Signal
Submitted
Apr 28, 2026, 13:45 UTC
German authorities identified Nikolay K. in Russia as a core suspect in the REvil ransomware group responsible for high-profile cyber extortion, but capture is unlikely due to his location and lack of extradition.
German prosecutors, supported by the Federal Criminal Police (BKA) and the Baden-Württemberg State Criminal Police (LKA), have identified Nikolay K., resident near a southern Russian city, as a key figure in the REvil ransomware group involved in extorting companies and public institutions. Using ransomware, REvil encrypts corporate networks and demands high ransoms, with the largest known demand reaching $70 million. Nikolay K. has reportedly used ransom funds to support a lavish lifestyle including luxury watches, cars, and vacations. Investigators traced Bitcoin payments worth nearly 400,000 euros linked to him, notably from a 2019 ransomware attack on the Stuttgart State Theaters that disrupted email communications and forced paper ticket replacements. Although an arrest warrant exists, extradition is improbable as he remains in Russia; a recent holiday in Turkey did not lead to detention. The German government and US officials have engaged Russia diplomatically over ransomware threats originating there. The continuous investigations aim to disrupt these cybercriminal networks and improve cyber defense capabilities.
Confidence: High
The article explicitly identifies a suspect in Russia connected to ransomware attacks targeting German entities and provides detailed investigative and operational context, confirming aggressive cybercriminal activity.
Source URL
https://tagesschau.de/investigativ/br-recherche/ransomware-revil-101.html
Source reliability
B
Info credibility
6
Event time
Oct 28, 2021, 07:35 UTC
Event time confidence
exact
Location
Baden-Württemberg, near Stuttgart, Germany
Region
Baden-Württemberg
Primary actor
Nikolay K.
Country
Germany
Countries
Germany
Tags
ransomware, REvil, Bitcoin, cybercrime, cyberattacks, Germany, Russia, Baden-Württemberg, law enforcement, Bitcoin payments, Stuttgart State Theaters, LKA Baden-Württemberg, BKA
Nodes
Node 2: 5th Column