惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
V
Visual Studio Blog
C
Check Point Blog
阮一峰的网络日志
阮一峰的网络日志
U
Unit 42
量子位
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
M
MIT News - Artificial intelligence
爱范儿
爱范儿
B
Blog RSS Feed
MyScale Blog
MyScale Blog
H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
美团技术团队
L
LangChain Blog
D
Docker

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
Russian initial access broker jailed for 81 months in US
2026-03-24 · via The Register - Security: Cyber-crime

Cyber-crime

Russian initial access broker who fed ransomware crews gets 81 months in US prison

Aleksei Volkov sentenced after enabling attacks that cost victims millions

A Russian national who sold the keys to corporate networks faces nearly seven years in a US prison after prosecutors tied his handiwork to a string of ransomware attacks costing victims millions of dollars.

Aleksei Volkov, 26, was sentenced to 81 months behind bars for his role as an initial access broker, a behind-the-scenes operator who breaks into company systems then sells that foothold to other criminals. He was extradited from Italy to the US to face the charges, part of a broader push by authorities to pursue enablers of cybercrime rather than just the crews that carry out the attacks.

Prosecutors say Volkov broke into company networks and sold that access on criminal forums, effectively handing over ready-made entry points to ransomware groups and other extortion outfits. One of those buyers was the Yanluowang gang, which used the footholds to launch attacks against organizations in the US and elsewhere.

REG AD

The activity affected multiple victims. Court filings say Volkov helped enable intrusions into at least seven US organizations, with ransomware crews moving in after access had been secured. By that stage, the hardest part of the job – getting inside – was already achieved.

REG AD

Case documents lay out how the business operated. Volkov obtained and sold access to compromised networks, sometimes charging a flat fee and other times taking a cut of any ransom paid. In one instance, he received roughly 20 percent of a $500,000 payout; in another, about 16 percent of a $1 million ransom.

Prosecutors say the attacks tied to his activity resulted in around $9 million in actual losses and more than $24 million in intended losses.

In November 2025, Volkov pleaded guilty to charges including conspiracy to commit computer fraud, bringing the case to a close after months of proceedings. As part of his sentence, he has also been ordered to pay restitution to victims.

The case is another example of how the ransomware economy now runs on specialization. Volkov's role was to obtain access and sell it on, leaving others to handle the encryption, data theft, and negotiations. He never deployed malware himself, but made sure others didn't have to start from scratch.

Volkov may have kept his distance from the actual attacks, but not far enough to escape the fallout. ®