VYPR
breachPublished Sep 15, 2026· 1 source

Ukrainian Ransomware Developer Sentenced to Nearly 13 Years in Swiss Prison

A Swiss court has sentenced a Ukrainian national to nearly 13 years in prison for developing and distributing the LockerGoga, MegaCortex, and Nefilim ransomware strains.

A Swiss court has handed down a significant prison sentence of 12 years and nine months to a 52-year-old Ukrainian man for his role in developing and distributing multiple ransomware families, including LockerGoga, MegaCortex, and Nefilim. The Zurich District Court found the man guilty of developing the malicious code but determined he was not the primary architect of the ransomware operations. In addition to the prison term, he has been issued a ten-year ban from Switzerland. The judgment is subject to appeal.

The convicted developer had been held in pretrial detention since October 2021 and consistently maintained his innocence, claiming the source code found at his residence was solely for consulting work for an unnamed IT security client. However, the court dismissed this defense, citing the discovery of extortion messages among his digital data as evidence of his involvement in criminal activities.

The court's ruling also implicated the developer in several high-profile ransomware attacks. Notably, he was found to have played a crucial part in the May 2020 attack on Stadler Rail, a rolling stock manufacturer. While Stadler Rail did not initially label the incident as ransomware, they confirmed it involved malware, a likely data leak, and an extortion attempt with a significant ransom demand, reportedly $6 million from the Nefilim operation.

Beyond the Stadler Rail incident, the developer was also found to be instrumental in attacks targeting Meier Tobler, an HVAC company, and Crealogix, a software firm. These attacks, orchestrated by the ransomware families he helped create, had a widespread impact.

Zurich prosecutors revealed in September 2022 that the suspect's arrest in October 2021 was part of a broader investigation into money laundering and data corruption. The investigation linked the ransomware operations to attacks on over 1,800 entities across 71 countries, resulting in estimated financial losses amounting to several hundred million Swiss francs.

This case highlights the global reach and devastating financial consequences of ransomware operations. While this developer has been brought to justice in Switzerland, the broader landscape of ransomware continues to be a significant threat, with other key figures, such as Volodymyr Tymoshchuk, indicted in the US and still at large, underscoring the ongoing challenges in dismantling these cybercriminal enterprises.

The sentencing serves as a stark reminder of the legal repercussions faced by individuals involved in developing and deploying ransomware, even if they claim a peripheral role. The court's decision to reject the 'consulting work' defense and focus on the presence of extortionate materials demonstrates a firm stance against cybercrime.

Synthesized by Vypr AI