Ransom Cartel Boss Gets 16 Years After $6.7M Extortion Spree

Belarusian national Maksim Silnikau built and ran the ransomware crew from 2021 to 2023, hitting at least 18 companies before Spanish police caught him and Poland handed him over.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A serious courtroom or official government setting with European architecture visible through windows, papers and case files spread across a wooden table, stern
Share

Key points

  • Maksim Silnikau, 40, a Belarusian national, was sentenced on Wednesday to 16 years in federal prison for running the Ransom Cartel ransomware operation.
  • The US Department of Justice says Silnikau built the crew in May 2021 and hit at least 18 companies across California, New York, Nebraska and abroad through 2023.
  • Prosecutors put attempted extortion at $5.2 million and confirmed victim losses at more than $6.7 million.
  • Silnikau was first arrested in Spain on 18 July 2023, fled while awaiting extradition, and was recaptured trying to cross from Poland into Belarus.
  • Ransom Cartel's code overlapped with the older REvil ransomware, suggesting a former REvil insider built it without the full source code.

The man who built Ransom Cartel is going to federal prison for 16 years. A judge in the Eastern District of Virginia handed down the sentence on Wednesday.

Maksim Silnikau, 40, ran what prosecutors call a ransomware-as-a-service operation: a criminal business that locks a company's files with encryption software, then demands payment for the key, while also threatening to publish stolen data if victims refuse to pay.

Who is Maksim Silnikau?

A Belarusian citizen who spent nearly two decades on Russian-language crime forums under the handles "J.P. Morgan," "xxx," and "lansky." The US Department of Justice says he'd been active on those forums since at least 2005 and belonged to the closed "Direct Connection" forum from 2011 until police shut it down in 2016.

He pleaded guilty to conspiracy to commit offences against the United States, conspiracy to commit wire fraud, and aggravated identity theft.

What did Ransom Cartel actually do?

It broke into companies, encrypted files, stole data and demanded payment. Silnikau launched the brand publicly in December 2021 and recruited helpers, called affiliates, through underground forums. He gave them stolen credentials, the encryption software, and a private website to coordinate attacks and split ransoms.

Between 2021 and 2023, affiliates hit at least 18 companies in California, New York, Nebraska and several other countries. The operation attempted to squeeze $5.2 million from victims; confirmed losses across those 18 known victims topped $6.7 million. Prosecutors say the real figure is higher because some victims never reported the attacks.

Two cases stand out. An August 2022 attack shut down a medical technology startup developing robotic surgical tools for two months. A May 2023 attack on infrastructure shared by a group of law firms caused disruptions ranging from days to months: one firm paid $125,000 after nearly a month offline, another paid $300,000 after a similar stretch of downtime. Combined losses in those law firm attacks reached about $2.2 million.

Fact Detail
Sentence 16 years
Victims (confirmed) 18 companies
Attempted extortion $5.2 million
Confirmed losses $6.7 million+
Active period May 2021 to 2023
First arrest 18 July 2023, Spain

Was this a rebrand of REvil?

Probably a spin-off. Researchers who examined the code found it shared chunks with REvil, a notorious Russian-speaking ransomware crew that collapsed in 2021. But Ransom Cartel lacked some of REvil's obfuscation features, the tricks that hide malware from antivirus tools. That gap suggested someone built it from a partial copy, not the full codebase. We covered REvil's ongoing legal trail in our 17 July story on an arrest at Yerevan Airport.

Silnikau sat at the centre of the business. He recruited affiliates, worked with access brokers who sold footholds in corporate networks, handled ransom negotiations, and routed payments through cryptocurrency mixers, services that shuffle coins across wallets to obscure the trail.

How was he caught?

Spanish police arrested him on 18 July 2023 in a coordinated international operation. He then fled before extradition could be arranged. Polish officers grabbed him as he tried to cross into Belarus. He eventually consented to extradition and was flown to Virginia.

The sentence is stiff by any measure, but it's worth watching whether it deters the affiliate model itself. Silnikau ran the infrastructure; the people who actually broke into those 18 companies haven't all been named.

© 2026 Threat Vectr