×

DOJ charges two men allegedly behind REvil ransomware attacks

By Alexander Mallin, Ben Gittleson, and Luke Barr, ABC News Nov 8, 2021 | 2:14 PM


Chip Somodevilla/Getty Images

(WASHINGTON) — The nation’s top law enforcement officials announced on Monday the seizure of approximately $6 million in ransom payments and new criminal charges against a Ukrainian national and Russian national alleged to have deployed the REvil ransomware that infected more than 1,000 companies and public organizations around the globe this summer.

Yaroslav Vasinskyi, a Ukrainian national arrested last month in Poland, and Yevgeniy Polyanin, a Russian national who remains at large, face charges of fraud, conspiracy and money laundering. Vasinskyi was charged in connection with his alleged role in carrying out the devastating July 4 ransomware attack against the software firm Kaseya, which in turn affected hundreds of companies within the U.S.

Together, the U.S. Treasury Department said the two men “are part of a cybercriminal group that has engaged in ransomware activities and received more than $200 million in ransom payments paid in Bitcoin and Monero.” It is announcing sanctions against the two men as well.

Charging documents unsealed Monday morning also accuse Vainskyi of conducting approximately 2,500 ransomware attacks and demanding approximately $767 million in ransom, $2.3 million of which was eventually paid.

There is no lawyer listed for Vasinskyi or Polyanin.

“Our message today is clear: The United States, together with our allies, will do everything in our power to identify the perpetrators of ransomware attacks, to bring them to justice and to recover the funds they have stolen from the American people,” Attorney General Merrick Garland said.

Deputy Attorney General Lisa Monaco lauded Kaseya for calling the FBI and Department of Justice and asking for help in finding the alleged criminals.

“As we’ve shown time and time again, we’re still going to pursue them, disrupt them and hold them accountable,” FBI Director Christopher Wray said.

Garland said REvil ransomware has been deployed on approximately 175,000 computers worldwide with at least $200 million paid in ransom.

REvil was also behind the May attack on meat supplier JBS, which paid $11 million in ransom to unlock its systems.

The State Department is is offering a reward of up to $10 million for information that helps identify or locate the leaders of the cybercriminal group known as REvil or Sodinokibi.

The U.S. is also offering up to $5 million for information that leads to the arrest or conviction of any individual involved in a REvil ransomware attack.

In June, the Justice Department announced it had successfully seized millions of dollars in cryptocurrency Colonial Pipeline paid to the cyber criminal group DarkSide following the attack that led the pipeline to briefly shut down its operations.

ABC News’ Connor Finnegan contributed to this report.

Copyright © 2021, ABC Audio. All rights reserved.