Yanluowang Ransomware Initial Access Broker Pleads Guilty
Summary
Hide ▲
Show ▼
Aleksey Olegovich Volkov, a 26-year-old Russian national from St. Petersburg, was sentenced to 81 months in prison for his role as an initial access broker (IAB) facilitating ransomware attacks. Volkov pleaded guilty to multiple charges, including conspiracy to commit computer fraud and money laundering, and must pay at least $9.2 million in restitution to victims. Between July 2021 and November 2022, Volkov breached corporate networks and sold access to ransomware groups, including Yanluowang, resulting in extortion attempts totaling $24 million. He was arrested in Rome in 2024, extradited to the U.S. in 2025, and admitted to working with several major cybercrime groups. Yanluowang, a Russian ransomware operation unmasked in 2022, employed 'triple extortion' tactics and claimed victims such as Cisco and Walmart. Volkov’s activities as an IAB were part of a broader cybercrime supply chain, enabling multiple ransomware-as-a-service (RaaS) groups to accelerate attacks by purchasing network access. Investigators linked Volkov’s identity through digital evidence, including Apple iCloud data and cryptocurrency records, while chat logs and stolen data provided further confirmation of his involvement. His case highlights the interconnected nature of cybercriminal ecosystems, where access brokers, RaaS operators, and affiliates collaborate to maximize financial gain and operational efficiency.
Timeline
-
10.11.2025 21:12 2 articles · 4mo ago
Yanluowang Ransomware Initial Access Broker Pleads Guilty
Aleksey Olegovich Volkov was sentenced to 81 months in prison for his role as an initial access broker facilitating ransomware attacks, including those by the Yanluowang group. Additional charges include unlawful transfer of identification, trafficking in access information, access device fraud, and aggravated identity theft. Volkov pleaded guilty in multiple U.S. courts before case consolidation in Indiana, and must pay at least $9.2 million in restitution. Investigators linked his identity through digital evidence, including Apple iCloud data and cryptocurrency records, while chat logs and stolen data confirmed his involvement. Volkov was arrested in Rome in 2024 after indictment in 2023, extradited to the U.S. in 2025, and admitted to working with several major cybercrime groups beyond Yanluowang, enabling RaaS operations through access sales.
Show sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
Information Snippets
-
Aleksey Olegovich Volkov used aliases 'chubaka.kor' and 'nets' to facilitate ransomware attacks.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov breached networks and sold access to the Yanluowang ransomware group.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Ransom demands ranged from $300,000 to $15 million, with two victims paying a total of $1.5 million.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Investigators recovered chat logs, stolen data, and evidence of Yanluowang email accounts used for ransom negotiations.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov's identity was traced through Apple iCloud data, cryptocurrency exchange records, and social media accounts.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Chat logs showed Volkov negotiating with a co-conspirator known as 'CC-1' for a percentage of ransom payments.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Investigators found a screenshot of a chat between Volkov and a user named LockBit, suggesting a potential link to the LockBit ransomware gang.
First reported: 10.11.2025 21:122 sources, 3 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov is facing a maximum sentence of 53 years in prison for multiple charges related to the ransomware attacks.
First reported: 10.11.2025 21:121 source, 2 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov must pay over $9.1 million in restitution to the victims of the Yanluowang attacks.
First reported: 10.11.2025 21:122 sources, 2 articlesShow sources
- Yanluowang initial access broker pleaded guilty to ransomware attacks — www.bleepingcomputer.com — 10.11.2025 21:12
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
-
Russian national Aleksei Volkov, 26, of St. Petersburg, was sentenced to 81 months in prison in an Indiana court on March 23, 2026
First reported: 24.03.2026 12:321 source, 1 articleShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
-
Volkov pleaded guilty to additional charges including unlawful transfer of a means of identification, trafficking in access information, access device fraud, and aggravated identity theft
First reported: 24.03.2026 12:322 sources, 2 articlesShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Before consolidation, Volkov pleaded guilty in a Pennsylvania court to conspiracy to commit computer fraud and conspiracy to commit money laundering
First reported: 24.03.2026 12:322 sources, 2 articlesShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov and co-conspirators attempted to extort victims for a total of $24 million
First reported: 24.03.2026 12:322 sources, 2 articlesShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov was arrested in Rome in 2024 after being indicted in the U.S. in 2023, and extradited to the U.S. in 2025
First reported: 24.03.2026 12:321 source, 1 articleShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
-
Volkov must pay at least $9.2 million in restitution to known victims
First reported: 24.03.2026 12:322 sources, 2 articlesShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
- Yanluowang ransomware access broker gets 81 months in prison — www.bleepingcomputer.com — 24.03.2026 15:06
-
Volkov worked as an IAB for several major cybercrime groups beyond Yanluowang, including other RaaS operations
First reported: 24.03.2026 12:321 source, 1 articleShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
-
Yanluowang employed 'triple extortion' tactics involving data theft, encryption, and threats of DDoS attacks and employee/business partner harassment since 2021
First reported: 24.03.2026 12:321 source, 1 articleShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
-
Internal Yanluowang communications were leaked in 2022 by a whistleblower, revealing group members including 'Saint', 'Killanas (coder0)', 'Felix', and 'Shoker'
First reported: 24.03.2026 12:321 source, 1 articleShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
-
Yanluowang counted Cisco and Walmart among its victims
First reported: 24.03.2026 12:321 source, 1 articleShow sources
- Russian Initial Access Broker Handed 81-Month Sentence — www.infosecurity-magazine.com — 24.03.2026 12:32
Similar Happenings
Phobos Ransomware Suspect Arrested in Poland
Polish authorities have arrested a 47-year-old man suspected of ties to the Phobos ransomware group. The arrest is part of "Operation Aether," a broader international effort coordinated by Europol. The suspect was found with stolen credentials, credit card numbers, and server access data, which could facilitate ransomware attacks. The suspect faces charges under Article 269b of Poland's Criminal Code, with a maximum prison sentence of five years if found guilty. Operation Aether has targeted Phobos-linked individuals at multiple levels, including backend infrastructure operators and affiliates involved in network intrusions and data encryption. The operation has led to the extradition of a key Phobos administrator to the United States and the seizure of 27 servers in Thailand. A Russian national, Evgenii Ptitsyn, pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation. Ptitsyn was extradited from South Korea in November 2024 and is facing up to 20 years in prison. The Phobos ransomware gang has collected over $39 million from more than 1,000 victims worldwide.
