HomeYoutubeRussian basketball player arrested for involvement in ransomware attacks

Russian basketball player arrested for involvement in ransomware attacks

Russian professional basketball player Daniil Kasatkin was arrested on June 21 at Paris' Charles de Gaulle airport on charges of acting as a negotiator for a ransomware gang. The arrest was made at the request of the United States.

Kasatkin previously played in the NCAA with Penn State. He then returned to Russia in 2019 and played for four seasons with MBA-MAI. He was in France for personal reasons with his fiancée when he was arrested on an international warrant. According to US authorities, he allegedly played a role as a negotiator in a ransomware gangthat attacked hundreds of companies and at least two federal agencies between 2020 and 2022.

The case has caused a stir, as the description of the gang refers to the notorious Conti, a Russian-based cyber-extortion group known for its massive ransomware attacks and its connection to older schemes such as Ryuk. Although authorities have not officially named Conti, the details of the attacks and the time period are consistent with the group's activities, which is believed to be responsible for attacks against government and private entities internationally.

See also: Former ransomware negotiator accused of collaborating with hackers

Daniil Kasatkin Russian basketball player ransomware

Kasatkin, however, denies any involvement. His lawyer, Frédéric Bélot, claims that it was a misunderstanding related to the purchase of a second-hand computer, which he says may have been infected with malware by the previous owner. “He bought a second-hand computer. He did absolutely nothing. He is dumbfounded,” Bélot said.

The lawyer also stated that his client has no computer knowledge at all, which makes him incapable of participating in such illegal operations: “He is useless with computers and cannot even install an application. He did not touch anything on the computer: either it had been hacked, or his hacker sold it to him to act under the cover of someone else.”

The Kasatkin case follows other efforts to crack down on cybercrime in Europe. In June, French authorities also arrested four suspects linked to the notorious hacking forum BreachForums, which is a meeting point for data traffickers and cybercriminals, including the notorious IntelBroker and ShinyHunters.

Russian basketball player arrested for involvement in ransomware attacks
Russian basketball player arrested for involvement in ransomware attacks

See also: M&S: Confirms it was targeted by DragonForce ransomware

The increase in such arrests suggests an intensification of international cooperation to combat cybercrime, in a field where the boundaries between the physical and digital worlds are becoming increasingly blurred. The outcome of the Kasatkin case is awaited with particular interest.

If the basketball player is indeed involved in ransomware attacks, then a major problem of the digital age comes to the fore: the involvement of "non-traditional suspects" in cybercrime rings.

The image of a professional athlete shatters the common perception that cybercriminals are exclusively technically skilled hackers who operate exclusively behind keyboards. The reality, as this case shows, is more complicated. Modern ransomware gangs now operate like regular businesses: they have technicians, financial managers, negotiators, and even communications representatives. The role of the “negotiator” – which Kasatkin allegedly played – involves communicating with victims to determine the ransom and payment terms, and does not always require technical knowledge.

See also: Ingram Micro: Restores its systems after ransomware attack

If the charges are true, then this is yet another case of individuals being used as “fronts” or intermediaries to protect the real perpetrators. But if it is a case of mistaken identity – as Kasatkin’s lawyer claims – then it highlights the difficulties of investigating such crimes, where the use of second-hand devices, VPNs, pseudonyms and other concealment techniques makes it extremely difficult to identify the real perpetrators.

Source: www.bleepingcomputer.com

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS