CYBERSECURITY

The reported arrest of Mikhail Matveev

A Russian arrest of a ransomware figure, and the reasons people were unsure what it meant.

Russia arrested Mikhail Matveev inside its own borders. His online names are Wazawaka and Boriselcin, and he is linked to the ransomware groups Hive, LockBit, and Babuk. The arrest was unusual. Russian authorities had long ignored hackers whose targets were outside Russia.

The background

That unofficial tolerance let a skilled criminal scene grow, as long as the activity did not touch Russian interests. U.S. authorities accused Matveev of ransomware against critical infrastructure, government organizations, healthcare, and private companies, with ransom demands in the tens of millions of dollars. Russia had resisted calls to prosecute or extradite people in that scene.

Why the arrest is significant

His crimes included attacks on the U.S. healthcare system, where ransomware disrupted hospitals, and attacks on private companies and law-enforcement databases. Why Russia acted is not settled. International pressure, geopolitical strategy, or a domestic concern are all possible, and the audience for the message was unclear.

What it could mean

If the arrest were part of a wider change, cross-border work against cybercrime could get easier. One arrest is not proof of a policy change, given a history of shielding criminals.

Possible reasons

  • A bargaining chip in talks, including with the United States, so Russia could look cooperative.
  • A response to sanctions and scrutiny, meant to blunt criticism of ransomware policy.
  • An internal line Matveev crossed, if his activity threatened Russian infrastructure or political stability.
  • A symbolic gesture to quiet international complaint, rather than the start of a campaign.

What about the cases

Matveev was a key player in several ransomware operations, including Babuk against the Washington, D.C. Metropolitan Police Department in 2021. Sensitive police files were leaked online after the ransom was not paid. He was also accused of extorting millions from U.S. companies and healthcare institutions.

The FBI and the U.S. Department of Justice charged him with crimes including conspiracy to commit computer fraud and intentional damage to protected computers. He was indicted in the United States earlier in 2024, placed on the FBI Most Wanted list. The FBI offered a $10 million reward for information leading to his arrest. He boasted about the attacks online and mocked victims and law enforcement.

What is still unknown

Caution is warranted. It was not clear, at the time, whether more arrests would follow or whether Matveev’s case would stand alone. Whether the arrest was a real shift in how Russia handles cybercriminals, or a calculated political move, was still open.

Back to the blog