US, UK, AU Officials Sanction 33-Year-Old Russian Medibank Hacker

A Russian national has been identified and sanctioned by Australia, the United Kingdom, and the United States for his role in the data breach of an Australian health insurance giant.
Aleksandr Gennadievich Ermakov, born May 16, 1990, is a former member of the bygone REvil ransomware gang.
Online, he goes by various monikers: GustaveDore, aiiis ermak, blade runner, and JimJones.
According to authorities, he is responsible for quarterbacking an October 2022 breach of Medibank, a $10 billion Melbourne-based insurer with nearly 4 million existing customers.
In that incident, Ermakov and his colleagues managed to access varied data belonging to 9.7 million current and former Medibank customers.
It included personally identifiable information - names, dates of birth, addresses, and more - for customers and healthcare providers, as well as health records pertaining to mental and sexual health, drug usage, and more.
The hackers leaked all of these records onto the Dark Web.
On Jan. 22, authorities did the best they could by way of retribution.
As part of its prolonged war with cybercrime syndicates, the Australian Ministry of Defence outed Ermakov and imposed a travel ban and financial sanctions.
As the ministry explained in a press release, the financial sanction makes stewarding or providing him with assets, including cryptocurrency wallets and ransomware payments, a criminal offense punishable by up to 10 years in prison plus significant fines.
Piling on, the UK Foreign, Commonwealth & Development Office and US Department of the Treasury's Office of Foreign Assets Control dittoed Australia's bans, freezing any assets he has in either country and adding his name to the Treasury's Specially Designated Nationals and Blocked Persons List.
Especially where finances are concerned.
US officials can't arrest a Russian in Russia, but they can influence the flow of international financial transactions.
Naming an entity to the SDN has a material impact on cybercriminal outfits, most notably ransomware operations, as it covers not only affiliates of these groups, but also any victims who'd otherwise be inclined to pay for the safe return of their data.
Major threat actors have seen serious repercussions as a result of such sanctioning.
Even a travel ban is more than just a bummer for a hacker's future vacations.
Russian Cybercriminals' Worst Fear An even more powerful alternative to Western law enforcement is the occasional Russian crackdown on its own domestic cybercrime.
One would do well to remember that, for all of the bad guys it shields, it was Russia's own police who administered the coup de grace against Ermakov's parent organization, ReVIL, back in 2022.


This Cyber News was published on www.darkreading.com. Publication date: Tue, 23 Jan 2024 21:55:15 +0000


Cyber News related to US, UK, AU Officials Sanction 33-Year-Old Russian Medibank Hacker

