ALEXANDRIA, Va. — Maksim Silnikau, the creator and leader of the Ransom Cartel ransomware operation, has been sentenced to 16 years in federal prison for his role in a cybercrime enterprise that targeted organizations in the United States and abroad.
Silnikau, 40, is a Belarusian and Ukrainian national who operated under numerous online aliases, including “J.P. Morgan,” “targa,” “xxx” and “lansky.” Authorities connected him to Russian-language cybercrime forums dating back nearly two decades.
His sentence was imposed Wednesday, August 5, 2026, in the Eastern District of Virginia for conspiracy to commit offenses against the United States, conspiracy to commit wire fraud and aggravated identity theft. The case marked the culmination of an international effort that tracked Silnikau across underground forums, ransomware infrastructure and several countries before his extradition to the United States.
Silnikau developed and administered Ransom Cartel, a ransomware-as-a-service operation that emerged in 2021. The platform allowed affiliates to use ransomware tools and criminal infrastructure supplied by the organization to attack victims without developing the malware themselves.
The ransomware-as-a-service model separates the individuals who create and maintain the malicious software from affiliates who identify targets, gain access to networks and deploy the ransomware. Criminal proceeds are then divided among the participants according to arrangements established by the organization.
Silnikau recruited affiliates through cybercrime forums and provided them with tools and resources used to carry out attacks. These resources included stolen credentials, access to compromised networks and ransomware capable of encrypting data across victim systems.
He also operated concealed online infrastructure that allowed Ransom Cartel members to coordinate attacks, communicate with victims, negotiate payments and distribute criminal proceeds. The platform provided affiliates with the operational support needed to transform unauthorized network access into organized extortion.
Between 2021 and 2023, Ransom Cartel affiliates attacked at least 18 organizations. The victims included businesses operating in California, New York, Nebraska and other locations within and outside the United States.
The attackers used a double-extortion strategy. Sensitive information was stolen from victim networks before ransomware encrypted files and disrupted access to computer systems.
Victims were then pressured to pay for a decryption key that could restore access to encrypted information. They were also threatened with publication of the stolen material if they refused to meet the group’s financial demands.
This approach gave the organization two forms of leverage. A victim that restored its systems through backups could still face the release of confidential records, customer information or internal business data. Payment for a decryption key also provided no independent guarantee that stolen information had been destroyed.
Federal prosecutors said Ransom Cartel’s activity was disrupted after Silnikau’s arrest in July 2023. Removing the administrator interfered with the leadership, tools and infrastructure required to support affiliates across separate attacks.
Silnikau was arrested during an international operation in Estepona, Spain, in 2023. He was later transferred through Poland and extradited to the United States in August 2024 to face federal cybercrime charges.
The arrest and extradition required cooperation among authorities in the United States, United Kingdom, Spain, Poland, Portugal, Germany and Ukraine. The operation demonstrated the amount of international coordination required to prosecute a ransomware administrator whose infrastructure, associates and victims were distributed across several jurisdictions.
Theophani K. Stamos, First Assistant U.S. Attorney for the Eastern District of Virginia; Acting Special Agent in Charge Andrew Forrest of the U.S. Secret Service Criminal Investigative Division; Special Agent in Charge Chris Ormerod of the FBI Kansas City Field Office; and Special Agent in Charge Craig L. Tremaroli of the FBI Albany Field Office announced the sentence. U.S. District Judge Rossie D. Alston Jr. imposed the 16-year prison term.
Assistant U.S. Attorney Jonathan S. Keim and former Assistant U.S. Attorney Zoe Bedell prosecuted the case. The Justice Department’s Office of International Affairs provided substantial assistance with Silnikau’s extradition and the collection of evidence. The U.S. Attorney’s Office for the District of New Jersey and the Computer Crime and Intellectual Property Section also assisted.
Silnikau was also accused in a separate federal case of cybercrime activity predating Ransom Cartel. Authorities alleged that he participated in the development and distribution of the Angler exploit kit, one of the most prominent malware-delivery tools used during the mid-2010s.
Exploit kits were designed to examine a visitor’s computer or web browser for security weaknesses and deliver malicious software when a vulnerable system was detected. Victims could encounter the malicious code through compromised websites or fraudulent advertisements placed within legitimate online advertising systems.
According to those allegations, the Angler operation used malvertising campaigns in which advertisements that appeared legitimate redirected users toward infrastructure designed to deliver malware, fraudulent content or deceptive warnings. The campaigns could reach large numbers of internet users without requiring criminals to contact each victim directly.
Authorities estimated that the alleged activity associated with Angler generated tens of millions of dollars annually. The exploit kit became a valuable service within the cybercrime economy because it provided other criminals with an automated way to compromise devices and distribute additional malware.
Silnikau was also accused of helping create Reveton, an early ransomware-as-a-service operation that appeared in 2011. Reveton locked victims’ computer screens and displayed fraudulent messages designed to appear as though they came from law enforcement.
The messages falsely accused victims of possessing or accessing illegal material and demanded payment of a supposed fine. The scheme relied upon fear, embarrassment and the threat of imprisonment to pressure victims into paying.
Prosecutors described Reveton as the first ransomware-as-a-service business model. It allowed affiliates with limited technical ability to launch attacks in exchange for sharing proceeds with the people who developed and maintained the platform.
The Reveton operation allegedly generated approximately $400,000 per month from victims between 2012 and 2014. Its business structure helped establish a model later adopted by major ransomware organizations, including the division of responsibilities between developers, administrators and affiliates.
Volodymyr Kadariya, a Belarusian and Ukrainian national, and Russian national Andrei Tarasov were charged in the United States as alleged co-conspirators in the malvertising and ransomware schemes.
The charges against Kadariya and Tarasov remain allegations unless resolved through guilty pleas or convictions. Silnikau’s 16-year sentence does not establish the guilt of either co-defendant.
The allegations involving Angler and Reveton are separate from the Ransom Cartel offenses for which Silnikau was sentenced.
Silnikau’s use of multiple aliases and concealed infrastructure allowed him to operate across international cybercrime communities for years. His arrest showed that online identities do not permanently separate ransomware administrators from the individuals operating behind them.
The 16-year sentence holds Silnikau accountable for building and administering a ransomware service that enabled attacks against organizations across multiple jurisdictions.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified




It sounds like they caught some big fish here. Silnikau sounds like he has earned every minute of the sentence he got. I appreciate the cooperation and work of authorities in other countries who assisted with this investigation and I appreciate the work those in the U.S. did as well.
Thank you for this article.
Thank you very much, and you’re very welcome, Chris.
What made Maksim Silnikau especially significant was not simply the number of attacks connected to Ransom Cartel, but his alleged role in building and administering the infrastructure that allowed other criminals to carry them out. Removing someone who supplies access, ransomware tools, negotiation systems, and payment infrastructure can disrupt far more activity than arresting a single affiliate.
His arrest in Spain, transfer through Poland, and prosecution in the United States also demonstrate that operating across borders does not guarantee permanent protection from accountability. After nearly two decades of activity under multiple online aliases, his 16-year sentence represents a substantial disruption to the criminal ecosystem he helped sustain.
Thank you again for reading and commenting, Chris. Your continued support is always greatly appreciated. I hope you have a great day ahead. 😎
You’re welcome, John, and thank you for your comment. Making it easier for others to commit crime is certainly another good reason for this long prison sentence.
The arrest route you describe should also send a message to anyone wanting to follow in Maksim Silnikau’s shoes. There is never an assurance that criminal activity like this will go unpunished.
Thanks you again, John, and I hope you have a great day ahead as well!😊