HomeinetLatvian hacker convicted for participating in Ransomware campaign

Latvian hacker convicted for participating in Ransomware campaign

A Latvian hacker, Denis Zolotarjovs, has been sentenced to 102 months in prison for his role in a Russia-linked ransomware campaign responsible for targeting more than 54 companies worldwide. The conviction marks a significant development in ongoing efforts to dismantle international ransomware networks.

See also: Finland: Arrest of teenager alleged to be a hacker of the Scattered Spider group

Latvian hacker convicted for participating in Ransomware campaign

According to the U.S. Department of Justice, Zolotarzovs played a central role in the extortion operations that took place between June 2021 and August 2023. The group operated under multiple ransomware brands, including Conti, Karakurt, Royal, TommyLeaks, SchoolBoys Ransomware , and Akira, reflecting a complex and evolving cybercrime structure.

Officials said Zolotarzovs was primarily responsible for increasing pressure on victims who were hesitant to pay the ransom demands. He analyzed the stolen data and used sensitive information to intensify the extortion tactics.

In one case involving a pediatric healthcare provider, Zolotarjovs used children’s health information to pressure the organization into paying. When the ransom demand was not met, he allegedly encouraged his accomplices to leak or sell the data. Court documents reveal that he distributed a large set of sensitive records to hundreds of patients, aiming to instill fear and force compliance.

Assistant Attorney General A. Tysen Duva described Zolotarjovs as a “cruel, ruthless and dangerous international cybercriminal,” noting that his actions included exploiting highly personal data to increase pressure on victims.

The ransomware organization's activities have caused widespread damage. Of the more than 54 companies targeted, attacks on 13 caused damages exceeding $56 million, including approximately $2.8 million paid in ransom. It is believed that an additional 41 companies paid approximately $13 million, although detailed damage figures are still being compiled.

See also: WordPress: Hackers exploit vulnerability in Breeze Cache plugin

Latvian hacker convicted for participating in Ransomware campaign

Authorities estimate that the total economic impact could reach hundreds of millions of dollars when the cases listed below are taken into account. Beyond the financial losses, the attacks resulted in the exposure of highly sensitive data, including Social Security numbers, addresses, dates of birth, and healthcare records.

In one case, a government entity's 911 emergency system was forced to go offline, raising serious concerns about public safety and the broader implications of ransomware attacks.

Researchers found that the ransomware organization operated with a structured hierarchy and used a network of companies in Russia, Europe , and the United States to cover its activities. The members were primarily from Russia and reportedly operated from an office in St. Petersburg.

The group's operations also involved corruption and misuse of public funds. Authorities said some members had ties to former Russian law enforcement officials, allowing them to access databases, intimidate individuals, and identify potential recruits. These connections also allowed members to evade scrutiny, including by evading taxes and avoiding military service through bribery.

Arrest, Extradition and Prosecution

Zolotarjovs was arrested in Georgia in December 2023 and later extradited to the United States in August 2024 after challenging the process. In July 2025, he pleaded guilty to conspiracy charges involving money laundering and wire fraud.

The case was investigated by the Federal Bureau of Investigation, with support from multiple field offices and international partners. Special Agent Jason Cromartie said the case reflects the agency's ongoing efforts to identify cybercriminals operating across borders.

See also: UK: Chinese hackers use proxy networks to avoid detection

ransomware

U.S. Attorney Dominick S. Gerace II added that the prosecution shows that cybercriminals cannot rely on geography or anonymity to evade justice.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS