France and Russia carried out a prisoner exchange that returned French conflict researcher Laurent Vinatier to France in exchange for Daniil Kasatkin, a Russian basketball player sought by the U.S. for alleged ties to ransomware operations. Vinatier, a political scientist focused on the Ukraine war and affiliated with the Swiss NGO Centre for Humanitarian Dialogue, had been detained in Russia and sentenced under Russia’s “foreign agent” framework, with Russian security services alleging he collected military-related information.
Kasatkin had been held in France since mid-2025 on an extradition hold tied to a U.S. warrant alleging he supported ransomware activity by acting as a negotiator for a major cybercrime group linked to roughly 900 victims, including U.S. government entities; reporting notes the victim count aligns with prior U.S. statements about the now-defunct Conti ransomware group, though the gang was not consistently named in all accounts. Kasatkin has denied the allegations, and the swap was characterized as part of Russia’s broader use of detainees for geopolitical leverage, underscoring how cybercrime prosecutions can intersect with state-to-state diplomacy.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
By January 2026, France and Russia carried out a prisoner exchange in which Kasatkin was returned to Russia and Vinatier was released to France. Russian state media published video of Kasatkin arriving on a plane used in the exchange.
In June 2025, Russian basketball player Daniil Kasatkin was detained at Paris Charles de Gaulle Airport at the request of U.S. authorities. He was held in French extradition custody over allegations that he acted as a negotiator for a ransomware group.
French researcher Laurent Vinatier was imprisoned in Russia in October 2024 after being accused of failing to register as a foreign agent. Russian authorities alleged he gathered military-related information.
Between 2020 and 2022, the ransomware operation tied in reporting to the now-defunct Conti group allegedly attacked roughly 900 victims worldwide, including two U.S. federal departments. U.S. authorities later cited this activity in allegations against Daniil Kasatkin.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.