Yemeni Hacker Charged in U.S. for Black Kingdom Ransomware Attacks on Hospitals, Schools, and Businesses


# Yemeni National Charged in Global Black Kingdom Ransomware Campaign

The U.S. Department of Justice has charged Rami Khaled Ahmed, a 36-year-old Yemeni national, with deploying the Black Kingdom ransomware against global targets including U.S. businesses, schools, and healthcare facilities. Ahmed faces charges of conspiracy, intentional damage to protected computers, and threatening damage to protected computers.

Between March 2021 and June 2023, Ahmed allegedly infected computer networks across the United States, including a medical billing company in California, an Oregon ski resort, a Pennsylvania school district, and a Wisconsin health clinic. The ransomware exploited the ProxyLogon vulnerability in Microsoft Exchange Server to encrypt data or claim to steal information from victims’ networks.

After encryption, victims received ransom notes demanding $10,000 in Bitcoin. The ransomware, also known as Pydomer, is estimated to have compromised approximately 1,500 computer systems worldwide. Cybersecurity experts at Sophos described Black Kingdom as “somewhat rudimentary and amateurish,” suggesting it bore hallmarks of a “motivated script-kiddie” operation.

If convicted, Ahmed faces up to five years in federal prison for each count. The FBI is investigating the case with assistance from New Zealand Police.

## Other Recent Cybercrime Enforcement Actions

The DoJ has announced several other significant cybercrime cases:

– Ukrainian citizen Artem Stryzhak was charged with Nefilim ransomware attacks and extradited from Spain
– British national Tyler Robert Buchanan, allegedly part of Scattered Spider, was extradited from Spain
– Two alleged leaders of child extortion group 764, Leonidas Varagiannis and Prasan Nepal, were arrested
– Cambodia-based HuiOne Group was designated as a “primary money laundering concern” for facilitating cybercrime

## Ransomware Trends Show Evolution

Despite law enforcement pressure, ransomware remains a persistent threat, though the landscape is changing. Attacks are becoming more decentralized, with former affiliates increasingly operating independently rather than within established groups.

Verizon reports that 44% of analyzed breaches in 2024 involved ransomware, up from 32% in 2023. However, more victims are refusing to pay ransoms, with 64% declining payment in 2024 compared to 50% two years prior. The median ransom payment decreased to $115,000 in 2024 from $150,000 the previous year.

The first quarter of 2025 saw 2,289 reported ransomware incidents, a 126% increase from Q1 2024, though March 2025 showed a 32% month-over-month decrease. North America and Europe accounted for over 80% of cases, with consumer goods, business services, manufacturing, healthcare, and construction being the most targeted sectors.

Share This Article