Select a theme from the list.
Insights

From our experts

Latest
Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development Platform
Security Insight

Ransom Cartel Architect Receives 16-Year Sentence for Global Extortion Campaign

Ransom Cartel Architect Receives 16-Year Sentence for Global Extortion Campaign
Photo by Ann H on Pexels

A US court sentenced Belarusian national Maksim Silnikau to 16 years in prison for creating and administering the Ransom Cartel operation. Prosecutors connected the ransomware service to attacks against at least 18 companies, attempted extortion demands totaling millions of dollars and prolonged disruption at legal and medical technology organizations.

News Date: 2026-08-05

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in a US federal prison. The Belarusian national played a central role in building an organized service that provided affiliates with the access, software and infrastructure needed to attack companies around the world.

Building Ransomware as a Business

According to prosecutors, Silnikau began developing Ransom Cartel in May 2021 and recruited participants through Russian-speaking cybercrime forums. Affiliates received stolen credentials and encryption tools, while a dedicated website allowed members to coordinate intrusions, communicate with victims, negotiate payments and divide the proceeds.

Between 2021 and 2023, the operation attacked at least 18 known companies. The gang stole corporate information before encrypting systems, enabling it to demand money for both decryption and a promise not to publish the stolen data.

Prosecutors said Ransom Cartel attempted to extort at least $5.2 million. Identified victims suffered more than $6.7 million in losses, although the actual total may have been higher because some incidents were not reported. One medical technology company experienced disruption for two months, while attacks on legal organizations interrupted operations for periods ranging from several days to several months.

An International Enforcement Effort

Silnikau was arrested in Spain in July 2023 but fled while awaiting extradition. Authorities later captured him as he attempted to return to Belarus through Poland, after which he consented to extradition to the United States.

The prosecution illustrates how international coordination can eventually reach ransomware operators who believe aliases, cryptocurrency mixers and jurisdictional boundaries will protect them. However, arrests rarely dismantle the wider ecosystem of affiliates, credential brokers and laundering services that support multiple ransomware brands.

Lessons for Business Leaders

  • Maintain tested offline backups that cannot be reached through ordinary administrator accounts.
  • Use multifactor authentication for remote access and privileged operations.
  • Monitor credential marketplaces and promptly disable exposed accounts.
  • Prepare legal, communications and operational response plans before an extortion event occurs.

I believe the sentence is significant because it targets an organizer rather than only a low-level affiliate. Even so, companies should not interpret one conviction as a decline in ransomware risk. The commercial structure that enabled Ransom Cartel remains attractive to other criminals and can quickly reappear under new branding.

Talk to our team →

Latest

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3IDScan Lawsuits Put Mass Identity Collection Under the Microscope4French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning5Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching6Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System