Seven Russian cyber criminals have been sanctioned by the UK and the US governments in the first wave of new coordinated action against international cyber crime.
The individuals sanctioned have been associated with the development or deployment of a range of ransomware strains which have targeted the UK and US.
Assests have been frozen and travel bans imposed for the seven Russian nationals affected.
Foreign Secretary James Cleverly said: “By sanctioning these cyber criminals, we are sending a clear signal to them and others involved in ransomware that they will be held to account.
“These cynical cyber attacks cause real damage to people’s lives and livelihoods. We will always put our national security first by protecting the UK and our allies from serious organised crime – whatever its form and wherever it originates.”
Ransomware criminals have traditioanlly struck at organisations and businesses where they feel they can either make the most money or do the most damage – recent attacks have been UK schools, local authorities and firms.
Internationally, ransomware attacks have targeted the Irish Health service executive, the Costa Rican government and American healthcare providers.
Ransomware groups known as Conti, Wizard Spider, UNC1878, Gold Blackburn, Trickman and Trickbot have been responsible for the development and deployment of: Trickbot, Anchor, BazarLoader, BazarBackdoor as well as the ransomware strains Conti and Diavol. They are also involved in the deployment of Ryuk ransomware.
Collectively, Conti and Ryuk have affected 149 UK individuals and businesses, and were responsible for extricating at least about £27 million. Conti racked up £10m from 104 victims, while Ryuk had 45 victims paying about £17m in total.
Conti was behind attacks targeting hospitals, schools, businesses and local authorities, including the Scottish Environment Protection Agency – the group extorted about £149m in ransomware in 2021 alone according to Chainalysis.
One of the first cyber crime groups to back Russia’s war in Ukraine, Conti voiced their support within 24 hours of the invasion.
Although the ransomware group responsible for Conti disbanded in 2022, reporting suggests that members of the group continue to be involved in some of the most notorious new ransomware strains that dominate and threaten UK security.
Security Minister Tom Tugendhat said: “We’re targeting cyber criminals who have been involved in some of the most prolific and damaging forms of ransomware. Ransomware criminals have hit hospitals and schools, hurt many and disrupted lives, at great expense to the taxpayer.
“Cyber crime knows no boundaries and threatens our national security. These sanctions identify and expose those responsible.”
These sanctions follow a complex, large-scale and ongoing investigation led by the NCA, which will continue to pursue all investigative lines of enquiry to disrupt the ransomware threat to the UK in collaboration with partners.
“The sanctions are the first of their kind for the UK and signal the continuing campaign targeting those responsible for some of the most sophisticated and damaging ransomware that has impacted the UK and our allies,” National Crime Agency Director-General Graeme Biggar said.
“They show that these criminals and those that support them are not immune to UK action, and this is just one tool we will use to crack down on this threat and protect the public.”
In the National Cyber Security Centre‘s (NCSC) assessment, they found it was almost certain that the Conti group were primarily financially motivated and chose targets based on their perceived monetary value.
They also found that the key group members are very likely to be maintaining links to the Russian Intelligence Services, from whom they have likely received tasks. Furthermore, the targeting of certain organisations, like the International Olympic Committee, by the group almost certainly aligns with Russian state objectives.
Additionally, it is highly likely that the group evolved from previous cyber organised crime groups and have extensive links to other cyber criminals, notably EvilCorp and those responsible for Ryuk ransomware.
Recommended
- Lessons from CivTech7: Innovation is No Luxury
- Tech Nation: Scottish Early Stage Scaleups Among Winners in 2023
- DIGIT Movers and Shakers | January 2023
“Ransomware is the most acute cyber threat facing the UK, and attacks by criminal groups show just how devastating its impact can be,” NCSC Chief Executive Officer Lindy Cameron said.
“The NCSCÂ is working with partners to bear down on ransomware attacks and those responsible, helping to prevent incidents and improve our collective resilience.
“It is vital organisations take immediate steps to limit their risk by following the NCSC’s advice on how to put robust defences in place to protect their networks.”
The individuals sanctioned are :
- Vitaliy Kovalev
- Valery Sedletski
- Valentin Karyagin
- Maksim Mikhailov
- Dmitry Pleshevskiy
- Mikhail Iskritskiy
- Ivan Vakhromeyev
Making funds available to these individuals is prohibited – this includes paying ransomware in any form, including crypto assets.
Organisations are advised to put in place robust cyber security and incident management systems to prevent and manage serious cyber incidents.
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





