A Ukrainian hacker was convicted in Switzerland for ransomware attacks
A Ukrainian IT specialist was sentenced in Zurich to 12 years and nine months in prison for participating in cyberattacks involving ransomware. The court also banned him from entering Switzerland for 10 years.
The Zurich District Court handed down the sentence on Thursday. The court imposed a harsher sentence than the prosecution had sought; prosecutors had requested 12 years in prison for the 52-year-old man.
The IT specialist lived in the canton of Basel-Land and had been in pretrial detention since October 2021.
The court found that the defendant played a key role in cyberattacks on the companies Stadler Rail, Meier Tobler, and Crealogix, which were carried out for the purpose of extorting ransom.
According to the case file, the Ukrainian national was the primary developer of the malware programs Lockergoga, Megacortex, and Nefilim. These programs were used to encrypt data belonging to the companies that fell victim to the attacks, after which the attackers demanded money from them.
During the attack on Stadler Rail, approximately 500 gigabytes of confidential information were stolen. The attackers threatened to publish this data online.
Stadler Rail refused to pay the ransom. At the same time, according to court records, other companies agreed to the attackers’ demands.
The total losses from the attacks are estimated at approximately 100 million Swiss francs, or about 123 million U.S. dollars.
However, the judge emphasized that the Ukrainian national was not the organizer of the cyberattacks.
According to the court’s findings, he developed the malicious software and passed it on to unknown organizers, who subsequently selected targets in Switzerland and other countries on their own and coordinated the ransom demands.
Thus, the court found him involved in large-scale cybercriminal activity but did not identify him as the direct leader of the operations.
The defendant consistently maintained that he was unaware of the criminal use of the programs he had developed.
According to him, he allegedly worked as a consultant for an unknown client in the field of IT security. This was his explanation for the presence of the source code for the malicious software at his home.
However, the court did not accept this explanation. Among the defendant’s digital data, the court also discovered messages related to ransom demands, which, in the court’s view, contradicted his account of his work as a consultant.
The Zurich District Court’s decision is not yet final. The verdict may be appealed in accordance with the law.
Thus, the Ukrainian IT specialist was sentenced to 12 years and nine months in prison and a 10-year ban on entering Switzerland for his involvement in the development of ransomware used in attacks on companies in Switzerland and abroad.
This was reported by Swissinfo.
As a reminder, in Berlin, Germany, the Rhysida hacker group published approximately 1.4 million records from the city administration’s systems on the dark web following a failed extortion attempt. The attackers demanded 30 bitcoins—approximately €2 million—from city officials, but Berlin refused to pay.
An unknown hacker stole about 4,000 bitcoins worth approximately $340 million from a Liquid Network wallet but later returned most of the assets. Liquid Network suspended operations until the incident was resolved.