The US announces charges, sanctions, and a $10M reward for info leading to the arrest of Russian national Mikhail Matveev, a Babuk ransomware campaign suspect
SPECIALLY DESIGNATED NATIONALS LIST UPDATE Sarai Rodriguez / HealthITSecurity : US Formally Charges Russian Hacker Behind Global Ransomware Attacks CircleID : U.S. Targets Russian Mastermind Behind Dominant Ransomware Landscape, Offers $10 Million Reward Gareth Corfield / Telegraph : Nine-fingered Russian hacker accused of Royal Mail attack hit with $10m bounty Krebs on Security : Russian Hacker “Wazawaka” Indicted for Ransomware William Turton / Bloomberg : Alleged Russian Hacker Charged in $200 Million Ransomware Spree Benjamin Freed / StateScoop : Russian man charged over ransomware attacks, including against D.C. police Eduard Kovacs / SecurityWeek : US Offering $10M Reward For Russian Man Charged With Ransomware Attacks Derek B. Johnson / SC Media : US CHARGES, SANCTIONS RUSSIAN RANSOMWARE OPERATOR WHO LEAKED STOLEN DC POLICE DATA Paul Hill / Neowin : US puts $10 million bounty on Russian hacker's head David Perera / HealthcareInfoSecurity.com : Alleged Babuk Ransomware Hacker ‘Wazawaka’ Indicted in US Joe Warminsky / The Record : Alleged Babuk ransomware gang leader ‘Wazawaka’ indicted, sanctioned by US Carly Page / TechCrunch : US sanctions Russian accused of being a ‘central figure’ in major ransomware attacks Mastodon: BrianKrebs / @briankrebs@infosec.exchange : BTW, here's the DOJ presser on Matveev today, who was indicted in two different jurisdictions for ransomware attacks on govt agencies, schools, and hospitals. — https://www.justice.gov/... … Tweets: Sean Lyngaas / @snlyngaas : “Asked for comment by CNN on Twitter, Matveev replied with a video with a Russian man repeating the phrase, 'I don't give a f*** at all.'” https://www.cnn.com/... @fbi : Prolific cyber criminal and Russian national Mikhail Matveev has been indicted on charges related to the alleged deployment of ransomware on thousands of victims around the world. Read more here: https://www.justice.gov/... #CyberIsATeamSport Wendy Siegelman / @wendysiegelman : Russian National Charged with Ransomware Attacks Against Critical Infrastructure Ransomware attacks were against law enforcement agencies in DC and NJ and other victims worldwide State Department is offering a reward of up to $10M https://www.justice.gov/... Aaron Schaffer / @aaronjschaffer : NEW: US government sanctions Mikhail Pavlovich Matveev, who @briankrebs identified as being network access broker Wazawaka last year https://ofac.treasury.gov/... https://krebsonsecurity.com/ ... @washingtonpost : U.S. authorities announced criminal charges, economic sanctions and a $10 million reward for information leading to the arrest of a Russian man accused of participating in a global ransomware campaign, whose victims included the D.C. police department. https://www.washingtonpost.com/ ...
Context & Ripple Effects
The case extends a U.S. and UK campaign pairing criminal charges with sanctions against Russia-based ransomware figures, following earlier sanctions tied to Conti, Ryuk, and Trickbot operators. It also sits against reporting that investigators had traced ransomware-payment activity to Moscow-based companies, sharpening the focus on the ecosystem around operators rather than malware alone.
The later reported arrest of Matveev in Russia makes this 2023 action a useful marker of the long interval between public attribution and any potential custody. Allied authorities subsequently used a similar charges-and-sanctions approach against LockBit's alleged leader.
First-order effects
- Matveev faces U.S. criminal charges, economic sanctions, and a reward of up to $10 million for information leading to his arrest; the measures raise the legal and financial risk of assisting him.
- The action publicly identifies an alleged participant in the Babuk campaign, giving victims, investigators, and financial intermediaries a named target for reporting and compliance screening.
Second-order effects
- Sanctions can complicate an operator's access to funds and services, while the reward creates a financial incentive for intelligence that could help law enforcement locate him or map collaborators.
- The package reinforces a playbook later applied in the US-UK action against LockBit's alleged leader, increasing pressure on ransomware groups' operators and their support networks rather than only on their infrastructure.
Third-order effects
- If sustained across jurisdictions, the combination of indictments, sanctions, and rewards shifts ransomware enforcement toward making operator networks harder to finance, shelter, and reuse across successive brands.
- Its deterrent value still depends on arrests or meaningful cooperation from the jurisdictions where suspects reside; the later report of Matveev's arrest suggests that public attribution can retain leverage over time.
The trend: Ransomware enforcement is evolving from incident-by-incident disruption toward coordinated financial, legal, and intelligence pressure on named operators and their networks.