{"id":2514,"date":"2022-03-11T23:35:14","date_gmt":"2022-03-12T06:35:14","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=2514"},"modified":"2022-03-11T23:36:17","modified_gmt":"2022-03-12T06:36:17","slug":"ukrainian-hacker-yaroslav-vasinskyi-extradited-to-the-united-states","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/11\/ukrainian-hacker-yaroslav-vasinskyi-extradited-to-the-united-states\/","title":{"rendered":"Ukrainian Hacker Yaroslav Vasinskyi Extradited to the United States"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/techstartups.com\/wp-content\/uploads\/2022\/03\/hacker.jpg\" alt=\"\" width=\"844\" height=\"475\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 844px; --smush-placeholder-aspect-ratio: 844\/475;\" \/><figcaption>Yaroslav Vasinskyi is facing charges in the US for using REvil malware in attacks against American companies, including an attack against US software company Kaseya. <\/figcaption><\/figure>\n\n\n\n<p class=\"has-text-align-left\">On March 3, 2022 Ukrainian hacker and REvil member Yaroslav Vasinskyi was extradited to the United States, and will be facing trial in Texas for his role in ransomware attacks against American companies. A statement by the U. S. Department of Justice (DOJ) reads: \u201cVasinskyi is charged with conspiracy to commit fraud and related activity in connection with computers, damage to protected computers, and conspiracy to commit money laundering.\u201d  If he is found guilty, he could face up to 115 years in prison. <\/p>\n\n\n\n<p class=\"has-text-align-left\">According to the indictment released last July by the DOJ, Vasinskyi has been part of REvil since at least 2019 and has launched around 2,500 attacks.&nbsp;Among these many attacks includes the July 2021 ransomware attack on the American software firm Kaseya. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">The Kaseya ransomware attack <\/h4>\n\n\n\n<p>Kaseya is a Florida based company that primarily helps small to medium businesses (SMBs) across the world manage networks&nbsp;managing&nbsp;networks,&nbsp;systems, and information technology&nbsp;infrastructure. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/th.bing.com\/th\/id\/R.992b23eaade38811f30bf8ff691640f7?rik=bY3BW5ywAbzBTw&amp;riu=http%3a%2f%2fwww.squidworks.net%2fwp-content%2fuploads%2f2011%2f03%2flogoKaseya-e1301179502788.gif&amp;ehk=qTyG9jWH8t7I3Der8%2bMByOPup4Irys6TUQkqlKm83dw%3d&amp;risl=&amp;pid=ImgRaw&amp;r=0\" alt=\"\" width=\"582\" height=\"163\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 582px; --smush-placeholder-aspect-ratio: 582\/163;\" \/><figcaption>Logo for the US software company Kaseya, which was hacked July 2021. <\/figcaption><\/figure>\n\n\n\n<p>Kaseya\u2019s services are managed remotely by Kaseya Virtual Storage Appliance (VSA), which allows customers to use virtual machines for storage instead of buying hardware. On July 2, 2021 unusual behavior on the endpoints of clients&#8217; networks was reported to Kaseya: it turned out hackers had found out a way to bypass the authentication of the VSA and distribute REvil ransomware through the hosts managed by the software. Within a few hours Kaseya shut down their VSA cloud servers and issued out a statement to its clients, however the damage had already been done. The effects of this attack were felt internationally; up to 1,500 companies across the world were affected. REvil took credit for the attack, and demanded $70 million for a decrypting key that would unlock all infected systems. Kaseya refused to pay the ransom, and in a statement made on July 22, 2021 the company declared that it had obtained a decryptor key from an anonymous third party, which was later revealed to have been the FBI. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Effects of the attack<\/h4>\n\n\n\n<p>The effects were felt by thousands of companies internationally. Virginia Tech University was affected, and many schools and kindergartens in New Zealand were also affected. In Sweden, the superstore chain Coop was unable to use its cash registers, and had to shut down its over 800 locations for  a few days. