/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

US charges a Ukrainian suspect, arrested in Poland last month, and a Russian citizen over REvil attacks, and says it seized $6M in ransom payments

(CNN)Law enforcement officials have seized an estimated $6 million in ransom payments, and the US Justice Department is expected to announce Monday …

CNN

Context & Ripple Effects

The formal case follows a report that US authorities had seized $6 million and were preparing charges. It also lands after Europol-backed arrests in Ukraine of suspected ransomware operators, tying the REvil matter to a broader cross-border enforcement effort.

The later 13-year-plus sentence and $16 million restitution order for Yaroslav Vasinskyi shows that the REvil investigation progressed from arrests and charges into a completed US prosecution.

First-order effects

  • The US Justice Department brings the Ukrainian suspect arrested in Poland and a Russian citizen into a US criminal case over REvil attacks, while taking $6 million in alleged ransom proceeds out of circulation.
  • The seized funds become subject to the Justice Department’s recovery process rather than remaining available to the alleged operators.

Second-order effects

  • The case adds a US charging-and-asset-seizure track to the European arrests, raising the operational cost for ransomware actors whose alleged activity and custody span multiple countries.
  • For investigators in Poland, Ukraine, and the US, the REvil matter provides a concrete basis for continued cooperation on suspects, evidence, and ransom-payment tracing.

Third-order effects

  • If prosecutions continue to pair arrests with payment seizures and restitution, ransomware enforcement shifts from disrupting individual operators toward constraining the financial returns that sustain their operations.
  • The subsequent REvil sentencing and later multinational ransomware disruptions point to cross-border law-enforcement coordination becoming a repeatable response model rather than a one-off action.

The trend: Ransomware enforcement is increasingly combining multinational arrests with financial recovery to target both operators and the proceeds of attacks.

Discussion

  • @campuscodi Catalin Cimpanu on x
    The US charged a Russian national who breached TSM Consulting in August 2019 and then deployed REvil on the networks of 20+ Texas government agencies He's still at large. FBI wanted poster below. https://therecord.media/... https://twitter.com/...
  • @briankrebs @briankrebs on x
    The DOJ today said 2 men were indicted (1 arrested) for allegedly working as affiliates of the REvil ransomware gang. There's now a $5M-$10M reward for info on REvil affiliates and leaders, and these two guys had zero operational security. Happy hunting! https://krebsonsecurity.c…
  • @fbi @fbi on x
    The @StateDept also announced rewards of up to $10 million for information leading to the identification, arrest, or conviction of leaders of (or participants in) the Sodinokibi/REvil ransomware transnational organized crime group. https://www.state.gov/... https://twitter.com/..…
  • @serghei @serghei on x
    Biden: “When I met with President Putin in June, I made clear that the United States would take action to hold cybercriminals accountable. That's what we have done today.” https://twitter.com/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    The US has charged today MrRabotnik, the Ukrainian hacker who worked as an affiliate for the REvil ransomware gang and orchestrated the ransomware attacks on Kaseya servers over the July 4th weekend He was detained in Poland last month. https://therecord.media/... https://t.co/CS…
  • @fbi @fbi on x
    The #FBI and our partners announced that Yaroslav Vasinskyi, a Ukrainian national, faces charges for allegedly launching ransomware attacks against multiple victims, including a July attack against information technology management company Kaseya. https://www.justice.gov/... http…
  • @thejusticedept Justice Department on x
    Ukrainian Arrested and Charged with Ransomware Attack on Kaseya Justice Department Seizes $6.1 million Related to Alleged Ransomware Extortionists https://www.justice.gov/...
  • @kylegriffin1 Kyle Griffin on x
    The Justice Department is expected to announce that it has charged a suspect from Ukraine over a damaging July ransomware attack on an American company — a breakthrough for the Biden administration's pursuit of cybercriminals. https://www.cnn.com/...
  • @europol @europol on x
    Five affiliates to #Sodinokibi/#REvil were arrested during operation #GoldDust, which involved 17 countries, Europol, @Eurojust & @INTERPOL_HQ. The arrested affiliates are suspected of 7 000 infections, asking for over €200 million in ransom. More ➡️ https://ow.ly/... https://twi…
  • @hackermaderas @hackermaderas on x
    Its good to pay attention to events like these to ascertain the extent of the authority's reach. If Europol can arrest Blackhat's in these nations, they can almost certainly (and probably have) accessed digital resources there (data centers hosting VPNs, Email providers, etc.). h…
  • @campuscodi Catalin Cimpanu on x
    MrRabotnik, aka Yaroslav Vasinskyi, is the “arrest in Europe” mentioned in the Europol press release today. Europol didn't reveal details about this arrest because the US had its own press releases on this case. https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    I love the smell of ransomware getting unplugged in the morning. Five affiliates to Sodinokibi/REvil unplugged | Europol https://www.europol.europa.eu/ ...
  • @c_c_krebs Chris Krebs on x
    Nice work here steadily ramping up pressure on ransomware operators. Evidence that int'lpartnerships can disrupt bad actors. Improve defenses, make it harder to transfer $, and #ImposeCosts. Won't eradicate r'ware, but will limit opportunity. https://europa.eu/!uWWkKf
  • @vickerysec Chris Vickery on x
    Speaking in US Dept of State reward money... that's a potential $35mil - $70mil right there. https://twitter.com/...
  • @fireeye @fireeye on x
    We're proud that our @McAfee_ATR team supported this investigation that has led to multiple arrests. https://www.europol.europa.eu/ ...
  • @dalperovitch Dmitri Alperovitch on x
    Major multinational effort against #REvil underway! https://twitter.com/...
  • @shanvav Shannon Vavra on x
    New: Russian-linked hackers are dropping like flies: Two more hackers linked with REvil ransomware, who have taken half a million euros in ransom payments, have been rounded up, Europol announces just now: https://www.europol.europa.eu/ ...
  • @ericgeller Eric Geller on x
    The crackdown continues. https://twitter.com/...
  • @selenalarson Selena on x
    This is awesome. Though half a million euros is less than some of the individual ransoms paid out to REvil. Hope they keep grabbing the affiliates to eventually take down the operators! https://twitter.com/...