Armenian authorities detained Russian tourist Aleksandr Yuryevich Ermakov in Yerevan on June 28 under a U.S. extradition request tied to alleged REvil ransomware activity, but his lawyers say he is not the wanted cybercriminal. The dispute centers on whether U.S. prosecutors and an Interpol notice were actually seeking Aleksandr Gennadievich Ermakov, a different Russian man sanctioned by the United States, United Kingdom, and Australia for alleged links to REvil and the 2022 Medibank breach.
Reporting indicates the extradition paperwork may have omitted key identifying details, including a patronymic, creating the risk of a mistaken match. U.S. charging materials cited in the case accuse an Aleksandr Ermakov of involvement in Sodinokibi/REvil attacks from April 2019 to July 2021, with the Interpol notice reportedly describing a platform administrator who earned more than $13.7 million and whose operations hit more than 1,000 organizations, including businesses, government offices, schools, and hospitals. Defense lawyers also suggested automated matching may have contributed to the detention, while Armenian authorities and the U.S. Justice Department had not publicly clarified the identity issue at the time of reporting.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
In January 2024, Australia, the United States, and the United Kingdom sanctioned Aleksandr Gennadievich Ermakov for links to cybercrime activity including the Medibank breach. The sanctions are cited as part of the paperwork that may have contributed to confusion with another man of a similar name.
The references state that the sanctioned Aleksandr Gennadievich Ermakov was linked to the 2022 Medibank breach. This linkage later became part of the identity dispute surrounding the Armenian detention.
U.S. charging material cited in the references alleges that an Aleksandr Ermakov participated in Sodinokibi/REvil ransomware attacks beginning around April 2019. The campaign reportedly went on to affect more than 1,000 entities, including businesses, government offices, schools, and hospitals.
On June 28, Armenian authorities detained Russian tourist Aleksandr Yuryevich Ermakov in Yerevan based on a U.S. extradition request tied to alleged REvil ransomware activity. His lawyers argued that he was not the sanctioned cybercriminal Aleksandr Gennadievich Ermakov and that the detention stemmed from insufficient identifying details in the request.
The U.S. charging material described in the references says the alleged participation of Aleksandr Ermakov in REvil attacks continued until July 12, 2021. An Interpol notice reportedly characterized him as a platform administrator who earned more than $13.7 million.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.