Europol arrests seven people suspected of helping with 7K+ cyberattacks since early 2019 while working with REvil and GandCrab, in a Romanian-led investigation
Europol has announced today the arrests of seven suspects who worked as “affiliates” (partners) for a major ransomware cartel …
Context & Ripple Effects
The Romanian-led case extends a run of Europol ransomware actions: it follows arrests in Ukraine of two alleged gang members and the detention of 12 suspects tied to attacks across 71 countries. The focus here is the affiliate layer associated with REvil and GandCrab, rather than a single malware operation.
That matters because the investigation attributes a large volume of attacks to people working alongside the two ransomware groups, making affiliates a concrete enforcement target in Europol’s cross-border campaign.
First-order effects
- Romanian authorities and Europol have removed seven alleged REvil and GandCrab affiliates from operation through arrest, putting the individuals accused of supporting more than 7,000 attacks into the criminal process.
- REvil and GandCrab’s alleged affiliate network faces immediate disruption where the investigation has identified its participants, rather than only its ransomware brands.
Second-order effects
- Europol and partner authorities gain an enforcement model reinforced by the earlier multi-country detention of 12 ransomware suspects: pursue the people who operationalize attacks alongside the groups they serve.
- Ransomware operators relying on affiliates face greater exposure across national jurisdictions, increasing the value of compartmentalizing roles but also making coordination harder.
Third-order effects
- If repeated across investigations, affiliate arrests shift ransomware enforcement from episodic takedowns of named gangs toward sustained pressure on the service and labor networks that let multiple brands operate.
- The pattern points to cybercrime investigations becoming more dependent on governed cross-border coordination, since the alleged operators, victims, and enforcement partners span different countries.
The trend: Ransomware enforcement is increasingly targeting affiliate networks through coordinated international investigations, not solely the malware groups’ public brands.