Stay up to date with notifications from The Independent

Notifications can be managed in browser preferences.

US charges suspect linked to notorious ransomware gang

A man who authorities say participated in a ransomware campaign that extracted tens of millions of dollars from victims has been charged in the United States

Eric Tucker
Thursday 10 November 2022 18:27 GMT
Ransomware Gang Arrest
Ransomware Gang Arrest (Bloomberg)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

A man who authorities say participated in a ransomware campaign that extracted tens of millions of dollars from victims has been charged in the United States, the Justice Department announced Thursday.

Mikhail Vasiliev, a dual national of Russia and Canada, was arrested Wednesday. He is currently in custody in Canada and is awaiting extradition to the U.S. on charges that accuse him of involvement in the Lockbit ransomware operation.

No lawyer for the 33-year-old Vasiliev, of Bradford, Ontario, Canada was listed on the court docket. He faces charges of conspiracy to intentionally damage protected computers and to transmit ransom demands.

Lockbit has been one of the most prolific strains of ransomware. During the first five months of this year it accounted for 46% of all ransomware-related breaches that were publicized on extortion sites used by the syndicate to pressure victims by threatening to publicly leak stolen data, according to the cybersecurity firm Palo Alto Networks.

Its top victims have been in the U.S., Italy and Germany, where it targeted a gamut of industries from manufacturing to retail.

The Justice Department says that between January 2020 and the present, LockBit members have conducted at least 1,000 ransomware attacks — in which hackers hold victims' data hostage through encryption until a sum is paid — in the U.S. and around the world. Prosecutors said the hackers made at least $100 million in ransom demands and extracted tens of millions of dollars in payments.

Deputy Attorney General Lisa Monaco said in a statement that the arrest was the “result of over two-and-a-half-years of investigation into the LockBit ransomware group.”

According to court documents made public Thursday, Canadian law enforcement searched Vasiliev's home and discovered a file named “TARGETLIST” on a device. One of the victims named on that list was a business in New Jersey, where the Justice Department filed the case, the documents say.

Law enforcement did another search in October, when they said they found on a laptop computer an open tab pointed to a site called “LockBit LOGIN.”

_____

Associated Press writer Frank Bajak in Boston contributed to this report.

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in