Cybercrime

US Prisons Russian Access Broker for Aiding Ransomware Attacks

Aleksei Volkov has been sentenced to 81 months in prison for his role in Yanluowang ransomware attacks. 

Hacker

The US Justice Department announced this week that Russian national Aleksei Volkov has been sentenced to 81 months in prison for his role in ransomware attacks. 

Volkov, 26, has been accused of taking part in Yanluowang ransomware attacks that caused more than $9 million in losses — the cybercriminals attempted to extort $24 million in ransom from targeted organizations, the DOJ said.

The man served as an initial access broker for the operation, gaining access to the targeted organizations’ systems and then handing over that access to other members of the operation, who specialized in malware deployment and data theft.

Following his indictment, Volkov was arrested by Italian police in Rome and later extradited to the US to stand trial.

Advertisement. Scroll to continue reading.

The hacker pleaded guilty in November 2025, admitting that he and his co-conspirators hacked into company networks, stole data, deployed ransomware, and demanded a ransom payment. 

In addition to the prison sentence, the Russian national has agreed to pay more than $9 million in restitution to victims. 

The Yanluowang ransomware group was active in 2021 and 2022. It made headlines in late 2021 for targeting financial corporations and other types of organizations in the United States. 

One of the cybercrime gang’s most notable attacks was against Cisco. Information shared by the networking giant in mid-2022 attributed the attack to an initial access broker with ties to the Russia-linked threat actor UNC2447 and to Lapsus$.

Related: Russian Ransomware Operator Pleads Guilty in US

Related: Dutch Port Hacker Sentenced to Prison

Related: 3 Men Charged With Conspiring to Smuggle US Artificial Intelligence to China

Related Content

Ransomware

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Ransomware

The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password.

Ransomware

Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.

Cyberwarfare

Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key...

Cyberwarfare

The speech is the latest in a string of warnings from intelligence experts that Russia is stepping up hostile activity in a “gray zone”...

Cybercrime

Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.

Cybercrime

The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version