{
  "id": "case-sikerin-polyanin-revil",
  "slug": "us-v-sikerin-polyanin-revil-affiliates",
  "title": "U.S. v. Aleksandr Sikerin & Yevgeniy Polyanin (REvil Operations)",
  "summary": "International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.",
  "case_number": "3:21-cr-00315",
  "court": "U.S. District Court for the Northern District of Texas",
  "district": "N.D. Tex.",
  "country": "United States",
  "opened_at": "2021-11-08",
  "status": "fugitive",
  "victim_sector": "Local Government, Healthcare, Manufacturing",
  "victim_country": "United States",
  "loss_amount_usd": 13000000,
  "loss_amount_note": "Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets.",
  "first_seen_at": "2019-08-01T00:00:00Z",
  "last_updated_at": "2026-05-30T11:00:00Z",
  "actor_slug": "revil-sodinokibi",
  "defendant_slugs": [
    "yevgeniy-polyanin"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Polyanin",
      "source_url": "https://www.justice.gov/opa/pr/justice-department-announces-first-extradition-revil-ransomware-attacks-seizure-61-million",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2021-11-08",
      "description": "DOJ unseals indictment against Polyanin and announces recovery of $6.1 million in extorted funds."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Local Government, Healthcare, Manufacturing networks. International enforcement action against REvil ransomware money exchangers and operators, recovering $6.1 million in ransomware proceeds extorted from businesses and local governments across the United States.",
    "blast_radius": "Extorted $13 million; federal seizure warrants recovered $6.1 million from crypto deposit wallets. Impacted Local Government, Healthcare, Manufacturing infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Impact",
        "title": "Operational Disruption or Extortion Detonation",
        "description": "Polyanin deployed Sodinokibi/REvil ransomware against dozens of municipal government agencies across Texas, encrypting servers and demanding ransoms in Monero.",
        "technical_artifacts": [
          "T1486",
          "Data Encrypted for Impact"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}