Cybercrime

Russian Hacker With $10 Million Bounty on His Head Reportedly Arrested

Russian authorities have reportedly arrested Mikhail Matveev, who is wanted by the US for ransomware attacks against critical infrastructure.

Hacker arrested

Russian authorities have reportedly arrested Mikhail Pavlovich Matveev, a 32-year-old man from Russia who is wanted by the United States over his alleged role in ransomware attacks.

Russian state-owned news agency RIA Novosti reported last week that local prosecutors had announced charges against a man accused of creating a malicious program, specifically one designed to encrypt the data of commercial organizations. 

RIA Novosti learned from sources that the suspect is Mikhail Pavlovich Matveev [Russian language article].

Matveev has been known online as Wazawaka, m1x, Boriselcin, and Uhodiransomwar. Cybersecurity blogger Brian Krebs revealed that Wazawaka was Matveev in early 2022, which the man later confirmed to be accurate.

The FBI added him to its most wanted list in May 2023. The US Justice Department at the time announced charges against Matveev over his alleged role in LockBit, Hive and Babuk ransomware attacks. 

He is believed to have been involved in ransomware attacks aimed at thousands of entities in the US and elsewhere, including critical infrastructure organizations such as hospitals, airlines, and government organizations.  

Advertisement. Scroll to continue reading.

Also in May 2023, the US Treasury Department announced sanctions against the Russian national and the Department of State announced a bounty of up to $10 million for information leading to Matveev’s arrest.

It appears that the Russian government has started cracking down on local cybercriminals. A Russian news agency reported last month that a court had sentenced four members of the  REvil ransomware group to prison. 

Related: Russian National Arrested, Charged in US Over Role in LockBit Ransomware Attacks

Related: US Announces Charges, Sanctions Against Russian Administrator of Carding Website

Related: Russian Phobos Ransomware Operator Extradited to US

Related: Russia Arrests 96 People Tied to US-Disrupted Cryptocurrency Exchanges

Related Content

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Data Breaches

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.

Data Breaches

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version