Europol has arrested seven people suspected of helping REvil and GandCrab with over 7,000 cyberattacks since early 2019, in a Romanian-led investigation
The Romanian-led case follows a month of escalating Europol activity against ransomware networks: authorities had already arrested two alleged ransomware members in Ukraine and then detained 12 suspects tied to attacks on more than 1,800 victims across 71 countries. The new arrests widen that enforcement focus from suspected core operators to people accused of supporting REvil and GandCrab.
The alleged 7,000-plus attacks make the case notable as an attempt to disrupt the service and support layer behind repeat ransomware campaigns, not solely identify a single intrusion crew.
First-order effects
Seven suspects now face a Romanian-led investigation over alleged assistance to REvil and GandCrab, potentially removing personnel connected to the groups' attack operations.
Europol and its partners add an alleged support network to the set of ransomware suspects they have detained, following the 12-suspect ransomware operation announced days earlier.
Second-order effects
Ransomware groups relying on intermediaries for access, deployment, or other operational support face greater exposure when cross-border investigations target collaborators alongside alleged gang members.
The sequence of arrests increases pressure on law-enforcement partners to connect separate victim cases and attribute recurring attacks to shared networks rather than treat them as isolated incidents.
Third-order effects
The cases point toward ransomware enforcement centered on network disruption: pursuing operators, affiliates, and facilitators across jurisdictions rather than expecting a single arrest to end a campaign.
If this pattern persists, the practical advantage shifts toward investigations that can combine victim reporting and international coordination to map the broader criminal infrastructure.
The trend: European ransomware enforcement is moving toward coordinated disruption of the broader networks that enable repeat attacks across borders.
Five affiliates to #Sodinokibi/#REvil were arrested during operation #GoldDust, which involved 17 countries, Europol, @Eurojust & @INTERPOL_HQ. The arrested affiliates are suspected of 7 000 infections, asking for over €200 million in ransom. More ➡️ https://ow.ly/... https://twi…
Its good to pay attention to events like these to ascertain the extent of the authority's reach. If Europol can arrest Blackhat's in these nations, they can almost certainly (and probably have) accessed digital resources there (data centers hosting VPNs, Email providers, etc.). h…
MrRabotnik, aka Yaroslav Vasinskyi, is the “arrest in Europe” mentioned in the Europol press release today. Europol didn't reveal details about this arrest because the US had its own press releases on this case. https://twitter.com/...
I love the smell of ransomware getting unplugged in the morning. Five affiliates to Sodinokibi/REvil unplugged | Europol https://www.europol.europa.eu/ ...
Nice work here steadily ramping up pressure on ransomware operators. Evidence that int'lpartnerships can disrupt bad actors. Improve defenses, make it harder to transfer $, and #ImposeCosts. Won't eradicate r'ware, but will limit opportunity. https://europa.eu/!uWWkKf
New: Russian-linked hackers are dropping like flies: Two more hackers linked with REvil ransomware, who have taken half a million euros in ransom payments, have been rounded up, Europol announces just now: https://www.europol.europa.eu/ ...
This is awesome. Though half a million euros is less than some of the individual ransoms paid out to REvil. Hope they keep grabbing the affiliates to eventually take down the operators! https://twitter.com/...