Friday, September 11, 2026

Ransomware Gang Member Linked to Russian Cybercrime Group Sentenced to Prison

A Latvian national operating from Moscow has been sentenced to 102 months in federal prison for his role as a key negotiator within a prolific Russian ransomware network.

Deniss Zolotarjovs, 35, participated in a cybercrime syndicate that orchestrated data theft and extortion campaigns against over 54 organizations worldwide between June 2021 and August 2023.

The sentencing highlights a significant victory for international law enforcement in dismantling the operational hierarchy of Eastern European cybercrime groups.

Zolotarjovs acted as the primary pressure point for victims who initially refused to pay ransom demands. His role required analyzing stolen data to find maximum leverage against target organizations.

He operated within a syndicate led by former Conti members, using a variety of prominent ransomware groups to disguise their activities. Law enforcement identified multiple ransomware strains deployed by his group, including Akira, Royal, Karakurt, TommyLeaks, and SchoolBoys Ransomware.

Rather than simply encrypting networks, Zolotarjov specialized in weaponizing highly sensitive information. In one incident involving a pediatric healthcare provider, he actively leveraged children’s medical records to force payment.

When the organization refused to comply, Zolotarjovs distributed a mass archive of sensitive health data to hundreds of patients simultaneously, demonstrating a ruthless approach to psychological manipulation.

The financial devastation caused by the ransomware syndicate exceeds hundreds of millions of dollars. Detailed statements from just 13 known victim companies revealed total losses of over $56 million, including approximately $2.8 million in direct ransom payments.

An additional 41 victims paid roughly $13 million during the same operational period. However, the full extent of the financial damage remains difficult to calculate due to widespread industry underreporting.

The attacks resulted in severe infrastructure disruption alongside mass data exposure. The compromised information included Social Security numbers, dates of birth, and critical healthcare records.

Furthermore, the syndicate’s operations successfully disrupted a government entity’s 911 emergency response system, placing public safety at risk.

The cybercrime organization operated with corporate-level sophistication from an office building in St. Petersburg, Russia.

The group utilised a hierarchical management structure and obfuscated their money laundering operations through a complex network of shell companies registered across Europe, Russia, and the United States.

The syndicate heavily relied on systemic corruption to maintain its operations and protect its members. The organization recruited former Russian law enforcement officers, enabling it to co-opt government databases to intimidate detractors and vet recruits.

Syndicate leaders also routinely evaded taxes and paid bribes to exempt their draft-age members from compulsory Russian military service.

The successful prosecution required extensive international collaboration led by the FBI’s Cincinnati Field Office. Working with international partners and the Government of Georgia, authorities secured Zolotarjov’s initial arrest in December 2023.

After contesting his extradition, he was transferred to United States custody in August 2024 and subsequently pleaded guilty to money laundering and wire fraud conspiracy in July 2025.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News