HomeSecurityRussian hacker jailed for involvement in ransomware attacks

Russian hacker imprisoned for involvement in ransomware attacks

A 26-year-old Russian citizen, Aleksei Olegovich Volkov, has been sentenced by a US court to 6.75 years in prison for his role as an initial access broker in supporting large cybercrime groups, including the Yanluowang ransomware crew. According to the US Department of Justice, Volkov facilitated dozens of ransomware attacks on US companies, causing more than $9 million (with projected losses exceeding $24 million). The case is one of the most significant blows to US authorities against international cybercrime and highlights the critical role of initial access brokers in the modern cyberthreat landscape.

Russian hacker imprisoned for involvement in ransomware attacks

Volkov acted as an initial access broker (IAB) for the Yanluowang ransomware group and other gangs. His work involved hacking into corporate networks and selling access to other criminal groups. In return , he would typically receive a percentage of the ransom the ransomware gang demanded from the victim.

See also: Hacker sends mass extortion emails from HungerRush to restaurant customers

The IAB has evolved into one of the most profitable and dangerous activities in the world of cybercrime, as it allows for the escalation of attacks through the commercialization of access to corporate networks.

Technical Details and Methods of Volkov

Volkov exploited system vulnerabilities to gain initial access to computer networks or used stolen employee credentials . His associates then used the access Volkov provided to infect affected networks with malware . This malware encrypted victims’ data and prevented them from accessing it, disrupting their business operations. The process also involved extensive network reconnaissance, stealing sensitive data before encryption, and strategically placing the ransomware for maximum impact.

Aleksei Volkov Russian hacker conviction ransomware attacks

The criminals then demanded that victims pay a ransom in cryptocurrency – sometimes tens of millions of dollars – in exchange for restoring access to the data and not making the stolen data public. Each time a victim paid the ransom, Volkov would receive a cut of the illicit proceeds.

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

The tactic of double blackmail – encryption and threat of data release – has become the dominant model in modern ransomware attacks, significantly increasing the pressure on victims to comply with criminals' demands.

Arrests and Legal Consequences

Volkov was arrested in Italy on January 18, 2024 , and extradited to the United States to face charges. He pleaded guilty in October 2025 to charges including conspiracy to commit computer fraud , access fraud, and money laundering. The digital investigation demonstrates how difficult it is for cybercriminals to remain anonymous in the modern era.

Aleksei Volkov Russian hacker conviction ransomware attacks

Protection Measures and Security Recommendations

To protect against IAB and ransomware attacks , organizations must implement multi-layered security strategies. Promptly installing security updates and enforcing multi-factor authentication (MFA) are key measures to block access through stolen credentials. Additionally, continuous monitoring for anomalous logins, unusual credentials, and data extraction can detect IAB activity before it escalates into full-blown ransomware attacks. Network segmentation , offline backups , and staff training to combat phishing and social engineering are also critical components of a comprehensive cybersecurity strategy.

See also: LeakNet Ransomware group uses ClickFix techniques

As part of the guilty plea, the defendant agreed to pay restitution to the victims (at least $9,167,198), along with the confiscation of the tools used to commit the crimes.

The revelation comes as US prosecutors have charged a third person, Angelo Martino, for his role as a negotiator for the BlackCat (ALPHV) ransomware, according to The Hacker News.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS