German law enforcement added Oleg Evgenievich Nefedov/Nefekov, a 35-year-old Russian national, to the EU’s most-wanted list in connection with the Black Basta ransomware operation. German prosecutors and the Federal Criminal Police Office (BKA) allege he founded and led the group, acting as a “managing director” who selected targets, recruited and tasked members, participated in ransom negotiations, and managed extortion proceeds used to pay affiliates.
Authorities attribute to Black Basta a large global victim set since at least early 2022; reporting cites BKA estimates of roughly 700 organizations attacked worldwide and external researcher estimates of $100M+ in extortion payments by the end of 2023. The manhunt follows broader disruption and scrutiny of the group after an internal leak reportedly contributed to Black Basta ceasing activity, and the EU listing includes multiple alleged aliases (e.g., tramp, tr, gg, AA, kurva, Washingt0n, S.Jimmi) tied to the suspect’s role in developing and operating the ransomware and related malware used for intrusion, data theft, and encryption-based extortion paid in cryptocurrency.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
German authorities placed Oleg Nefedov on the EU Most Wanted list and said Interpol issued a Red Notice for him, seeking public tips on his whereabouts, travel, contacts, and online accounts. Authorities believe he is likely in Russia, though his exact location is unknown.
Germany's BKA and Frankfurt prosecutors publicly identified Russian national Oleg Evgenievich Nefedov as the suspected founder and leader of Black Basta. They accused him of developing the ransomware, selecting targets, recruiting members, participating in ransom negotiations, and managing cryptocurrency proceeds.
Investigators identified two Ukrainian suspects accused of supporting Black Basta by extracting passwords from stolen data, stealing credentials, and escalating privileges to prepare ransomware attacks. Authorities said their work enabled intrusions, data theft, and malware deployment against victims.
Ukrainian and German law enforcement conducted coordinated searches in the Ivano-Frankivsk and Lviv regions targeting alleged Black Basta members. Authorities seized digital devices, notes, and cryptocurrency assets for forensic analysis as part of the investigation.
Following the 2025 internal leak, Black Basta reportedly became inactive, removed its leak site, and ceased activity in a collapse compared by some reporting to Conti’s post-leak downfall. Some affiliates were reported to have shifted to other operations such as CACTUS.
Between March 2022 and February 2025, German authorities say Black Basta extorted more than 100 companies and institutions in Germany and roughly 600 to 700 organizations worldwide. Reported losses in Germany exceeded €20 million, with hospitals and public institutions among the victims.
Internal Black Basta chat logs and related data were leaked in early 2025, exposing operational details, member aliases, and technical information used by researchers and investigators. The leak was later cited as key evidence linking Oleg Nefedov to the group’s leadership.
Black Basta began operating as a ransomware-as-a-service group in 2022, with multiple reports placing its emergence in early 2022 or April 2022. Authorities later tied the group to hundreds of extortion incidents worldwide involving data theft and system encryption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcecyberscoop.com
Open sourcehelpnetsecurity.com
Open sourcecsoonline.com
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcedatabreaches.net
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.