Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actionvendor-distribution-compromisethird-party-vendor-breach

DOJ Charges REvil Operators Over Kaseya Supply-Chain Ransomware Attack

Updated 28d agoFirst seen May 25, 20264 sources

U.S. authorities charged alleged Sodinokibi/REvil operators Yaroslav Vasinskyi of Ukraine and Yevgeniy Polyanin of Russia over ransomware attacks that included the compromise of Kaseya's remote management software, an intrusion that cascaded to managed service providers and their customers worldwide. The Kaseya incident was reported to have affected as many as 1,500 organizations, with attackers allegedly encrypting systems, leaving ransom notes, and directing victims to Tor-based or public payment sites to obtain decryption keys; victims that did not pay were allegedly threatened with the publication or sale of stolen data.

The Justice Department said Vasinskyi was arrested in Poland, later extradited to the United States, and arraigned in Texas on charges including conspiracy to commit computer fraud, damage to protected computers, and money laundering conspiracy. In parallel, U.S. authorities seized $6.1 million in alleged ransom proceeds tied to Polyanin, part of a broader multinational enforcement effort involving the FBI, Europol, Eurojust, and law enforcement partners across Europe and other allied countries to disrupt the REvil ransomware operation linked to the Kaseya attack.

Share:
DOJ Charges REvil Operators Over Kaseya Supply-Chain Ransomware Attack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 9, 20224y ago

Vasinskyi appears in Texas court on Kaseya-linked charges

On 2022-03-09, the DOJ announced that Vasinskyi had appeared in the Northern District of Texas to face charges including conspiracy to commit computer fraud, damage to protected computers, and money laundering conspiracy. Prosecutors said he was tied to multiple ransomware incidents, including the Kaseya attack.

Mar 3, 20224y ago

Vasinskyi is extradited to the United States

On 2022-03-03, Vasinskyi was transported to Dallas after being extradited from Poland to face U.S. charges related to REvil ransomware attacks, including the July 2021 Kaseya attack. The extradition followed international law enforcement cooperation.

Nov 8, 20215y ago

DOJ charges REvil suspects and seizes $6.1 million

On 2021-11-08, the U.S. Department of Justice announced charges against Yaroslav Vasinskyi and Yevgeniy Polyanin for REvil ransomware activity tied to attacks on U.S. businesses and government entities, including Kaseya. The DOJ also announced the seizure of $6.1 million allegedly traceable to ransom payments received by Polyanin.

Oct 8, 20215y ago

Polish authorities arrest Yaroslav Vasinskyi

On 2021-10-08, alleged REvil affiliate Yaroslav Vasinskyi was arrested in Poland in connection with multiple ransomware attacks, including the Kaseya incident. He remained in custody pending extradition to the United States.

Jul 6, 20215y ago

Reports say up to 1,500 organizations were compromised

By July 6, 2021, reporting indicated that the Kaseya ransomware attack had affected as many as 1,500 organizations. This marked a major escalation in the understood scale of the incident.

Jul 2, 20215y ago

REvil exploits Kaseya software in global ransomware attack

In July 2021, attackers linked to the Sodinokibi/REvil ransomware operation used a Kaseya product to spread ransomware to customer endpoints and encrypt data at organizations worldwide. The attack became one of the incidents later cited in U.S. criminal charges against alleged REvil operators.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

DOJ Charges REvil Operators Over Kaseya Supply-Chain Ransomware Attack | Mallory