“Silnikau and his co-conspirators attempted to extort at least $5.2 million from victims during the multi-year scheme.”
A conviction capped a multi-year scheme
A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain tied to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday. The defendant, identified in court records as a 40-year-old Belarusian national, pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft.
Timeline: forums, recruitment, flight, arrest and extradition
According to officials, the man was active on Russian-speaking cybercrime forums since at least 2005 and was a member of the cybercrime site Direct Connection from 2011 to 2016. He created Ransom Cartel and began recruiting participants from cybercrime forums in 2021. While awaiting extradition from Spain, he fled and was later arrested in Poland in July 2023 as he tried to return to Belarus; he was extradited to the United States in August 2023. Authorities say Ransom Cartel’s operations ended when he was arrested.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTools, functions and aliases
Prosecutors describe the defendant as more than an administrator who collected payments. He provided co-conspirators with stolen credentials and mechanisms to encrypt compromised computers, built a site to monitor and control ongoing attacks, and used that platform to communicate with co-conspirators and victims, negotiate payment demands, and manage distribution of funds between co-conspirators. Court records identify him by the online aliases “J.P. Morgan,” “xxx,” and “lansky.”
Victim profile and operational impact
The Justice Department linked Ransom Cartel to attacks on at least 18 companies between 2021 and 2023. Victims included a group of law firms, several medium-sized businesses, a small medical technology startup, educational institutions and large multinational corporations based in California, New York, Nebraska and elsewhere. Officials said some victims’ operations were disrupted for several months during the campaign.
What this means for technologists, affected enterprises, and law enforcement
- Technologists and security teams should note that the accused provided stolen credentials and encryption mechanisms to others, and operated a dedicated control site — concrete capabilities that complicate incident response and attribution.
- Affected enterprises, including law firms, a medical technology startup, and educational institutions, face documented operational disruption — some for several months — and can expect that ransom-focused groups may combine commoditized tools with centralized coordination.
- Law enforcement and prosecutors demonstrated cross-border cooperation: the case involved forum activity dating back to 2005, flight from Spain, an arrest in Poland in July 2023, extradition to the United States in August 2023, and a subsequent guilty plea and sentence that officials say ended Ransom Cartel’s operations.
The sentencing closes one chapter: authorities said the group never grew large enough to inflict losses comparable to larger ransomware variants, but the record shows a multi-year, forum-driven operation that successfully targeted a range of organizations and attempted to extract millions of dollars. The case underscores how an individual operator can scale harm by supplying both tools and centralized management, and it leaves open what becomes of co-conspirators and the infrastructure once the principal actor is removed.




