Short version (because you’ll skim anyway)
Maksim Silnikau — a 40-year-old from Belarus who ran the Ransom Cartel ransomware operation — was handed a federal sentence of 16 years after U.S. prosecutors tied him to attacks on at least 18 companies around the world. The charges included conspiracy, wire fraud, and aggravated identity theft. He built the service, recruited partners, and handled ransom dealings like a sketchy freelance event planner for cybercrime.
How the scheme worked and why it mattered
Silnikau had been lurking on Russian-speaking cybercrime forums for years and used several aliases. He launched the Ransom Cartel effort in 2021, set up an affiliate portal for co-conspirators to manage break-ins, negotiate ransoms, and split proceeds, and provided stolen credentials and encryption tools to his network.
The operation hit organizations across the U.S. and abroad between 2021 and 2023. Victims had their data stolen, systems encrypted, and were pressured to pay for decryption tools or silence. Prosecutors say the gang tried to extort at least $5.2 million, and investigators tied about $6.7 million in documented losses to 18 known victims — with the real total probably higher because not every victim reports these incidents.
- Major disruptions included a medical technology startup crippled for roughly two months and several law firms that were knocked offline for days to months.
- Some victims paid: one law firm paid $125,000 after nearly a month of disruption; another paid $300,000 after a prolonged outage. Combined losses for a handful of high-impact attacks were estimated near $2.2 million.
- Technically, Ransom Cartel shared some code similarities with a notorious encryptor, but it lacked some advanced obfuscation—suggesting it might have been created by an ex-member rather than the original core team.
Silnikau didn’t just write malware — he coordinated. He worked with initial access brokers who sold corporate network access, communicated with victims, moved ransom funds through cryptocurrency mixing services to mask the trail, and generally ran the whole ransomware-as-a-service circus.
He was arrested in Spain in mid-2023 during an international law enforcement operation, briefly fled while awaiting extradition, and was later captured trying to cross into his home country. Eventually he was extradited to the United States to face charges in Virginia.
Bottom line: the operator who built and ran the Ransom Cartel network is off the internet for a long stretch, and the case is another reminder that the people behind these attacks can be tracked, arrested, and prosecuted — despite their best efforts to hide behind aliases and crypto.