Ukrainian authorities have extradited a suspected member of the Ryuk ransomware gang to the U.S., where he faces charges over cyberattacks that extorted more than $100 million from victims worldwide. The 33-year-old foreign national was arrested in Kyiv in April and handed over to American authorities earlier this week. The suspect was engaged in searching for vulnerabilities in corporate networks of victim companies, acting as an 'initial access broker.' The group launched over 2,400 ransomware attacks, encrypting victims' data and demanding cryptocurrency payments in exchange for access. The attacks targeted corporations, critical infrastructure, and industrial enterprises across the world, typically for financial gain.
Source: https://therecord.media/alleged-ryuk-member-arrest-ukraine-extradited-us
TPRM report: https://scoringcyber.rankiteo.com/company/national-center-for-victims-of-crime
"id": "nat157062025",
"linkid": "national-center-for-victims-of-crime",
"type": "Ransomware",
"date": "6/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Multiple countries',
'type': 'Corporations, critical infrastructure, and '
'industrial enterprises'}],
'attack_vector': 'Ransomware',
'data_breach': {'data_encryption': "Victims' data encrypted"},
'date_detected': 'August 2018',
'date_publicly_disclosed': '2023-11-22',
'description': 'Ukrainian authorities extradited a suspected member of the '
'Ryuk ransomware gang to the U.S., where he faces charges over '
'cyberattacks that extorted more than $100 million from '
'victims worldwide.',
'impact': {'financial_loss': ['$100 million extorted from victims worldwide',
'$600,000 in crypto assets seized'],
'systems_affected': 'Corporations, critical infrastructure, and '
'industrial enterprises'},
'initial_access_broker': {'high_value_targets': 'Corporations, critical '
'infrastructure, and '
'industrial enterprises'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain',
'ransomware': {'data_encryption': "Victims' data encrypted",
'ransom_demanded': 'High ransom payments',
'ransomware_strain': 'Ryuk'},
'references': [{'date_accessed': '2023-11-22',
'source': 'Ukraine’s Office of the Prosecutor General'}],
'regulatory_compliance': {'legal_actions': 'Extradition and charges'},
'response': {'law_enforcement_notified': ['U.S. law enforcement',
'Ukrainian authorities',
'FBI']},
'threat_actor': 'Ryuk Ransomware Gang',
'title': 'Extradition of Suspected Ryuk Ransomware Gang Member',
'type': 'Ransomware'}