International Authorities Intensify Manhunt for Ukrainian Ransomware Kingpin

by Sarah Steffens

Law enforcement agencies across Europe and the United States have escalated efforts to capture a Ukrainian national accused of orchestrating a series of devastating ransomware attacks that caused billions in damages worldwide. The suspect, Volodymyr Tymoshchuk, has been added to the European Union’s Most Wanted list as part of a coordinated crackdown.

Authorities allege Tymoshchuk headed a sophisticated cybercriminal operation responsible for unleashing the LockerGoga virus, a destructive malware that paralyzed major corporations and disrupted global supply chains. The group is believed to have targeted over 250 companies in the United States alone, along with hundreds more internationally.

One of the most notorious incidents linked to Tymoshchuk occurred in 2019, when Norsk Hydro, a major Norwegian aluminum producer, fell victim to a cyberattack. The breach forced the company to halt production at multiple facilities, leading to tens of millions of dollars in losses and weeks of manual operations to recover.

The investigation, coordinated by European policing agencies, involved collaboration from France, Germany, Norway, Switzerland, Ukraine, the United Kingdom, and the United States. Researchers described the group as operating like a business, with distinct roles for programmers, infiltrators, and money launderers.

Earlier this week, U.S. prosecutors released a new indictment charging Tymoshchuk under multiple aliases, including “deadforz” and “Boba.” The charges cover a three-year period from 2018 to 2021, during which he allegedly deployed LockerGoga along with two other ransomware variants—MegaCortex and Nefilim.

The U.S. State Department has offered a reward of up to $10 million for information leading to Tymoshchuk’s arrest or conviction, while an additional $1 million is available for tips on other key figures in the ransomware network.

“This individual systematically attacked high-value firms, medical facilities, and industrial giants, threatening to expose confidential data unless ransoms were paid,” said U.S. Attorney Joseph Nocella, emphasizing the severity of the crimes.

Court documents reveal that Tymoshchuk specifically instructed accomplices to target companies with annual revenues exceeding $200 million, focusing on firms based in the United States, Canada, and Australia. The group employed tactics such as network encryption and data publication on leak sites to pressure victims into paying.

Several associates have already been apprehended in Ukraine, including malware developers, intrusion specialists, and financial operators who managed complex money-laundering operations.

LockerGoga first appeared in early 2019 and quickly became infamous for its destructive impact. Unlike some ransomware that merely encrypts data, it often rendered systems unusable for months, with recovery costs running into the millions. Norsk Hydro chose not to pay the ransom, but the attack highlighted the growing vulnerability of industrial sectors to cyber threats.