According to court documents, Yaroslav Vasinskyi, also known as Rabotnik, 24, conducted thousands of ransomware attacks using the ransomware variant known as Sodinokibi/REvil. Ransomware is malicious software designed to encrypt data on victim computers, allowing bad actors the ability to demand a ransom payment in exchange for the decryption key.
The co-conspirators demanded ransom payments in cryptocurrency and used cryptocurrency exchangers and mixing services to hide their ill-gotten gains. To drive their ransom demands higher, Sodinokibi/REvil co-conspirators also publicly exposed their victims’ data when victims would not pay ransom demands.
Vasinskyi previously pleaded guilty in the Northern District of Texas to an 11-count indictment charging him with conspiracy to commit fraud and related activity in connection with computers, damage to protected computers, and conspiracy to commit money laundering. He was previously extradited to the United States from Poland.
Relatedly, in 2023, the Department obtained the final forfeiture of millions of dollars’ worth of ransom payments obtained through two related civil forfeiture cases, which included 39.89138522 Bitcoin and $6.1 million in U.S. dollar funds traceable to alleged ransom payments received by other members of the conspiracy.
The FBI investigated the case.
Senior Counsel Frank Lin of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Tiffany H. Eggers for the Northern District of Texas prosecuted the case. Assistant U.S. Attorney Dimitri N. Rocha for the Northern District of Texas assisted with the related civil forfeiture cases.
The Justice Department’s Office of International Affairs worked with Polish authorities to secure the extradition of Vasinskyi.