Belarusian Ransom Cartel Creator Sentenced To 16 Years In Prison
August 6, 2026Read also: the Cornflake hacker pleads guilty; a former FBI agent accused of the crypto theft; and more.

Ransom Cartel creator sentenced to 16 years in prison
Maksim Silnikau, a 40-year-old Belarusian national and the creator of the Ransom Cartel ransomware group, has been sentenced to 16 years in prison in the United States. He was convicted of conspiracy to commit offenses against the US, conspiracy to commit wire fraud, and aggravated identity theft.
According to prosecutors, Silnikau aka "J.P. Morgan," "xxx," and "lansky," had been active on Russian-speaking cybercrime forums since at least 2005. He was also a member of the notorious Direct Connection cybercrime website from 2011 to 2016, until the site was shut down after its administrator was arrested.
In May 2021, Silnikau created the Ransom Cartel ransomware operation and began recruiting cybercriminals through underground forums. He supplied members with stolen credentials, information about compromised computers, and ransomware tools used to encrypt victims' systems. He also operated a hidden website where affiliates could manage attacks, communicate with each other, negotiate ransom payments with victims, and distribute profits.
Between 2021 and 2023, Ransom Cartel affiliates carried out ransomware attacks against at least 18 companies worldwide. During the attacks, the group stole corporate data and demanded ransom payments in exchange for decryption keys or promises not to leak the stolen information.
Federal prosecutors said the group attempted to extort at least $5.2 million from victims. Known losses exceeded $6.7 million, although officials believe the true amount is higher because some attacks were never reported.
Silnikau was arrested in Spain in July 2023 but escaped while awaiting extradition. He was later caught while attempting to return to Belarus, extradited from Poland to the United States, and prosecuted in the Eastern District of Virginia.
A hacker behind the Snowflake breach pleads guilty
A Canadian man has pleaded guilty for his role in the major compromise of cloud storage company Snowflake, which affected at least 165 firms. Connor Riley Moucka, 26, admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy in a US federal court. He will be sentenced on October 27 and could face up to 32 years in prison.
Prosecutors said Moucka and his partners used stolen login details to break into Snowflake customer accounts between February and October 2024. They stole billions of files from companies including AT&T, Ticketmaster, Neiman Marcus and Santander.
The stolen data included banking records, passport numbers, driver's license numbers and Social Security numbers. The hackers demanded ransom payments and threatened to release the data online if companies refused to pay.
Authorities said the group made about $2.5 million in ransom payments, while Moucka also earned nearly $500,000 by selling stolen data on cybercrime forums. The attacks caused an estimated $9.5 million in losses for victims.
Moucka was arrested in Canada in November 2024 and extradited to the United States in July 2025. Authorities said the hackers gained access by using stolen customer login credentials rather than exploiting a weakness in Snowflake's systems.
Two arrested in Pakistan in connection to Tycoon2FA phishing service
Two Pakistani nationals suspected of developing the Tycoon2FA phishing platform have been arrested in Pakistan after a joint investigation by the Singapore Police Force (SPF), Pakistan's National Cyber Crime Investigation Agency (NCCIA), and Interpol.
Tycoon2FA was a phishing-as-a-service platform that allowed cybercriminals to create fake websites to steal login details and bypass multi-factor authentication. The platform leveraged more than 24,000 domains and has been linked to more than 96,000 phishing victims worldwide. In March 2026, a joint effort seized over 300 domains linked to the service’s core infrastructure.
The more recent arrests took place on 25 June and 1 July 2026 after investigators shared intelligence on the group's activities. Raids in Islamabad, Faisalabad, and Sialkot seized computers, servers, mobile devices, and storage media, while four additional suspects fled Pakistan and are now the subject of Interpol Red Notice requests. Authorities also allege that proceeds from the operation were invested in Islamabad real estate, which authorities are seeking to confiscate.
A former FBI agent charged with $925K cryptocurrency theft
A former FBI supervisory special agent has been charged after prosecutors accused him of stealing cryptocurrency using wallet recovery phrases obtained during FBI investigations.
According to a criminal complaint, Patrick Steven Yaroch allegedly memorized cryptocurrency seed phrases from wallets identified in federal investigations and used them to access the funds. Authorities say he made around 10 to 12 transfers between late 2024 and early 2025.
Authorities recovered about $925,426 in cryptocurrency linked to the case, although prosecutors said that may not represent the full amount allegedly taken. They also found about $165,582 in Yaroch's Kraken account.
Court documents say Yaroch admitted to making "very poor decisions" and told investigators he acted out of frustration because the FBI could not seize the wallets. The FBI placed him on leave before firing him, and investigators later recovered electronic devices, a Trezor hardware wallet, and a handwritten seed phrase during a search of his home.
Yaroch was arrested on July 31 and faces charges of interstate transportation of stolen property and receipt of stolen property.
A scammer indicted in a $14M travel agency fraud scheme
A man from Côte d’Ivoire has been indicted in connection with a $14 million fraud scheme that targeted travel agencies. US prosecutors have charged 30-year-old Koffi Dongo Parfait Teya with conspiracy to commit wire fraud, and unauthorized use of an access device.
According to the indictment, Teya and his associates sent phishing emails pretending to be from an airline reservation service. The emails claimed travel agencies needed a security update and directed employees to fake websites that looked like the real login page. Once employees entered their usernames and passwords, the group allegedly used the stolen credentials to book airline tickets and charge the costs to the agencies' accounts.
Authorities said the scheme caused about $14 million in losses and affected around 430 travel agencies.
Teya was arrested in Côte d’Ivoire with the help of local law enforcement. Authorities say the man will not be extradited to the United States. Instead, Teya is expected to be charged in Côte d'Ivoire.
Was kommt als Nächstes?
- Fordern Sie eine kostenlose Produktdemo oder Preisinformationen an.
- Registrieren Sie sich für unsere Webinare und Produktschulungen.
- Lesen Sie unseren wöchentlichen Blog „Cybercrime Investigations“
- Folgen Sie uns auf LinkedIn, X, Telegram und WhatsApp
- Abonnieren Sie unseren Newsletter
- Nehmen Sie an unserem Partnerprogramm teil.