U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the Northern District of Texas.
- Primary Target Sector: Local Government, Healthcare, Manufacturing.
- Documented Financial Loss: $13.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Local Government, Healthcare, Manufacturing networks. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.
Operational & Financial Fallout
Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets. Impacted Local Government, Healthcare, Manufacturing infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Local Government, Healthcare, Manufacturing networks. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.
Adversary Kill Chain Flow
1 Documented PhasesPolyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.
Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets. Impacted Local Government, Healthcare, Manufacturing infrastructure and associated victim operations.
Procedural & Incident Timeline
DOJ unseals indictment against Polyanin and announces recovery of $6.1 million in extorted funds.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Yevgeniy Polyanin | Russian Federation | fugitive | Pending | $6.1 million | REvil affiliate indicted in N.D. Tex.; $6.1 million in ransom proceeds recovered by DOJ. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1486 | Data Encrypted for Impact Impact | "Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero." | Indictment ¶ 14, Page 7 | reviewed |