U.S. authorities charged alleged Sodinokibi/REvil operators Yaroslav Vasinskyi of Ukraine and Yevgeniy Polyanin of Russia over ransomware attacks that included the compromise of Kaseya's remote management software, an intrusion that cascaded to managed service providers and their customers worldwide. The Kaseya incident was reported to have affected as many as 1,500 organizations, with attackers allegedly encrypting systems, leaving ransom notes, and directing victims to Tor-based or public payment sites to obtain decryption keys; victims that did not pay were allegedly threatened with the publication or sale of stolen data.
The Justice Department said Vasinskyi was arrested in Poland, later extradited to the United States, and arraigned in Texas on charges including conspiracy to commit computer fraud, damage to protected computers, and money laundering conspiracy. In parallel, U.S. authorities seized $6.1 million in alleged ransom proceeds tied to Polyanin, part of a broader multinational enforcement effort involving the FBI, Europol, Eurojust, and law enforcement partners across Europe and other allied countries to disrupt the REvil ransomware operation linked to the Kaseya attack.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2022-03-09, the DOJ announced that Vasinskyi had appeared in the Northern District of Texas to face charges including conspiracy to commit computer fraud, damage to protected computers, and money laundering conspiracy. Prosecutors said he was tied to multiple ransomware incidents, including the Kaseya attack.
On 2022-03-03, Vasinskyi was transported to Dallas after being extradited from Poland to face U.S. charges related to REvil ransomware attacks, including the July 2021 Kaseya attack. The extradition followed international law enforcement cooperation.
On 2021-11-08, the U.S. Department of Justice announced charges against Yaroslav Vasinskyi and Yevgeniy Polyanin for REvil ransomware activity tied to attacks on U.S. businesses and government entities, including Kaseya. The DOJ also announced the seizure of $6.1 million allegedly traceable to ransom payments received by Polyanin.
On 2021-10-08, alleged REvil affiliate Yaroslav Vasinskyi was arrested in Poland in connection with multiple ransomware attacks, including the Kaseya incident. He remained in custody pending extradition to the United States.
By July 6, 2021, reporting indicated that the Kaseya ransomware attack had affected as many as 1,500 organizations. This marked a major escalation in the understood scale of the incident.
In July 2021, attackers linked to the Sodinokibi/REvil ransomware operation used a Kaseya product to spread ransomware to customer endpoints and encrypt data at organizations worldwide. The attack became one of the incidents later cited in U.S. criminal charges against alleged REvil operators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcesecurityaffairs.com
Open sourcethehill.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.