A Latvian national was sentenced to eight years in prison on Monday for his role in the negotiation process for a major Russian ransomware group. 

Deniss Zolotarjovs, 35, of Moscow, Russia, was a member of a ransomware group called Karakurt, which was led by the former operators of Conti. Zolotarjovs worked for the group between 2021 and 2023, and was primarily responsible for pressuring ransomware victims who initially resisted quick payment after the group made ransom demands. 

Zolotarjovs was initially arrested in Georgia (the country) in 2023 and was transferred to U.S. custody in August 2024. In July 2025, he pleaded guilty to conspiring to commit both money laundering and wire fraud. 

“Ransomware groups disrupt victims’ lives, cruelly extracting money through psychological manipulation and fear. And they create lingering security issues,” said U.S. Attorney Dominick S. Gerace II for the Southern District of Ohio, in a statement this week. “Cybercriminals might think they are invulnerable by hiding behind anonymizing tools and complex cryptocurrency patterns while they attack American victims from non-extradition countries.”

The Justice Department detailed how Zolotarjovs put pressure on victims, often analyzing stolen data and researching victims before negotiations kicked off. In one attack against a pediatric healthcare company, he used children’s health data as an extortion method. After the victim didn’t pay, he urged the other ransomware gang members to be “DESTROYERS” and leak or sell the stolen health records as a way to tighten the pressure. When one of the other members suggested sending each pediatric patient their own data, he said he didn’t have time to do that and instead sent a “general pack” of sensitive data to “hundreds of patients.”

Overall, while Zolotarjovs worked at the ransomware group, it stole data from 54 companies. Of these companies:

  • Attacks on only 13 of those companies resulted in over $56 million in losses 
  • That includes around $2.8 million in ransom payments.
  • The loss estimate only includes known victim companies. It doesn’t include an additional 41 victim companies that made $13 million in ransom payments. The government doesn’t have detailed loss statements for these yet.

“Due to widespread underreporting of ransomware attacks, true loss numbers are uncertain, but, extrapolating from the known victims and known losses, the government estimates total losses for the period of Zolotarjovs’s participation to likely be in the hundreds of millions of dollars,” according to the DoJ. “These loss estimates omit the cost, both psychological and financial, to tens of thousands of individual clients whose data was stolen from these victim companies.”

Actual arrests and sentences like this one or the extradition of a Silk Typhoon hacker last week are far more effective than indictments or charges–although they’re also far more rare. This is partly because many times, these individuals live in so-called safe haven countries.

The DoJ in its release detailed exactly how ransomware groups leveraged corruption to operate within these safe haven countries. Members of Zolotarjovs' organization were Russian or based in Russia and operated out of an office building on Lakhtinskaya Street in St. Petersburg, Russia. According to the DoJ, the organization relied on a hierarchical management structure and divided the work into separate teams, using a network of companies registered throughout Russia, Europe, and the U.S. to hide their operations. 

The organization fueled corruption in Russia, with members typically including multiple former Russian law enforcement officers. 

“These connections allowed members of the group to co-opt Russian government databases and law enforcement connections to intimidate and harass personal detractors, and to identify and evaluate potential new recruits to the organization,” said the DoJ. “Corruption also ensured special treatment for members of the organization. Leaders avoided Russian taxes and regularly paid bribes to exempt members — draft-age men — from compulsory military service in Russia.”