Sixteen years in prison: that is the sentence handed down to Maksim Silnikau, the Belarusian national the U.S. Department of Justice says created and administered the Ransom Cartel ransomware operation that hit at least 18 companies around the world.
The conviction and charges
The U.S. Department of Justice announced that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft. Federal prosecutors said the Ransom Cartel operation attempted to extort at least $5.2 million from victims; the United States identified more than $6.7 million in losses suffered by 18 known victims, while prosecutors noted the total likely exceeded that because some victims had not reported attacks.
How Ransom Cartel was built and run
According to court documents cited by prosecutors, Silnikau began developing Ransom Cartel in May 2021 and launched it publicly in December 2021. He recruited affiliates through underground, Russian‑language cybercrime forums and supplied them with tools and stolen credentials used to intrude into corporate networks. Silnikau also ran an affiliate website that let members manage attacks, communicate, negotiate ransom demands, and divide revenue shares after payments were made.
Prosecutors described Silnikau as holding a central role in the ransomware‑as‑a‑service operation: recruiting affiliates, coordinating with initial access brokers who supplied network access, communicating with victims, and handling ransom payments. He transmitted ransom proceeds through cryptocurrency mixers, according to prosecutors, to make tracing the funds more difficult.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechnical traces and links to other ransomware
When Ransom Cartel emerged publicly in December 2021, researchers noticed code similarities with the REvil encryptor. Prosecutors reported that Ransom Cartel's encryptor lacked some of REvil’s obfuscation features, leading researchers to conclude it may have been created by a former core member of REvil who did not have access to the complete source code. The operation’s code choices and infrastructure reflected the syndicate model: a central developer providing an encryptor and management portal while affiliates carried out intrusions and extortion.
Notable victims, disruptions, and financial impact
Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide, including organizations in California, New York, and Nebraska as well as victims outside the United States. In August 2022, the cartel reportedly disrupted operations at a medical technology startup developing robotic surgical technology for two months. In May 2023, the gang targeted infrastructure used by a group of law firms; one law firm paid a $125,000 ransom after being disrupted for nearly a month, while another suspended operations for almost a month before paying $300,000. Prosecutors said the combined losses associated with those law‑firm and healthcare attacks reached approximately $2.2 million.
Arrest, flight, and extradition
Prosecutors recount an international enforcement sequence. Silnikau was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation. He fled while awaiting extradition and was later apprehended while trying to cross from Poland to his native Belarus — "The defendant fled Spanish authorities while awaiting extradition to the United States and was apprehended while trying to cross from Poland to his native Belarus," prosecutors wrote in their sentencing filing. He ultimately consented to extradition and was sent from Poland to the United States to face prosecution in the Eastern District of Virginia.
How technologists, policymakers, and affected companies are likely to respond
- Technologists and security teams will note the described business model: a central developer providing encryptor code and an affiliate portal, plus the use of initial access brokers and cryptocurrency mixers — factors that emphasize the technical and operational chains behind these attacks.
- Policymakers and law enforcement will point to the extradition and multinational cooperation that led to prosecution, as prosecutors have tied the sequence of arrests and transfers to the eventual conviction in the Eastern District of Virginia.
- Affected enterprises and law firms will be reminded of the concrete costs traced to individual incidents: multi‑week operational disruptions, negotiated ransom payments of $125,000 and $300,000 in the examples prosecutors cited, and the roughly $2.2 million in combined losses from those attacks.
Silnikau’s conviction ties a human face and a quantifiable financial toll to a ransomware operation that ran for roughly two years. It leaves open a question the facts in the prosecution underscore: how many additional victims — beyond the 18 identified and the $6.7 million in reported losses — remain uncounted because they did not report attacks, and how the networks that supplied access and laundried ransom payments will be further disrupted.
Source: BleepingComputer — Ransom Cartel ransomware creator sentenced to 16 years in prison