Jordanian Cybercriminal Admits Selling Access to 50 Enterprise Networks
Feras Khalil Ahmad Albashiti, a 40-year-old Jordanian national residing in Georgia, pleaded guilty in a US court to selling unauthorized access to at least 50 compromised enterprise networks. The access was sold to an undercover agent on an underground cybercriminal forum. Albashiti, known online as 'r1z,' received payment in cryptocurrency. He faces up to 10 years in prison and a $250,000 fine, with sentencing scheduled for May 11, 2026. The Justice Department's Office of International Affairs secured Albashiti's extradition from Georgia in July 2024. Initial access brokers like Albashiti are critical middlemen in the cybercrime ecosystem, providing other threat actors with the credentials needed to breach victims' networks and drop malicious tools to steal data, deploy ransomware, or conduct espionage.
Black Basta Leader Identified and Added to Interpol's Red Notice List
Law enforcement in Ukraine and Germany have identified Oleg Evgenievich Nefedov, a 35-year-old Russian national, as the leader of the Black Basta ransomware gang. Nefedov, known by multiple aliases, has been added to Europol's 'Most Wanted' and Interpol's 'Red Notice' lists. Ukrainian police, in collaboration with German authorities, identified two additional individuals involved in initial network breaches and privilege escalation for ransomware attacks. These individuals were found to be 'hash crackers', specializing in extracting passwords from account databases. Raids in Ukraine seized digital storage devices and cryptocurrency assets. Black Basta has targeted over 500 companies globally and is estimated to have earned hundreds of millions of dollars in cryptocurrency. Nefedov is believed to have ties to Russian intelligence agencies and was arrested in Armenia but secured his freedom. The group's internal chat logs leaked, revealing its structure and key members, and its data leak site was taken down in February 2025. Former affiliates may have migrated to the CACTUS ransomware operation.
Ransomware extortion totals $2.1B from 2022 to 2024, FinCEN reports
FinCEN's report reveals that ransomware gangs extorted over $2.1 billion from 2022 to 2024, with a peak in 2023 followed by a decline in 2024 due to law enforcement actions against major gangs like ALPHV/BlackCat and LockBit. The report details 4,194 ransomware incidents, with manufacturing, financial services, and healthcare being the most targeted industries. The top ransomware families, including Akira, ALPHV/BlackCat, and LockBit, were responsible for the majority of attacks and ransom payments, with Bitcoin being the primary payment method. Recently, the U.S. Department of Justice charged Angelo Martino, a former DigitalMint employee, for his involvement in a scheme with the BlackCat (ALPHV) ransomware operation. Martino shared confidential information with BlackCat operators and was directly involved in ransomware attacks alongside accomplices Kevin Tyler Martin and Ryan Goldberg. The defendants operated as BlackCat affiliates, demanding ransom payments and threatening to leak data stolen from victims' networks.
Conti Ransomware Member Extradited from Ireland to US
Oleksii Oleksiyovych Lytvynenko, a 43-year-old Ukrainian national, has been extradited from Ireland to the United States and appeared in a Tennessee court on charges related to the Conti ransomware operation. He is accused of conspiring to deploy Conti ransomware, extorting over $500,000 in cryptocurrency from victims in the Middle District of Tennessee, and publishing stolen information. The Conti ransomware operation has been linked to over 1,000 victims worldwide, with ransom payments exceeding $150 million as of January 2022. Lytvynenko faces charges that could lead to 25 years in prison, including 20 years for wire fraud conspiracy and 5 years for computer fraud conspiracy. He was arrested in July 2023 by Irish authorities and detained until his extradition. The Conti group, initially a ransomware operation, evolved into a larger cybercrime syndicate, controlling multiple malware operations. After shutting down, its members have infiltrated other cybercrime groups. The FBI estimates Conti's malware was used in more critical infrastructure attacks than any other ransomware variant.