Federal authorities are intensifying their pursuit of the cybercriminals behind hospital and healthcare ransomware attacks, bringing charges against ransomware developers, state-sponsored hackers and even insiders from the cybersecurity industry.
The latest move came July 14, when the Justice Department indicted three Russian nationals and two “bulletproof hosting” companies tied to $62 million in U.S. victim losses. The action is part of Operation Riptide, the FBI’s ongoing campaign against cybercrime infrastructure, after Americans reported more than $20 billion in cybercrime losses last year, a 26% single-year increase.
Here are 11 healthcare hacker cases the feds have brought or advanced since 2024:
1. Three Russians — Alexander Volosovik, Kirill Zatolokin and Yulia Pankova — and two St. Petersburg-based hosting firms were indicted July 14 in the Northern District of Ohio for allegedly leasing server infrastructure that enabled ransomware, phishing and brute-force attacks on 42 victims across 21 states, including hospitals.
2. Three cybersecurity professionals were charged in the Southern District of Florida with moonlighting as ALPHV BlackCat affiliates, extorting $1.27 million from a Florida medical device firm and targeting a California physician’s office and a Maryland pharmaceutical company. Ryan Goldberg and Kevin Martin were sentenced in April to four years each, while Angelo Martino — a former ransomware negotiator who fed clients’ confidential negotiation details to BlackCat — received 70 months in July.
3. Conti ransomware member Oleksii Lytvynenko pleaded guilty in June after being extradited from Ireland and faces sentencing in September; a separate 2023 indictment linked the group to attacks on about 300 U.S. organizations, including the 2021 hack of San Diego-based Scripps Health.
4. Russian nationals Roman Berezhnoy and Egor Glebov were charged in February 2025 with running a Phobos ransomware operation that extorted more than $16 million, with victims including a North Carolina children’s hospital and healthcare organizations in Maryland and Pennsylvania. Phobos administrator Evgenii Ptitsyn, extradited from South Korea, pleaded guilty to wire fraud conspiracy in March, with sentencing set for October.
5. Rostislav Panev, a dual Russian-Israeli national accused of developing LockBit malware used against more than 2,500 victims, including hospitals, was charged in December 2024, extradited to the U.S. in March 2025 and is detained pending trial.
6. Sudanese nationals Ahmed Salah Yousif Omer and Alaa Salah Yusuuf Omer were indicted in October 2024 over a cyberattack on Los Angeles-based Cedars-Sinai that diverted emergency department patients for about eight hours, allegedly in retaliation for Israel’s bombing of hospitals in Gaza.
7. Deniss Zolotarjovs, a ransom negotiator for the Karakurt gang — which claimed to have stolen patients’ DNA records from McAlester (Okla.) Regional Health Center — was sentenced in May to 8 1/2 years in prison after pleading guilty to money laundering and wire fraud conspiracy charges.
8. North Korean government hacker Rim Jong Hyok was indicted in July 2024 for allegedly deploying Maui ransomware against U.S. hospitals as part of Andariel, a group tied to the country’s military intelligence agency; he remains at large, with the State Department offering up to $10 million for his capture.
9. LockBit affiliates Ruslan Astamirov and Mikhail Vasiliev pleaded guilty in July 2024 to deploying ransomware against at least 12 victims each for the gang, which has extorted approximately $500 million from organizations including hospitals.
10. Dmitry Khoroshev, the alleged LockBit mastermind, was charged in May 2024 in a 26-count indictment accusing him of personally pocketing $100 million from extortions of victims including hospitals; he also remains at large with a $10 million reward on offer.
11. Vladimir Dunaev, whose Trickbot malware was used in attacks that extorted $100 million from U.S. hospitals, was sentenced in January 2024 to more than five years in prison.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.