US investigators traced ransomware payments back to companies in Moscow skyscraper Federation Tower East, suggesting Russia tolerates ransomware operators
Cybersecurity experts tracing money paid by American businesses to Russian ransomware gangs found it led to one of Moscow's most prestigious addresses. Tweets: @hatr , @adam_k_levin , @ericgarland , @ddd1ms , and @stick631 Tweets: Hakan / @hatr : “American cryptocurrency tracking services provide data to non-Russian exchanges to help them avoid illicit transactions but have refused to work with Russian traders” out of fear they might use the information to tip off criminals https://www.nytimes.com/... Adam Levin / @adam_k_levin : This is unsurprising, given Russia's hands-off policy toward international cybercrime. https://www.nytimes.com/... Eric Garland / @ericgarland : U.S. intelligence narrows down those attacks on our hospitals and critical infrastructure to - HOLD ONTO YER BUTTS!!! - the Russians. With the de facto blessings of Putin. https://www.nytimes.com/... @ddd1ms : Like the banks and insurance companies they share space with, those firms are likely to have chosen the site for its status and its stringent building security, said Mr. Smilyanets, the researcher at @RecordedFuture https://www.nytimes.com/... Scott Stewart / @stick631 : That this high-rise in Moscow's financial district has emerged as an apparent hub of such money laundering has convinced many security experts that the Russian authorities tolerate ransomware operators. https://www.nytimes.com/... Expand More For Next Unexpand More For Next
Context & Ripple Effects
The earlier cross-sector ransomware task force had already framed the problem as one requiring coordinated U.S. and allied action, while attacks on managed service providers showed how a single intrusion could disrupt many smaller organizations. Payment tracing adds a concrete financial and geographic lead to that broader response.
The reporting links extortion proceeds from American victims to businesses at a prominent Moscow address, sharpening the distinction between technically identifying ransomware infrastructure and holding the jurisdiction around it accountable.
First-order effects
- U.S. investigators gain a specific commercial location around which to focus financial intelligence and potential attribution work on ransomware proceeds.
- The Russian authorities face a more concrete allegation that operators can function with official tolerance, based on the traced payment flows.
Second-order effects
- U.S. policy makers have stronger grounds to combine financial tracing with the charges, sanctions, and reward-based pressure later used against a Russian ransomware suspect.
- Cryptocurrency intermediaries handling cross-border flows face greater scrutiny as investigators treat payment routes as operational infrastructure, not merely a record of victim losses.
Third-order effects
- If payment-trail attribution becomes repeatable, ransomware enforcement will increasingly target the ecosystems that convert and shelter extortion proceeds, alongside the individual hackers who deploy malware.
- The episode points to a durable conflict in which internationally exposed financial rails create leverage against ransomware groups operating from jurisdictions accused of tolerating them.
The trend: Ransomware response is shifting from victim-by-victim incident handling toward financial attribution and cross-border pressure on the ecosystems behind attacks.