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">The US Government&#8217;s response<\/h4>\n\n\n\n<p>In August 2021, the US Department of Justice released an Indictment for Vasinskyi, connecting him as well as Russian hacker Yevgyeniy Polyanin with the Kaseya attack. In fall of 2021 Vasinskyi was arrested in Poland, and held there until his extradition to the US. While Vasinskyi is not a US citizen, the US government has made it clear that they will prosecute cybercriminals regardless of nationality. Attorney General Merrick Garland declared in a public statement: &#8220;The Justice Department will spare no resource in identifying and bringing to justice transnational cybercriminals who target the American people&#8221;. <\/p>\n\n\n\n<p>Hopefully this trial will help dissuade international hackers from engaging in ransomware, as it is sad when a small group of malicious actors are able to cause such a disruption to thousands of innocent people across the world. Companies and individuals certainly do have a responsibility to ensure that they always use best security practices, however governments also have a responsibility to bring justice to hackers who do break into systems and cause harm to companies and individuals across the world.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">References <\/h3>\n\n\n\n<p><a href=\"https:\/\/www.msn.com\/en-za\/news\/world\/alleged-ukrainian-hacker-in-us-court-after-extradition-from-poland\/ar-AAUR8aP?ocid=BingNewsSearch\">Alleged Ukrainian hacker in US court after extradition from Poland (msn.com)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.hackread.com\/ukraine-revil-ransomware-gang-member-extradite-us\/\">Alleged Ukrainian Member of REvil Ransomware Gang Extradited to US (hackread.com)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.itnews.com.au\/news\/kaseya-ransomware-attackers-trial-begins-577163\">Kaseya ransomware attacker&#8217;s trial begins &#8211; Security &#8211; iTnews<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.justice.gov\/opa\/pr\/sodinokibirevil-ransomware-defendant-extradited-united-states-and-arraigned-texas\">Sodinokibi\/REvil Ransomware Defendant Extradited to United States and Arraigned in Texas | OPA | Department of Justice<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/helpdesk.kaseya.com\/hc\/en-gb\/articles\/4403440684689\">Important Notice August 4th, 2021 \u2013 Kaseya<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/web.archive.org\/web\/20211003205303\/https:\/\/www.zdnet.com\/article\/kaseya-denies-paying-ransom-for-decryptor-refuses-comment-on-nda\/\">Kaseya denies paying ransom for decryptor, refuses comment on NDA | ZDNet (archive.org)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.reuters.com\/technology\/hackers-demand-70-million-liberate-data-held-by-companies-hit-mass-cyberattack-2021-07-05\/\">Up to 1,500 businesses affected by ransomware attack, U.S. firm&#8217;s CEO says | Reuters<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/en.wikipedia.org\/wiki\/Kaseya_VSA_ransomware_attack#cite_note-ZDNet-ransom-10\">Kaseya VSA ransomware attack &#8211; Wikipedia<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.cyberscoop.com\/revil-kaseya-texas-court-yaroslav-vasinskyi\/\">REvil member accused of Kaseya ransomware attack arraigned in Texas (cyberscoop.com)<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/www.pragmastrategy.com\/news\/lessons-learnt-from-the-kaseya-ransomware-attack\/\">Lessons Learnt from the Kaseya Ransomware Attack &#8211; Pragma &#8211; Securing Your Digital Future (pragmastrategy.com)<\/a><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 3, 2022 Ukrainian hacker and REvil member Yaroslav Vasinskyi was extradited to the United States, and will be facing trial in Texas for his role in ransomware attacks against American companies. A statement by the U. S. Department of Justice (DOJ) reads: \u201cVasinskyi is charged with conspiracy to commit fraud and related activity &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/03\/11\/ukrainian-hacker-yaroslav-vasinskyi-extradited-to-the-united-states\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Ukrainian Hacker Yaroslav Vasinskyi Extradited to the United States&#8221;<\/span><\/a><\/p>\n","protected":false},"author":381,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-2514","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Sebastian Reinberg-Abernethy","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/sebastian-reinberg-abernethy\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/381"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=2514"}],"version-history":[{"count":37,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2514\/revisions"}],"predecessor-version":[{"id":2551,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/2514\/revisions\/2551"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=2514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=2514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=2514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}