Back Local12 Ransomware negotiator sentenced in Cincinnati for millions of dollars in attacks
Deniss Zolotarjovs, 35, was a member of the group known as Karakurt, TommyLeaks and SchoolBoys Ransomware, which has been involved in $56 million in cyberattacks. (BCSO)
CINCINNATI (WKRC) - A man originally from Latvia was sentenced Monday to 8 1/2 years in federal prison for his role in a ransomware operation that stole millions of dollars from victims.
Deniss Zolotarjovs, 35, was a member of a group known as Karakurt, TommyLeaks and SchoolBoys Ransomware, which carried out cyberattacks totaling $56 million, according to the U.S. Attorney’s Office.
Deniss Zolotarjovs, 35, was a member of the group known as Karakurt, TommyLeaks and SchoolBoys Ransomware, which has been involved in $56 million in cyberattacks. (WKRC, BCSO)
Prosecutors said Zolotarjovs acted as a negotiator, demanding payments ranging from $25,000 to $13 million and receiving 10% of the proceeds, typically in cryptocurrency.
A company with offices in Hamilton, Butler, Montgomery, and Franklin counties paid $1.3 million, authorities said.
Investigators said Zolotarjovs contacted the FBI and offered information the group in exchange for $365,000. Agents arranged a meeting in the country of Georgia, where he was arrested in 2023.
“With this sentence, a cruel, ruthless, and dangerous international cybercriminal is now behind bars,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “Deniss Zolotarjovs helped his ransomware gang profit from hacks of dozens of companies, and even on a government entity whose 911 system was forced offline. He also used stolen children’s health information to increase his leverage to extort victim payments. The Criminal Division will continue to investigate and prosecute international hackers and extortionists from around the world, no matter where they live or operate.”
Zolotarjovs pleaded guilty to conspiracy to commit money laundering and wire fraud.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
