Ransomware Prosecution: Ransom Cartel Founder Maksim Silnikau Sentenced to 16 Years in Prison
Ransom Cartel Founder Sentenced to 16 Years for Building Ransomware Empire
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5, 2026, for creating and operating Ransom Cartel — a ransomware-as-a-service platform that targeted at least 18 companies across the United States and abroad.
The sentencing marks one of the stiffest penalties handed down in a U.S. ransomware prosecution and signals a sharpening federal resolve to pursue the architects of cybercrime infrastructure — not just the attackers who use it.
Who Is Maksim Silnikau and What Did He Build?
Silnikau, a 40-year-old Belarusian national, operated under the online handles "J.P. Morgan," "lansky" and "xxx." According to the Justice Department, he launched the operation in May 2021 and later rebranded it "Ransom Cartel" in late 2021 before actively promoting it on security news sites.
He did not conduct most of the intrusions himself. Instead, Silnikau constructed the business around them — developing locking software, purchasing stolen credentials from initial access brokers and maintaining a hidden affiliate panel where partners could monitor attacks, negotiate with victims and divide proceeds.
The operation functioned like a franchise. Silnikau ran a ratings system that rewarded high-performing affiliates and funneled ransom payments through cryptocurrency mixers to obscure the money trail. This model — where a central operator builds and maintains the infrastructure while affiliates carry out the attacks — is a hallmark of modern cybercrime-as-a-service operations, a growing threat that law enforcement agencies are only beginning to prosecute at scale.
A forum advertisement posted on May 4, 2021 to a Russian-language cybercrime forum captured the operation's cold commercial logic. The post sought access to corporate networks outside the Commonwealth of Independent States and set explicit financial thresholds: "Revenue: from $10 million. Prices from $100 and up."
Targeted companies were located in California, New York and Nebraska, with additional victims abroad. The last charged act in the Virginia case occurred on April 25, 2023, when Silnikau negotiated terms for supplying computers to be encrypted — just three months before his July 2023 arrest.
Poland extradited him to the United States in August 2024. Federal prosecutors in Virginia charged seven counts and secured convictions on three. The sentencing announcement includes no restitution or forfeiture figure and does not specify whether he pleaded guilty or was convicted at trial.
How the Affiliate Model Worked
The Ransom Cartel structure deserves closer examination because it illustrates how ransomware operations have evolved well beyond the image of a lone hacker. Silnikau's role was closer to that of a platform operator than an attacker. He:
- Developed and maintained the ransomware code
- Sourced stolen network credentials from initial access brokers
- Built and operated a private affiliate panel with attack monitoring tools
- Managed a performance ratings system to incentivize high-value affiliates
- Directed ransom proceeds through cryptocurrency mixers to layer and obscure the money trail
This division of labor is precisely what makes ransomware-as-a-service operations so difficult to dismantle. Removing one affiliate has little effect on the platform. Removing the platform operator — as this prosecution demonstrates — is where meaningful disruption occurs.
A Sentence That Resets the Benchmark
The 16-year term surpasses the previous high-water mark in ransomware sentencing. In 2024, Yaroslav Vasinskyi received 13 years and seven months for conducting more than 2,500 REvil attacks that generated over $700 million in ransom demands.
That comparison raises a question worth sitting with: if running the platform that enables attacks now draws a longer sentence than executing thousands of them, federal prosecutors appear to be sending a deliberate message about where they place culpability in the ransomware supply chain. The verdict suggests that building criminal infrastructure is now treated as seriously — if not more seriously — than exploiting it.
The REvil Connection
Cybersecurity researchers at Palo Alto Networks' Unit 42 first observed Ransom Cartel activity in mid-January 2022 — several months after prosecutors date the operation's launch to May 2021. The June 2023 federal indictment, unsealed in 2024, resolved the discrepancy by documenting that Silnikau ran the operation under a different name before the Ransom Cartel rebrand.
Unit 42's 2022 analysis found that Ransom Cartel's operators possessed the original REvil source code but apparently lacked the obfuscation engine that gang had used. Researchers speculated the groups were connected at some point but stopped short of calling Ransom Cartel a REvil rebrand. Neither the indictment nor the sentencing release mentions REvil.
What Remains Unresolved
The Virginia conviction closes only part of the legal picture. A second federal prosecution in New Jersey remains unresolved and names two co-defendants — Volodymyr Kadariya and Andrei Tarasov — who remain at large.
That case centres on the Angler Exploit Kit malvertising scheme, which prosecutors say ran from 2013 to 2022. The Virginia sentencing announcement makes no mention of it.
The U.S. Secret Service still lists Tarasov as a wanted fugitive. The State Department is offering up to $2.5 million for information leading to Kadariya's arrest or conviction.
The outcome leaves a familiar gap in high-profile cybercrime cases: one architect is behind bars while his alleged co-conspirators remain beyond reach. Whether the New Jersey prosecution advances — and when — will determine how complete this chapter of the Ransom Cartel story ultimately becomes.
What This Means for Organisations Right Now
The Silnikau sentencing arrives as law enforcement agencies across the United States and Europe continue pressing ransomware cases with greater coordination and longer timelines. Building the infrastructure that enables attacks, the verdict suggests, now carries consequences as serious as launching them.
For organisations, the enforcement trend is encouraging — but it does not reduce the immediate threat. Ransom Cartel's model relied heavily on purchased credentials from initial access brokers, making strong identity management, multi-factor authentication and dark web credential monitoring concrete defensive priorities rather than abstract best practices.
The absence of a restitution figure in the sentencing announcement also underscores that criminal conviction does not automatically produce financial recovery for victims. Understanding how to respond effectively to a ransomware attack — and having a tested incident response plan in place before one occurs — remains as important as any enforcement outcome. Organisations should treat cyber insurance and incident response planning as essential rather than optional.
The State Department's $2.5 million bounty for Kadariya's whereabouts reflects a growing use of financial incentives to pursue cybercriminals in jurisdictions where formal extradition is difficult — a tool worth tracking as ransomware enforcement continues to evolve.