Federal judge sentences a Russian citizen, extradited to the US in March 2019, to five years in prison for stealing $1.5M in targeted hacks of US tax preparers
Context & Ripple Effects
This sentencing closes the case the Justice Department opened two years ago when it charged the same Russian citizen after his arrest in Thailand and extradition to the US in March 2019 — a five-year term for $1.5M stolen in targeted intrusions of US tax preparers.
It lands on an established pattern in US cybercrime prosecutions of Russian nationals: Roman Seleznev's 27-year sentence for selling 2M+ stolen credit cards set the record, while the Citadel malware developer drew a comparable five-year term after infecting ~11M computers, making extradition-and-sentencing the consistent endgame rather than the exception.
First-order effects
- The defendant, arrested in Thailand and held in US custody since the March 2019 extradition, now serves a fixed federal prison term — converting a DOJ prosecution into completed punishment.
Second-order effects
- For other Russian hackers operating abroad, the Thailand-to-US extradition route remains demonstrably open, reinforcing that third-country arrests are the practical enforcement mechanism since direct apprehension in Russia is unavailable.
Third-order effects
- If the Seleznev-to-Citadel-to-tax-preparer sequence holds as the template, US cybercrime sentencing will keep functioning as a deterrent signal aimed at actors who assume geographic distance insulates them, even as sentences vary widely with the scale of losses.
The trend: US prosecution of Russian cybercriminals increasingly runs through third-country extraditions, with multiyear federal sentences becoming the standard endpoint.