Critical

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

The Hacker News
Actively Exploited

Overview

Maksim Silnikau, the creator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison on August 5 by a federal judge in Alexandria, Virginia. Ransom Cartel, which he launched in 2021, was responsible for cyberattacks on at least 18 companies across the U.S., including businesses in California, New York, and Nebraska, as well as targets overseas. The Justice Department's action underscores the seriousness of ransomware operations and the legal consequences for those who engage in such criminal activities. Ransomware-as-a-service models allow other criminals to use the malware for their own attacks, amplifying the threat to businesses and organizations that may not have robust cybersecurity measures in place. This case serves as a reminder of the ongoing challenges posed by ransomware and the importance of cybersecurity vigilance.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Ransomware-as-a-service operations targeting businesses in various sectors, including firms in California, New York, and Nebraska.
  • Action Required: Companies should implement strong cybersecurity protocols, including regular software updates, employee training on phishing attacks, and backup systems to mitigate ransomware risks.
  • Timeline: Ongoing since 2021

Original Article Summary

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.

Impact

Ransomware-as-a-service operations targeting businesses in various sectors, including firms in California, New York, and Nebraska.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since 2021

Remediation

Companies should implement strong cybersecurity protocols, including regular software updates, employee training on phishing attacks, and backup systems to mitigate ransomware risks.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Ransomware, Malware.

Related Coverage

TeamPCP Traced Back to 2020 Cryptojacking Operation

Infosecurity Magazine

Oligo Security has traced TeamPCP back to a cryptojacking operation that has been active since 2020. This group has been linked to the ShadowRay 2.0 malware, which is designed to hijack computing resources for cryptocurrency mining without the owner's consent. The researchers' findings indicate that the infrastructure used by TeamPCP has been operating for several years, raising concerns about the long-term impact on affected systems. Users and organizations need to be vigilant, as cryptojacking can lead to degraded system performance and increased energy costs. Understanding the history and tactics of such groups is crucial for improving defenses against these types of cyber threats.

Aug 6, 2026

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

BleepingComputer

A recent analysis by Skyhigh Security reveals that artificial intelligence has brought attention to existing security vulnerabilities in web browsers, rather than creating new ones. As organizations increasingly rely on browsers for data management and AI interactions, these vulnerabilities pose significant risks. Browsers are now seen as essential points for controlling data flow, which means any weaknesses can lead to data leaks or breaches. Companies need to reassess their browser security measures to protect sensitive information, especially as remote work continues to be prevalent. This situation underscores the importance of proactive security practices in the face of evolving technology.

Aug 6, 2026

Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

SecurityWeek

Researchers at Zenity have identified a serious vulnerability affecting AI browser applications, specifically Anthropic's Claude and OpenAI's ChatGPT Atlas. This issue allows attackers to hijack these platforms through seemingly harmless emails and posts on social media, particularly X (formerly Twitter). Despite reporting their findings to the companies involved in late 2025 and early 2026, the vulnerabilities remain unpatched, putting users at risk. This situation raises concerns about the security of AI tools that many people rely on for various tasks. Users of these applications should be cautious and stay informed about potential exploits until a fix is implemented.

Aug 6, 2026

AI failed to properly patch software flaws 74% of the time, 1Password's study warns

Latest news

A recent study by 1Password has revealed that artificial intelligence tools are failing to effectively patch software vulnerabilities 74% of the time. This raises concerns for organizations relying on AI to enhance their cybersecurity measures. The research suggests that while AI can assist in identifying flaws, it often struggles to implement effective fixes. This shortfall could leave systems vulnerable to attacks, as timely and accurate patching is crucial for maintaining security. Companies should critically evaluate their reliance on AI for patch management and consider maintaining human oversight to ensure proper security measures are in place.

Aug 6, 2026

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

The Hacker News

Forescout has identified a significant number of Rockwell Automation programmable logic controllers (PLCs) that are exposed to the internet, with a total of 4,407 found globally. Among these, 2,844 are located in the United States, including 22 in cities that have recently experienced cyberattacks on water utilities. Notably, 19 of these controllers are using the same mobile carrier network. While Forescout's scan raised concerns about the potential risks, they could not confirm any instances of these devices being compromised. This situation is alarming as it highlights the vulnerabilities in critical infrastructure, particularly in areas that have already been targeted by cyber threats, raising questions about the security measures in place to protect essential services.

Aug 6, 2026

75% of European businesses fear a US tech kill switch - American companies should, too

Latest news

A recent survey revealed that 75% of European businesses are concerned about their reliance on a few major technology providers, fearing they could be abruptly cut off from critical services. This dependency poses a significant risk, as it could leave companies vulnerable to disruptions in their operations. The article suggests that American businesses should be equally cautious, as the interconnectedness of the tech industry means that a 'kill switch' could impact them as well. The potential for a sudden loss of access to essential technology raises alarms about business continuity and the need for diversified tech partnerships. Companies are urged to reassess their vendor relationships to mitigate these risks.

Aug 6, 2026