The Ransom Cartel Boss Got 16 Years — His Business Model Didn’t
A US court has handed Maksim Silnikau, the Belarusian who built the Ransom Cartel ransomware operation, a 16-year prison sentence. As BleepingComputer and the US Department of Justice report, his crew hit at least 18 companies between 2021 and 2023 and racked up more than US$6.7 million in losses. That’s a genuine win. But read the court file closely and the more useful story is how he actually worked.
Silnikau didn’t personally break into most of those businesses. He ran the operation like a franchise: he bought network access from “initial access brokers”, handed affiliates stolen credentials and ready-made encryption tools, ran a panel where they negotiated ransoms, and laundered the payouts through crypto mixers. That’s ransomware-as-a-service, and it’s exactly why jailing one operator doesn’t switch the threat off. The supply chain he plugged into is still open for business, and someone else has already taken his seat.
Here’s the pattern we keep seeing in Australian client environments, and it’s the same one this case lays bare: nearly every ransomware hit starts with a stolen login, not a Hollywood-style hack. Look at the stories we’ve covered this month alone — credentials lifted off SonicWall VPNs, fake IT-support calls on Microsoft Teams, harvested Microsoft 365 passwords. Those aren’t separate scares. They’re the front end of the same machine Silnikau monetised. And the victims named in his case — a medical-tech startup, a cluster of law firms knocked offline for the better part of a month — look a lot like the mid-sized practices we support across the Central West and the Northern Beaches. High-value data, leaner security teams. That’s the exact profile brokers like to sell.
You can’t arrest your way out of this, but you can shut the door the brokers walk through. Turn on phishing-resistant MFA everywhere, disable unused VPN and admin accounts, patch internet-facing gear on a schedule, and make sure someone is genuinely watching the logs. If you’re not sure which of those boxes are ticked, that’s a fair question to put to your IT provider. Our cybersecurity team can run that check with you and tell you where the gaps are.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