Who is Alleged Medibank Hacker Aleksandr Ermakov? - Authorities in Australia, the United Kingdom and the United States this week levied financial sanctions against a Russian man accused of stealing data on nearly 10 million customers of the Australian health insurance giant Medibank. 33-year-old ...
1 year ago Krebsonsecurity.com
US, UK, AU Officials Sanction 33-Year-Old Russian Medibank Hacker - A Russian national has been identified and sanctioned by Australia, the United Kingdom, and the United States for his role in the data breach of an Australian health insurance giant. Aleksandr Gennadievich Ermakov, born May 16, 1990, is a former ...
1 year ago Darkreading.com
Who is the DOGE and X Technician Branden Spikes? – Krebs on Security - Branden Spikes California Russian Association Congress of Russian Americans Constellation of Humanity Cyberinc Department of Government Efficiency Diana Fishman Donald J. Prior to founding Spikes Security, Branden Spikes was married to a native ...
3 months ago Krebsonsecurity.com
Russian state hackers spy on Ukrainian military through Signal app | The Record from Recorded Future News - Google said that while these recent attacks were likely driven by wartime demands to access sensitive government and military communications in the context of Russia’s invasion of Ukraine, researchers expect attacks on Signal to grow and spread to ...
4 months ago Therecord.media Turla
FSB arrests Russian hackers working for Ukrainian cyber forces - The Russian Federal Security Service arrested two individuals believed to have helped Ukrainian forces carry out cyberattacks to disrupt Russian critical infrastructure targets. Both suspects were taken into custody one same day in two different ...
1 year ago Bleepingcomputer.com
Australian government warns of 'large-scale ransomware data breach' - The incident recalls an October 2022 ransomware attack on Medibank, one of the country's largest health insurance providers, that led to the scandalous publication of sensitive healthcare data. As part of the Medibank criminals' extortion attempt, ...
1 year ago Therecord.media
Russian military hackers target NATO fast reaction corps - Russian APT28 military hackers used Microsoft Outlook zero-day exploits to target multiple European NATO member countries, including a NATO Rapid Deployable Corps. Researchers from Palo Alto Networks' Unit 42 have observed them exploiting the ...
1 year ago Bleepingcomputer.com CVE-2023-23397 Fancy Bear APT28
Notorious Evil Corp Hackers Targeted NATO Allies for Russian Intelligence | WIRED - On Tuesday, the United Kingdom's National Crime Agency released new details about the real world identities of alleged Evil Corp members, the group's connection to the LockBit platform, and the gang's ties to the Russian state. UK law ...
8 months ago Wired.com LockBit
Detained Russian student allegedly helped Ukrainian hackers with cyberattacks - A Russian tech student could face treason charges for helping Ukrainian hackers carry out cyberattacks against Russia. A resident of the Siberian city of Tomsk, Seymour Israfilov was detained by Russian security services in October, but little ...
1 year ago Therecord.media
Russian hackers use Ngrok feature and WinRAR exploit to attack embassies - After Sandworm and APT28, another state-sponsored Russian hacker group, APT29, is leveraging the CVE-2023-38831 vulnerability in WinRAR for cyberattacks. APT29 is tracked under different names and has been targeting embassy entities with a BMW car ...
1 year ago Bleepingcomputer.com CVE-2023-38831 APT28 APT29
Hacker Conversations: Chris Evans, Hacker and CISO - Chris Evans is CISO and chief hacking officer at HackerOne. SecurityWeek's Hacker Conversations series seeks to understand the mind and motivations of hackers by talking to hackers. Evans challenges the common perception of both hackers and their ...
11 months ago Securityweek.com Silence
Ukraine says it hacked Russian aviation agency, leaks data - Ukraine's intelligence service, operating under the Defense Ministry, claims they hacked Russia's Federal Air Transport Agency, 'Rosaviatsia,' to expose a purported collapse of Russia's aviation sector. Rosaviatsia is the agency responsible for ...
1 year ago Bleepingcomputer.com
Ukraine Arrests Hacker for Assisting Russian Missile Strikes - Ukrainian security services have arrested a hacker for allegedly targeting government websites and providing intelligence to Russia to carry out missile strikes on the city of Kharkiv. Security Service of Ukraine revealed that its cyber unit has ...
1 year ago Infosecurity-magazine.com
HPE: Russian hackers breached its security team's email accounts - Hewlett Packard Enterprise disclosed today that suspected Russian hackers known as Midnight Blizzard gained access to the company's Microsoft Office 365 email environment to steal data from its cybersecurity team and other departments. Midnight ...
1 year ago Bleepingcomputer.com Cozy Bear APT29
Major Russian delivery company down for three days due to cyberattack - A little-known hacker group claimed responsibility for an attack that has disrupted service for days at CDEK, one of Russia's largest delivery companies. The Russian-speaking hackers, who call themselves Head Mare, said they encrypted the company's ...
1 year ago Therecord.media
Feds arrest Russians accused of tech smuggling operation The Register - Three Russian nationals were arrested in New York yesterday on charges of moving electronics components worth millions to sanctioned entities in Russia, pieces of which were later recovered on battlefields in Ukraine. Nikolay Goltsev, a ...
1 year ago Theregister.com
Siberia's largest dairy plant reportedly disrupted with LockBit variant | The Record from Recorded Future News - During the attack on the Semyonishna plant, which occurred earlier in December, the unidentified hacker group encrypted the company’s systems with a LockBit ransomware strain, the regional office of Russia’s security service (FSB) said in a ...
3 months ago Therecord.media LockBit
Russian hackers stole Microsoft corporate emails in month-long breach - Microsoft disclosed Friday night that some of its corporate email accounts were breached and data stolen by the Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12th, with Microsoft initiating its ...
1 year ago Bleepingcomputer.com APT29
Russian hackers stole Microsoft corporate emails in month-long breach - Microsoft disclosed Friday night that some of its corporate email accounts were breached and data stolen by the Russian state-sponsored hacking group Midnight Blizzard. The company detected the attack on January 12th, with Microsoft initiating its ...
1 year ago Bleepingcomputer.com APT29
US sanctions Russian for cleaning Ryuk's and oligarchs' cash The Register - A Russian woman the US accuses of being a career money launderer is the latest to be sanctioned by the country for her alleged role in moving hundreds of millions of dollars on behalf of oligarchs and ransomware criminals. Among these was her alleged ...
1 year ago Theregister.com Wizard Spider
Who Is Behind Pro-Ukrainian Cyberattacks on Iran? - COMMENTARY. Ukrainian cyber forces have attacked Russian infrastructure and assets almost since the first day of the Russian invasion of Ukraine on Feb. 24, 2022. While its mainstay is denial-of-service attacks that have knocked out the Russian ...
1 year ago Darkreading.com
Signal no longer cooperating with Ukraine on Russian cyber threats, official says | The Record from Recorded Future News - Speaking to Recorded Future News on the sidelines of the Kyiv cyber forum, Demediuk said that Ukraine used “an official communication channel” to reach out to Signal about how the app is being abused by Russians, including for phishing attacks ...
3 months ago Therecord.media
China Reportedly Admits Their Role in Cyber Attacks Against U.S. Infrastructure - During a high-level meeting in Geneva with American officials, representatives from China’s Ministry of Foreign Affairs indirectly linked years of computer network breaches at U.S. ports, water utilities, airports, and other critical targets to ...
2 months ago Cybersecuritynews.com Volt Typhoon
Russia tightens cybersecurity measures as financial fraud hits record high | The Record from Recorded Future News - Earlier in March, Russian internet users faced widespread outages that regulators attributed to issues with “foreign server infrastructure.” However, local experts suggested the disruptions stemmed from Russia’s blocking of Cloudflare, a ...
2 months ago Therecord.media
Hacker 'ShinyHunters' Pleads Not Guilty in Cybercrime Case - A hacker known as 'ShinyHunters' has pleaded not guilty in a case of cybercrime. The hacker is accused of taking part in illegal activities to steal data from victims, including passwords, credit card information, and other personal details. The ...
2 years ago Blog.cloudflare.com Hunters