2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

U.S. Imprisons Russian Initial-Access Broker for 6.75 Years After Ransomware Campaigns Caused Millions in Losses


A federal court has handed a 26-year-old Russian national an 81-month prison sentence for his involvement in supplying access to networks later used in ransomware attacks. The U.S. Department of Justice says Aleksei Olegovich Volkov played a central role in multiple intrusions that targeted U.S. businesses and other entities, producing more than $9 million in confirmed losses and over $24 million in projected losses.

Volkov was taken into custody in Italy on January 18, 2024 and was subsequently extradited to face U.S. charges. According to court records, he admitted guilt in November 2025. Prosecutors describe him as an initial access broker who secured unauthorized entry into computer systems-by exploiting software flaws or otherwise gaining illicit network entry-and then sold those footholds to criminal partners, including ransomware operators such as the Yanluowang group.

Once Volkov’s customers obtained the purchased access, the DoJ says they deployed malware that encrypted victims’ files, disrupted operations and prevented organizations from accessing critical data. The attackers then demanded cryptocurrency ransoms-occasionally seeking sums that reached into the tens of millions-in return for decryption tools and promises not to publish or leak stolen information on extortion “leak” sites. When victims paid, Volkov received a portion of the proceeds.

His criminal indictment contained multiple charges: unlawful transfer of a means of identification, trafficking in access information, access device fraud, aggravated identity theft, two counts of computer fraud, and conspiracy to commit money laundering. Under the terms of his guilty plea, Volkov agreed to make full restitution to victims, including at least $9,167,198 to known victims for their documented losses, and to forfeit the software and other tools used to carry out the offenses.

The Volkov case arrives alongside other enforcement moves targeting ransomware facilitators. U.S. prosecutors have also charged a third individual accused of serving as a negotiator for the BlackCat/ALPHV ransomware operation, allegedly pushing victims toward larger payouts. The suspect, identified as 41-year-old Angelo Martino (previously referenced in filings as “Co-Conspirator 1”), reportedly worked as a ransom negotiator through a firm called DigitalMint and is accused of helping extract increased payments from at least 10 victims.

Investigators say they seized roughly $9.2 million held across 21 cryptocurrency wallets in five different coins-Bitcoin, Monero, Ripple, Solana and Stellar-as well as luxury cars and real estate linked to Martino. He faces a potential sentence of up to 20 years in prison. Two other individuals tied to incident response and affiliated with BlackCat, Ryan Clifford Goldberg and Kevin Tyler Martin, entered guilty pleas in December 2025 for their roles.

First published on March 24, 2026.
Last updated on April 24, 2026.