A court in the United States has sentenced the man accused of building and running the Ransom Cartel ransomware group. The judge gave him 16 years in prison. Prosecutors said his group attacked at least 18 companies around the world.
According to the U.S. Department of Justice (DOJ), the man is 40-year-old Maksim Silnikau from Belarus. A court found him guilty of teaming up to break U.S. law, teaming up to commit wire fraud, and stealing people’s identities in a serious way.
Reports say Silnikau had been active on Russian-language hacker forums since 2005. He went by online names like “J.P. Morgan,” “xxx,” and “lansky.” He also belonged to a hacker forum called Direct Connection from 2011 to 2016. That site shut down after police arrested the person who ran it.
How the scheme worked
Court papers say Silnikau started building the Ransom Cartel in May 2021. He then found other hackers on underground forums and brought them into his group.
He reportedly gave his team the tools they needed to break into company networks. This included stolen usernames and passwords, plus software that locked up victims’ computers.
Silnikau also ran a hidden website for his group, according to the DOJ. Members used it to talk to each other, set ransom prices, track their attacks, and split the money after victims paid up.
Prosecutors said Silnikau played a leading role in the whole scheme. He brought in new members, worked with people who sold stolen network access, and dealt directly with victims. He also handled the ransom payments himself.
He allegedly sent stolen funds through crypto mixing services. These services scramble transactions to make money harder to trace.
Ransom Cartel became active in December 2021, based on the reports. Researchers had noticed it looked similar to another ransomware called REvil. But some parts of the code seemed to be missing. That made them think the builder may not have had the full original code.
The damage and the victims
Between 2021 and 2023, Silnikau’s group hit at least 18 organizations, prosecutors said. Victims came from California, New York, Nebraska, and other countries too.
The hackers stole the company’s data first. Then they demanded payment. Victims had to pay for a key to unlock their files, or to stop the stolen data from going public.
Prosecutors said the group tried to squeeze at least $5.2 million out of its victims. Officials later confirmed that the 18 known victims lost more than $6.7 million combined. The real number may be higher, since some victims likely never reported the attack.
The ransomware threat is expected to grow as attackers adopt AI tools. Five Eyes agencies warned that frontier AI will enable threat actors to generate more convincing phishing lures and improve their ability to select high-value targets.
One attack in August 2022 hit a medical tech startup building robotic surgery tools. That company’s work was disrupted for about two months, according to court records. Another attack in May 2023 hit systems used by several law firms. Some firms lost service for days. Others were down for months.
One law firm stayed offline for nearly a month before paying $125,000. Another firm paused work for about a month before paying $300,000. Together, these two cases alone caused about $2.2 million in losses, per court filings.
Arrest, escape, and capture
Police first arrested Silnikau in Spain on July 18, 2023, as part of an international operation, the DOJ said. He was waiting to be sent to the United States for trial.
But he escaped custody before that could happen. Officers later caught him again as he tried to cross from Poland into Belarus, his home country.
Prosecutors confirmed in their sentencing filing that Silnikau ran from Spanish police during the extradition process. Officers stopped him at the Poland-Belarus border.
He eventually agreed to be sent to the U.S. Officials transferred him from Poland to face trial in the Eastern District of Virginia, according to the DOJ.
His 16-year sentence closes out the case against the man authorities call the leader of the Ransom Cartel ransomware group.