Armenia has detained a Russian tourist, Aleksandr Ermakov, at Yerevan’s Zvartnots airport on June 28, 2026, based on a U.S. extradition warrant for a REvil ransomware suspect with the same name. The detained individual’s lawyers assert that the U.S. has the wrong man, as the wanted suspect is Aleksandr Gennadievich Ermakov, sanctioned by Australia, the U.S., and the UK in January 2024 for the Medibank Private data breach involving 9.7 million records. The wanted Ermakov is also serving a two-year sentence in Russia under Article 273(2) for co-writing the SugarLocker ransomware and is prohibited from leaving the country.
The detained man, identified as Aleksandr Yuryevich Ermakov from Omsk, is a former prison-service lawyer who does not speak English. His lawyers argue that the U.S. warrant likely lacked a patronymic, leading to an automated match error. The U.S. charging document accuses the wanted Ermakov of participating in Sodinokibi/REvil attacks from April 2019 to July 2021, affecting over 1,000 victims, including private companies, law enforcement, and government entities in the Northern District of Texas. An Interpol notice further alleges he was a platform administrator with a take of over $13.7 million.
The case highlights the complexity of international cybercrime investigations, with the U.S. Department of Justice yet to announce charges, and Armenian authorities remaining silent. The detained man is held under a 30-day Interpol detention order while Russia seeks consular access. The article also details the investigative chain linking the sanctioned Ermakov to the SugarLocker ransomware through Operation Aquila by Australia’s signals directorate and federal police, and Intel 471’s analysis of forum data revealing handles like SHTAZI, shtaziIT, and JimJones.
Attack groups: REvil, Sodinokibi
Malware: SugarLocker
Companies: Intel 471, Medibank Private
Events: Operation Aquila
Original source: thehackernews.com