displace

Outcome distribution across all scored operations, the operations the ecosystem simply absorbed, and how fast each layer reconstitutes after a hit.

Displacement watch: operations scored 2 or lower

DateOperationScoreWhere it went

Reconstitution speed by layer

EventRecovery timeLayerConf.

Pattern: Russian-language financial infrastructure reconstitutes in 1-14 days when personnel are untouched. Recovery time scales with personnel exposure, not with the size of the seizure.

04Operations

All scored operations. Click any row for the full assessment: action components, personnel outcome, measured impact, and score rationale. Every row links to a primary source.

Result All Neutralized (4-5) Degraded (3) Failures (1-2) Too recent
Target layer All Ransomware Financial BPH Malware / enablers
Period All 2021-2024 2025 2026
Date ↕ OperationTargetAuthorities Score ↕ OutcomeConf.Src
05Findings

What the scored record shows. Each finding states its evidence, confidence, and the leverage implication.

06Methodology

Scoring scale

ScoreLabelDefinition

Rules

The unit of analysis is the operation, not the press release: coordinated multi-authority actions are one row, and every named lead authority is credited with that row's score. Averages exclude operations under roughly 90 days old (marked TBD), because reconstitution takes weeks to observe. Individual arrests are recorded inside their parent operation's personnel outcome rather than as separate rows.

Re-score policy

Scores are not static. A brand that resurfaces, a successor that reaches material scale, or a fugitive brought into custody triggers a re-score at the next revision, in either direction. Each revision is dated and the workbook behind this page preserves the full history.

Confidence and sources

Confirmed primary source (official press release, court filing) or multiple credible sources. Credible single reputable vendor or media source. Assessments and inferences are labeled as such in the row detail. Every operation links to at least one primary source.

Independence

This scoreboard is independent research. It is not affiliated with, endorsed by, or informed by non-public material from any government or law enforcement agency. Scoring reflects publicly observable outcomes: whether the target kept operating, how fast it recovered, and whether anyone was held accountable. Corrections are welcome and will be applied with a dated note.