Romanian law enforcement authorities have arrested a ransomware affiliate suspected of hacking and stealing sensitive information from the networks of several high-profile companies worldwide, including a major Romanian IT company with clients in the retail, energy, and utilities sectors.
See also: Ransomware hacker arrested for healthcare attacks

The 41-year-old Romanian national was arrested on Monday morning at his home in Craiova, Romania, by DIICOT (Romanian Directorate for the Investigation of Organized Crime and Terrorism) and judicial police officers, on suspicion of unauthorized access to a computer system without a license, transfer of computer data, illegal interception of computer transmissions and extortion.
The affiliate ransomware stole a wide range of sensitive information from the systems it targeted, according to the Romanian National Police, including companies' financial information, employees' personal data, and customer details.
See also: New Cerber ransomware targets Confluence and GitLab servers
DIICOT conducted the investigation within the framework of the European Multidisciplinary Platform Against Criminal Threats (EMPACT) with the assistance of the FBI and Europol's EC3.
It is currently unknown which ransomware gang the suspect was working with, the only detail is that the hacker was targeting high-profile companies.

This is consistent with previous arrests made by Romanian law enforcement last month, on November 8, when they arrested two suspects believed to be Sodinokibi/REvil. On the same day, Kuwaiti authorities also arrested a GandGrab ransomware affiliate.
"All these arrests follow joint international law enforcement efforts to identify, intercept and seize certain infrastructures used by the Sodinokibi/REvil ransomware family, which is considered the successor to GandCrab," Europol said.
U.S. Deputy Attorney General Lisa Monaco also said in November that the U.S. would combat ransomware activity in an interview with the Associated Press.
See also: Emotet installs Cobalt Strike on devices allowing for faster ransomware infection
While key ransomware gang operators are still safe in Russia, these recent arrests show that law enforcement worldwide is now disrupting their Ransomware-as-a-Service (RaaS) operations by arresting associates located around the world.
Information source: bleepingcomputer.com
