← Back to BrewedIntel
malwaremediumCybercrime AttributionRansomwareGandCrabREvil

Apr 06, 2026 • Bill Toulas

German authorities identify REvil and GandCrab ransomware bosses

German Federal Police (BKA) have identified two Russian nationals as leaders of the REvil and GandCrab ransomware operations spanning 2019-2021. These...

Source
Bleeping Computer
Category
malware
Severity
medium

Executive Summary

German Federal Police (BKA) have identified two Russian nationals as leaders of the REvil and GandCrab ransomware operations spanning 2019-2021. These ransomware-as-a-service (RaaS) groups targeted organizations worldwide, extorting millions from victims. REvil, also known as Sodinokibi, was responsible for high-profile attacks including the Kaseya supply chain incident. GandCrab was one of the most prolific ransomware families before its operators announced retirement. This attribution represents a significant law enforcement achievement, demonstrating increased international cooperation in holding ransomware operators accountable despite jurisdictional challenges with Russian-based threat actors.

Summary

The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. [...]

Published Analysis

German Federal Police (BKA) have identified two Russian nationals as leaders of the REvil and GandCrab ransomware operations spanning 2019-2021. These ransomware-as-a-service (RaaS) groups targeted organizations worldwide, extorting millions from victims. REvil, also known as Sodinokibi, was responsible for high-profile attacks including the Kaseya supply chain incident. GandCrab was one of the most prolific ransomware families before its operators announced retirement. This attribution represents a significant law enforcement achievement, demonstrating increased international cooperation in holding ransomware operators accountable despite jurisdictional challenges with Russian-based threat actors. The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. [...] The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. [...]

Linked Entities

  • GandCrab
  • REvil
  • GandCrab
  • REvil