The U.S. Justice Department disclosed on July 19, 2022 that federal investigators had seized approximately $500,000 in cryptocurrency connected to North Korean state-sponsored ransomware attacks against American healthcare providers.

The announcement paired a completed seizure with a newly public civil-forfeiture proceeding in the District of Kansas. The FBI had obtained a sealed seizure warrant in May 2022 and taken the contents of two cryptocurrency accounts. The July 19 development was the government’s public disclosure of that operation and its effort to forfeit and return funds—not a claim that every related hacker or money launderer had been identified or arrested.

The case mattered to the digital-asset sector because it demonstrated both sides of cryptocurrency’s role in ransomware. Bitcoin gave attackers a remotely transferable payment instrument, but transactions recorded on its public ledger also supplied investigators with a trail they said could be followed across addresses and into accounts used by intermediaries.

A hospital report opened the trail

According to the Justice Department, North Korean hackers used previously unidentified ransomware later called Maui to encrypt files and servers at a Kansas medical center in May 2021. The disruption lasted more than a week, after which the provider paid approximately $100,000 in Bitcoin to recover access to its computers and equipment.

The medical center also reported the incident to the FBI. Investigators examined the malware and traced the payment through the Bitcoin blockchain, eventually identifying accounts associated with China-based money launderers that the government said helped the North Korean actors convert ransom proceeds into conventional currency.

In April 2022, the FBI observed another payment—approximately $120,000 in Bitcoin—enter one of the accounts identified through the Kansas investigation. The bureau determined that the transfer came from a Colorado medical provider attacked with the same ransomware. The FBI seized the contents of that account and another associated cryptocurrency account in May.

The approximately $500,000 total exceeded the two specifically described ransom payments. Deputy Attorney General Lisa Monaco said the recovered property included the entire Kansas payment, funds believed to have come from the Colorado provider and cryptocurrency associated with possible additional victims.

Those amounts were government estimates expressed in dollars. The public July 19 records did not disclose the number of bitcoin seized, the exchange-rate source or timestamp used for conversion, every transaction included in the total, or whether all funds retained the same dollar value between payment and seizure.

From tracing to disruption

Monaco presented the operation as evidence that prompt reporting could produce consequences beyond reimbursement for one victim. The Kansas provider’s cooperation helped investigators connect another victim, identify a ransomware strain and develop information used in a joint federal cybersecurity advisory.

That advisory, issued by the FBI, Cybersecurity and Infrastructure Security Agency and Treasury Department on July 6, said North Korean state-sponsored actors had used Maui against healthcare and public-health organizations since at least May 2021. It documented technical characteristics and indicators derived from FBI incident response and industry analysis.

The advisory discouraged ransom payments, noting that payment did not guarantee recovery and could create sanctions risk. That warning did not establish that the Kansas or Colorado providers had violated sanctions rules; the July 19 records described them as victims whose cooperation enabled recovery efforts.

What the disclosure did not establish

The forfeiture complaint concerned property rather than a criminal conviction. On July 19, the FBI investigation remained active, and the public record did not identify the healthcare providers, publish all relevant wallet addresses or establish the identities and locations of every participant.

Nor did the operation show that blockchain tracing makes every cryptocurrency ransom recoverable. Success depended on the victim’s report, investigators linking multiple transfers, and authorities obtaining control over accounts holding the assets. The defensible event-day conclusion was narrower: a reported Bitcoin ransom gave federal investigators a path to another victim and an approximately half-million-dollar seizure, making transaction tracing an operational law-enforcement tool rather than a theoretical capability.

Primary sourceU.S. Justice Department — July 19 announcement of North Korean ransomware cryptocurrency seizure

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.