Notorious Ryuk Ransomware Hacker Who Infiltrated Corporate Networks Extradited to Face U.S. Justice


# Ryuk Ransomware Member Extradited to US Following International Investigation

A 33-year-old cybercriminal specializing in network infiltration for the notorious Ryuk ransomware operation has been extradited to the United States. The suspect was arrested in April 2025 at his Kyiv residence following an FBI request and was transferred to US custody on June 18.

## International Investigation Uncovers Major Ransomware Network

In 2023, Ukrainian cyber police, the National Police, and international law enforcement partners launched a comprehensive investigation into a ransomware operation targeting companies across France, Norway, Germany, the Netherlands, Canada, and the United States. This investigation successfully identified and arrested multiple cybercriminals in Ukraine connected to several major ransomware families, including LockerGoga, MegaCortex, Hive, and Dharma.

## Suspect’s Role in Cyber Operations

According to Ukraine’s National Police, the extradited individual served as a network access specialist within the Ryuk organization. His primary responsibility involved identifying vulnerabilities in corporate networks, which other gang members then exploited to steal data and deploy ransomware.

“The 33-year-old member of the group was engaged in searching for vulnerabilities in the corporate networks of victim companies,” stated the National Police announcement. “The data obtained by the hacker was used by his accomplices to plan and carry out cyberattacks.”

The suspect, whose identity remains undisclosed, was previously placed on an international wanted list by the FBI and faces multiple charges in the United States.

## Ryuk’s Criminal Legacy

The Ryuk ransomware gang operated from 2018 to mid-2020, conducting attacks across virtually all business sectors, including healthcare facilities during the COVID-19 pandemic. Security researchers estimate the operation generated approximately $150 million in ransom payments during its active period.

In 2020, the group rebranded as the Conti ransomware operation, becoming one of the most prolific cybercriminal organizations. Conti eventually disbanded in 2022, with its members forming various splinter groups that remain active today.

This extradition represents a significant victory in international efforts to combat ransomware operations and demonstrates the effectiveness of cross-border law enforcement cooperation in pursuing cybercriminals.

Share This Article