Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.
The U.S. Department of Justice announced today that the 40-year-old Belarusian national was sentenced for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud, and aggravated identity theft.
The DOJ says Silnikau had been active on Russian-speaking cybercrime forums since at least 2005 and used the aliases “J.P. Morgan,” “xxx,” and “lansky.”
He was also a member of the Direct Connection cybercrime website between 2011 and 2016, when the site was shut down following the arrest of its administrator.
According to court documents, Silnikau began developing the Ransom Cartel ransomware operation in May 2021 and recruited other cybercriminals through underground forums to participate in attacks.
He supplied members with information and tools used in the intrusions, including stolen credentials for compromised computers and software designed to encrypt victims’ computers.
Silnikau also operated an affiliate website that allowed members of the ransomware operation to manage attacks, communicate with each other, negotiate ransom demands, and distribute revenue shares after a ransom was paid.
Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 companies worldwide, including organizations in California, New York, Nebraska, and countries outside the United States.
During the attacks, the threat actors stole corporate data and demanded payments in exchange for decryption keys or promises that the stolen information would not be publicly leaked.
Federal prosecutors said the ransomware operation attempted to extort at least $5.2 million from its victims.
The United States identified more than $6.7 million in losses suffered by 18 known victims, although prosecutors said the total was likely higher because some victims had not reported their attacks.
In one August 2022 attack, Ransom Cartel reportedly disrupted the operations at a medical technology startup developing robotic surgical technology for two months. In May 2023, the gang also attacked infrastructure used by a group of law firms, causing business disruptions lasting from several days to multiple months.
One law firm paid a ransom worth $125,000 after being disrupted for nearly a month, while another suspended operations for almost a month before paying a $300,000 ransom.
Prosecutors said the combined losses associated with those attacks reached approximately $2.2 million.
Ransom Cartel launched publicly in December 2021 and shared code similarities with the REvil ransomware encryptor.
However, the lack of some of REvil’s obfuscation features led researchers to believe that it may have been created by a former core member of the operation who did not have access to the complete source code.
Silnikau reportedly held a central role in the ransomware-as-a-service operation, recruiting affiliates, working with initial access brokers who supplied access to compromised corporate networks, communicating with victims, and handling ransom payments.
He also transmitted ransom payments through cryptocurrency mixers to make it harder for law enforcement to trace the funds.
Silnikau was initially arrested in Spain on July 18, 2023, as part of an international law enforcement operation. However, he fled while awaiting extradition to the United States and was later captured while attempting to return to Belarus.
“The defendant fled Spanish authorities while awaiting extradition to the United States and was apprehended while trying to cross from Poland to his native Belarus,” prosecutors said in their sentencing filing.
Silnikau ultimately consented to extradition and was sent from Poland to the United States to face prosecution in the Eastern District of Virginia.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
West Pharmaceutical says hackers stole data, encrypted systems
Data breach at medical billing firm MCBS affects 1.26 million people
Coca-Cola confirms data theft in Fairlife ransomware attack
Always good to see consequences for these criminals. I remember a decade ago I never would have believed that any of these guys would get arrested, let alone serve prison time. Hopefully the DOJ can bring more of them to justice.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Massive ChainDrop npm supply-chain attack infects hundreds of packages
New Pass-ta-key attacks let malware hijack Google-synced passkeys
Explore ESET’s H1 2026 Threat Report to uncover the latest AI, phishing, and ransomware trends.
Spend four hours inside a fully-simulated underground with DARKROOM.
AI is a data-breach time bomb: Read the new report
Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


