A 26-year-old Russian citizen, Aleksei Olegovich Volkov, has been sentenced by a US court to 6.75 years in prison for his role as an initial access broker in supporting large cybercrime groups, including the Yanluowang ransomware crew. According to the US Department of Justice, Volkov facilitated dozens of ransomware attacks on US companies, causing more than $9 million (with projected losses exceeding $24 million). The case is one of the most significant blows to US authorities against international cybercrime and highlights the critical role of initial access brokers in the modern cyberthreat landscape.

Volkov acted as an initial access broker (IAB) for the Yanluowang ransomware group and other gangs. His work involved hacking into corporate networks and selling access to other criminal groups. In return , he would typically receive a percentage of the ransom the ransomware gang demanded from the victim.
See also: Hacker sends mass extortion emails from HungerRush to restaurant customers
The IAB has evolved into one of the most profitable and dangerous activities in the world of cybercrime, as it allows for the escalation of attacks through the commercialization of access to corporate networks.
Technical Details and Methods of Volkov
Volkov exploited system vulnerabilities to gain initial access to computer networks or used stolen employee credentials . His associates then used the access Volkov provided to infect affected networks with malware . This malware encrypted victims’ data and prevented them from accessing it, disrupting their business operations. The process also involved extensive network reconnaissance, stealing sensitive data before encryption, and strategically placing the ransomware for maximum impact.

The criminals then demanded that victims pay a ransom in cryptocurrency – sometimes tens of millions of dollars – in exchange for restoring access to the data and not making the stolen data public. Each time a victim paid the ransom, Volkov would receive a cut of the illicit proceeds.
See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit
The tactic of double blackmail – encryption and threat of data release – has become the dominant model in modern ransomware attacks, significantly increasing the pressure on victims to comply with criminals' demands.
Arrests and Legal Consequences
Volkov was arrested in Italy on January 18, 2024 , and extradited to the United States to face charges. He pleaded guilty in October 2025 to charges including conspiracy to commit computer fraud , access fraud, and money laundering. The digital investigation demonstrates how difficult it is for cybercriminals to remain anonymous in the modern era.

Protection Measures and Security Recommendations
To protect against IAB and ransomware attacks , organizations must implement multi-layered security strategies. Promptly installing security updates and enforcing multi-factor authentication (MFA) are key measures to block access through stolen credentials. Additionally, continuous monitoring for anomalous logins, unusual credentials, and data extraction can detect IAB activity before it escalates into full-blown ransomware attacks. Network segmentation , offline backups , and staff training to combat phishing and social engineering are also critical components of a comprehensive cybersecurity strategy.
See also: LeakNet Ransomware group uses ClickFix techniques
As part of the guilty plea, the defendant agreed to pay restitution to the victims (at least $9,167,198), along with the confiscation of the tools used to commit the crimes.
The revelation comes as US prosecutors have charged a third person, Angelo Martino, for his role as a negotiator for the BlackCat (ALPHV) ransomware, according to The Hacker News.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
