Subscribe Sign in

Courts

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

2 min read Rewritten in plain language

Security

Show what we removed Rules applied: A1×3 A2 C5×2 D1×3 D2 D3×5 D4 E3 F2 all 30 rules
  • A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail.
  • The judgment is not final and can be appealed.
  • The ransomware developer was also found guilty of playing a role in high-profile ransomware attacks, including the one that hit Stadler Rail in 2020 [PDF].
  • As it did following this year's incident, Stadler refused to pay.
  • In September 2022, Zurich prosecutors reported that a suspect had been arrested in Basel-Landschaft in October 2021 on suspicion of money laundering and data corruption.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Zurich District Court found the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the operations. Not to be confused with the more recent attack on the rolling stock manufacturer the earlier breach occurred in May 2020.

Headline check

One of the three things this headline claims did not turn up in the report.

  • The figure “13” is in the headline. We could not find it in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. Figures are matched digit for digit, so a report that writes “forty per cent” out in words where the headline wrote “40%” is queried here when it should not be. How this is checked

Read the full reportHide the full report2 min

The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations

A Swiss court has sentenced a 52-year-old Ukrainian ransomware developer to 12 years and nine months in prison for his role in attacks on companies including Stadler Rail.

Zurich District Court found that the man developed LockerGoga, MegaCortex, and Nefilim, but was not the mastermind behind the operations. He also received a ten-year ban from Switzerland. The judgment is not final and can be appealed.

He had been held in pretrial detention since October 2021 and consistently denied knowing that his software was being used for criminal purposes.

He said the source code found at his home in Basel-Landschaft came from his consulting work for a unidentified IT security client.

The court rejected that explanation because extortion messages were also found among his data, SWI reported.

The ransomware developer was also found guilty of playing a role in high-profile ransomware attacks, including the one that hit Stadler Rail in 2020 [PDF].

Not to be confused with the more recent attack on the rolling stock manufacturer – that one was claimed by Everest – the earlier breach occurred in May 2020.

At the time, Stadler Rail did not use the word "ransomware," but said the attack involved malware, that it "most likely led to a data leak," and that "the offenders tried to extort a large amount of money," threatening to leak the files if the ransom was not paid.

As it did following this year's incident, Stadler refused to pay. The 2020 Nefilim ransom demand was reportedly $6 million.

The court also found that he played a role in attacks on HVAC company Meier Tobler and software company Crealogix.

In September 2022, Zurich prosecutors reported that a suspect had been arrested in Basel-Landschaft in October 2021 on suspicion of money laundering and data corruption.

The statement accused the perpetrators of involvement in attacks on more than 1,800 individuals and institutions across 71 countries, causing estimated losses of several hundred million Swiss francs.

The same law enforcement action in 2021 led to the identification of other alleged members of the three ransomware operations, none of whom were named.

Volodymyr Tymoshchuk was formally indicted in the US last year and was described by prosecutors as the mastermind of all three ransomware crews.

Unlike many others, Tymoshchuk has not yet been arrested, but is on the FBI's most wanted list, with an $11 million bounty placed on the information that could lead to his arrest or conviction, or that of other leaders.

He was allegedly responsible for attacks on at least 250 companies, including the Norsk Hydro attack in 2019. ®

You are reading our version, not theirs. This is The Register's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
The Registeras they published this story 10.2 5 51 -0.9 33.8
Mundane Readneutralized from The Register 6.6 2 51 -0.6 33.8

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works