Russian media reporting cited by multiple outlets says Moscow resident Ruslan Satuchin has been accused of attempting to extort money from the Conti ransomware group by posing as an officer of Russia’s Federal Security Service (FSB). The alleged scheme began in September 2022, when Satuchin reportedly contacted a Conti member and claimed he could influence law-enforcement activity targeting the gang, demanding payment in exchange for avoiding prosecution; Satuchin has denied wrongdoing.
Authorities reportedly sought to keep Satuchin in pre-trial detention over concerns including potential witness intimidation, and he could face up to 10 years in prison and a fine if convicted. The reporting also reiterates Conti’s history as a major ransomware operation that extorted governments, businesses, and healthcare organizations, and notes that the group’s internal operations and apparent avoidance of Russian targets were widely exposed after leaked Conti chat logs and materials surfaced in 2022.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By late February 2026, Russian authorities had accused Ruslan Satuchin of attempting to extort the Conti ransomware gang by posing as an FSB officer. He denied wrongdoing and was reported to be in pre-trial detention in Moscow, with investigators arguing detention was needed to prevent possible witness intimidation.
In 2023, the United States and the United Kingdom publicly named and sanctioned key individuals linked to the Conti ransomware operation. The action marked a formal government response targeting people associated with the group.
According to Russian media reports, Moscow resident Ruslan Satuchin allegedly began an extortion scheme in September 2022 by contacting a Conti ransomware member while impersonating an officer of Russia’s FSB. He allegedly demanded payment in exchange for protection from criminal consequences and claimed influence over law enforcement investigations.
In 2022, a pro-Ukraine researcher published Conti chat logs, source code, and infrastructure documents, exposing the ransomware group's internal operations. The leaks reinforced suspicions that Conti avoided Russian targets and had ties aligned with Kremlin interests, contributing to the group's later collapse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bitdefender.com
Open sourcedatabreaches.net
Open sourcerbc.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.