Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler
A Zurich court has sentenced a 52-year-old Ukrainian man to 12 years and nine months in prison for developing the LockerGoga, MegaCortex and Nefilim ransomware strains used in attacks on companies including Swiss train maker Stadler Rail. The court found he wrote the malicious code but was not the mastermind behind the wider criminal operations, and it also imposed a ten-year ban from Switzerland. The case is significant as one of the few instances where an alleged ransomware developer has faced trial and sentencing, while the suspected ringleader remains at large.
The man had been in pretrial detention since October 2021 and denied knowing his software was used criminally, claiming the code found at his Basel-Landschaft home came from IT security consulting work; the court rejected this after extortion messages were also found in his data. He was also found guilty over attacks on Stadler Rail in May 2020 (a $6 million Nefilim ransom demand), HVAC firm Meier Tobler and software company Crealogix. Prosecutors previously linked the wider operation to attacks on more than 1,800 victims across 71 countries, with losses estimated at several hundred million Swiss francs. Alleged ringleader Volodymyr Tymoshchuk, indicted in the US last year and blamed for attacks on at least 250 companies including Norsk Hydro, remains uncaught and carries an $11 million FBI bounty. The verdict is not final and may be appealed.
- Swiss court jails Ukrainian ransomware coder for nearly 13 years
- He wrote LockerGoga, MegaCortex and Nefilim, but wasn't the ringleader
- Alleged mastermind Tymoshchuk still at large, $11m FBI bounty offered