Apr 06, 2026 • Bill Toulas
German authorities identify REvil and GandCrab ransomware bosses
German Federal Police (BKA) have identified two Russian nationals as leaders of the REvil and GandCrab ransomware operations spanning 2019-2021. These...
Executive Summary
German Federal Police (BKA) have identified two Russian nationals as leaders of the REvil and GandCrab ransomware operations spanning 2019-2021. These ransomware-as-a-service (RaaS) groups targeted organizations worldwide, extorting millions from victims. REvil, also known as Sodinokibi, was responsible for high-profile attacks including the Kaseya supply chain incident. GandCrab was one of the most prolific ransomware families before its operators announced retirement. This attribution represents a significant law enforcement achievement, demonstrating increased international cooperation in holding ransomware operators accountable despite jurisdictional challenges with Russian-based threat actors.
Summary
The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. [...]
Published Analysis
German Federal Police (BKA) have identified two Russian nationals as leaders of the REvil and GandCrab ransomware operations spanning 2019-2021. These ransomware-as-a-service (RaaS) groups targeted organizations worldwide, extorting millions from victims. REvil, also known as Sodinokibi, was responsible for high-profile attacks including the Kaseya supply chain incident. GandCrab was one of the most prolific ransomware families before its operators announced retirement. This attribution represents a significant law enforcement achievement, demonstrating increased international cooperation in holding ransomware operators accountable despite jurisdictional challenges with Russian-based threat actors. The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. [...] The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. [...]
Linked Entities
- GandCrab
- REvil
- GandCrab
- REvil