DOJ: Ransomware Gang Tapped Russian Government Databases
U.S. prosecutors revealed the Russian ransomware gang Karakurt accessed government databases and used law enforcement ties to evade taxes and military service, following the sentencing of hacker Deniss Zolotarjovs. This highlights Russia's role as a cybercriminal "safe haven."

The U.S. Justice Department has revealed that the notorious Russian ransomware group Karakurt operated with direct access to Russian government databases and leveraged law enforcement connections to further its criminal enterprise. This revelation came during the sentencing of Latvian hacker Deniss Zolotarjovs, who received over eight years in prison for his involvement in the gang’s attacks, which included disrupting 911 emergency services and stealing sensitive health data.
Zolotarjovs, a key figure in applying "escalating pressure" on victims refusing to pay ransoms, was convicted for his role in the Karakurt operations. The gang, formed by individuals previously linked to the Akira and Conti ransomware groups—both of which were sanctioned by the U.S. Treasury for alleged ties to Russian intelligence—represents a stark example of the intertwined nature of cybercrime and state apparatus in Russia, according to U.S. prosecutors.
The explicit connection to Russian state resources outlined by the DOJ underscores a long-held accusation by security researchers: that the Russian government actively shields cybercriminals from Western justice. This alleged sanctuary has transformed Russia into a “safe haven” for hackers, as noted by U.S. officials, making ransomware a significant national security threat to the United States. The Russian Foreign Ministry has not responded to inquiries regarding these claims.
According to the Justice Department's press release, the Karakurt gang’s illicit activities extended beyond typical ransomware operations to "fueling corruption" within the Russian government itself. This corruption manifested in tangible benefits for the gang’s leadership, who allegedly used their government ties to evade state taxes and, through bribes to officials, secure exemptions from compulsory military service for their members. These details paint a picture of a criminal organization deeply embedded within and benefiting from state institutions.
Karakurt targeted more than 54 companies, extracting at least $15 million in ransom payments from its victims. Among its particularly egregious attacks were those against U.S. government entities, which caused significant disruption, including to critical 911 emergency dispatch systems. The gang also illicitly obtained children's health information, highlighting the wide-ranging and damaging scope of their cyber-operations. While Karakurt itself no longer appears to be an active entity, ransomware operations frequently rebrand or change ownership to circumvent international sanctions and law enforcement efforts.
The sentencing of Zolotarjovs marks a significant win for international law enforcement. He was apprehended in Georgia in 2023 and subsequently extradited to the United States in August 2024, where he later pleaded guilty to the charges. His conviction, coupled with the DOJ's detailed allegations, casts a critical light on the operational environment for cybercriminals within Russia and the challenges faced by global efforts to combat ransomware. The case serves as a potent reminder of the complex interplay between national interests, geopolitical tensions, and the escalating threat of state-backed or state-enabled cybercrime.
FAQ
Q: What is the significance of the DOJ's announcement regarding Karakurt?
A: The U.S. Justice Department's statement is significant because it explicitly details how the Karakurt ransomware gang not only operated from Russia but also leveraged direct access to Russian government databases and connections with law enforcement officials. This indicates a deeper level of state enablement and corruption than previously confirmed for many such groups.
Q: Who is Deniss Zolotarjovs and what was his role in the Karakurt gang?
A: Deniss Zolotarjovs is a Latvian hacker who was sentenced to over eight years in prison for his involvement with the Karakurt ransomware gang. His specific role included "escalating pressure" on victims who resisted the gang's ransom demands, a critical component of their extortion tactics.
Q: How did the Karakurt gang benefit from its alleged ties to Russian officials?
A: The gang leaders allegedly benefited significantly from their ties to Russian officials, using them to "fuel corruption." This allowed them to avoid paying state taxes and to secure exemptions from Russia's compulsory military service for their members through bribery, in addition to using government databases for their criminal activities.
Related articles
Kalshi Bans George Santos for Life Over Investigation Non-Compliance
Prediction market platform Kalshi has issued its first-ever lifetime ban to former Republican congressman George Santos. The move, announced Monday, comes after Santos reportedly failed to cooperate with an internal company investigation. This adds another chapter to the controversies surrounding the former House member, who was expelled from Congress in 2023.
Professor Murder Rides the Subway is a forgotten slice of dance punk
In a recent digital archaeology expedition, Terrence O'Brien, Weekend Editor at The Verge, unearthed and lauded Professor Murder's 2006 EP, "Professor Murder Rides the Subway," as a quintessential, yet largely
ai: Musk’s faster path to more gas turbines comes with pollution
Elon Musk's SpaceX is building a secret Texas foundry to produce gas turbine blades, aiming to accelerate AI data center power by 18 months. This addresses a critical energy bottleneck, but faces environmental backlash over pollution and health risks from gas turbines.
Robotaxis' Hidden Human Cost: Test Drivers Injured
An exclusive TechCrunch investigation reveals a hidden human cost in the robotaxi industry, with Waymo and Zoox test drivers suffering over two dozen injuries from sudden autonomous vehicle movements in 2024-2025. These incidents, including whiplash, sideline workers for months, challenging the industry's safety narrative. The report highlights occupational hazards for those at the forefront of AV development and raises questions about broader industry reporting as the sector expands.
Caterpillar Leverages Mining Automation Expertise for AI Deployment
Industrial giant Caterpillar is pioneering a pragmatic approach to artificial intelligence deployment, drawing upon decades of experience automating challenging physical environments like mining sites. The company's
Hollywood A-Listers Embrace Microdrama Apps Amidst Industry Shift
In a surprising pivot, some of Hollywood’s most recognizable names, accustomed to blockbuster films and substantial paychecks, are now making a significant bet on microdramas. These bite-sized, scripted series, designed





