Rostislav Panev, a 51-year-old Russian-Israeli national, was extradited from Israel to the United States as a key ransomware LockBit.

According to the Department of Justice , Panev was arrested in Israel in December 2024, and is one of the hackers to have been arrested so far for their role in LockBit. Since then, Panev has been awaiting extradition to the US.
Prosecutors allege that Panev was a programmer who worked for the LockBit ransomware group from 2019 until at least February 2024. Panev and other programmers designed the malware, maintained its infrastructure, and shared the tool and illicit proceeds with affiliates of the gang.
See also: Decrypt Linux/ESXi Akira Ransomware files without paying ransom
"If you are a member of the LockBit ransomware conspiracy, the United States will find you and bring you to justice," said U.S. Attorney John Giordano.
LockBit emerged in September 2019 and has since been linked to numerous attacks worldwide. Some of the most notable targets included Bank of America, Boeing, Continental, the Italian Inland Revenue Service, and the UK Royal Mail.
In February 2024, an international law enforcement operation (Operation Cronos) shut down LockBit's infrastructure and seized 34 servers with over 2,500 decryption keys. These were used to create a free decryption tool for the LockBit 3.0 Black Ransomware. However, the attacks continue.

The US Department of Justice and the UK NCA estimate that the gang has demanded up to $1 billion from victims, across 7,000 attacks between June 2022 and February 2024.
See also: New SuperBlack ransomware exploits Fortinet vulnerabilities
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
See also: Medusa ransomware: Has targeted over 300 organizations in critical infrastructure

Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software to ensure it is equipped to handle new threats.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.
Source: techcrunch.com
