Thursday, 10 September 2026 MUMBAI EDITION LIVE

Ransomware Creator Sentenced to 16 Years in Prison

Maksim Silnikau sentenced, Ransom Cartel disrupted, businesses warned to prepare for continuity and recovery.

Mumbai Alert · Markets Desk
Mumbai Alert · Markets Desk
Markets Desk · Mumbai Alert News · Thu, 10 September 2026 at 01:29 pm
Ransomware Creator Sentenced to 16 Years in Prison

A significant law-enforcement outcome was achieved with the sentencing of Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, to 16 years in prison. This arrest and prosecution disrupted the group and removed an experienced operator who had spent years building ransomware infrastructure and recruiting participants.

The Ransom Cartel had attacked at least 18 organisations between 2021 and 2023, with a highly organised operating model that separated those building and administering the ransomware operation from affiliates carrying out intrusions. Participants could obtain compromised access, encryption tools, and infrastructure for managing attacks, negotiating with victims, and distributing criminal proceeds.

While this sentence may weaken one criminal operation, it does little to change the underlying economics that make ransomware possible. Ransomware attacks have become less dependent on a single attacker, malware strain, or criminal group. Access can be obtained separately, attacks can be executed by affiliates, and data can be stolen before systems are encrypted.

This changes the question companies should be asking. Preventing ransomware remains necessary, but the harder question is whether the business can continue operating when prevention fails, with the confirmation that their data is not extracted and still inside the organisation.

A recent cyberattack on French rugby club Stade Français illustrates this point. The club restored its IT environment from clean backups and continued normal operations, with its ticketing platform and online store remaining operational. However, recovery did not end the incident, as data allegedly stolen during the attack appeared online, forcing the organisation to investigate the breach, determine whose information may have been affected, engage authorities, and manage communications with stakeholders.

The paradox is clear: an organisation can restore its systems and still remain in crisis. This distinction should shape how boards and management teams assess ransomware readiness. Traditional ransomware discussions often focus on endpoint controls, patching, detection, and backups. Those measures matter, but they do not establish whether the enterprise can sustain critical business operations while technology teams investigate, isolate, and rebuild compromised systems.

The immediate challenge is operational continuity. Management needs to know which business services must continue, which systems can be taken offline, what manual alternatives are viable, which dependencies must be restored first, and how long the organisation can tolerate degraded operations. Those decisions cannot be developed for the first time during an attack.

Another issue is recovery confidence. A backup is an asset, but a tested ability to recover is essential. Companies must be able to restore their systems and data quickly and reliably, with minimal disruption to business operations.

In conclusion, while the sentencing of Maksim Silnikau is a significant law-enforcement outcome, it is a reminder that ransomware attacks are a persistent threat to businesses. Companies must be prepared to prevent attacks, but also to respond and recover quickly in the event of a breach. This requires a comprehensive approach to ransomware readiness, including operational continuity and recovery confidence.

The key takeaway is that preventing ransomware is not enough; companies must also be able to continue operating when prevention fails. This requires a focus on operational continuity, recovery confidence, and the ability to sustain critical business operations during a crisis.

As the threat of ransomware continues to evolve, companies must be proactive in their approach to readiness and response. This includes investing in endpoint controls, patching, detection, and backups, as well as developing a comprehensive plan for operational continuity and recovery confidence.

By taking a proactive approach to ransomware readiness, companies can reduce the risk of a successful attack and minimize the impact of a breach. This requires a commitment to ongoing monitoring, testing, and improvement of ransomware defenses, as well as a focus on operational continuity and recovery confidence.

In the end, ransomware readiness is not just about preventing attacks; it is about being prepared to respond and recover quickly in the event of a breach. By prioritizing operational continuity and recovery confidence, companies can reduce the risk of a successful attack and minimize the impact of a breach.

Frequently asked questions

What is the Ransom Cartel ransomware operation?

The Ransom Cartel is a highly organised ransomware operation that attacked at least 18 organisations between 2021 and 2023.

How can companies prepare for ransomware attacks?

Companies can prepare for ransomware attacks by investing in endpoint controls, patching, detection, and backups, as well as developing a comprehensive plan for operational continuity and recovery confidence.

ransomwarecybersecuritybusiness continuity
X Facebook Telegram
Read the original report ↗

More in Markets

Markets

HUL Focuses On Premium Products Amid Resilient FMCG Demand

HUL bets on premium products, FMCG demand stays strong despite inflation.

By Mumbai Alert · Markets Desk · 1 hr ago

Markets

Ultraviolette Invests ₹779 Crore In Tamil Nadu Plant

Ultraviolette to expand electric motorcycle production with new plant in Hosur, Tamil Nadu. Investment to boost manufacturing capacity and strengthen market presence.

By Mumbai Alert · Markets Desk · 1 hr ago

Markets

Sonaselection India IPO Launches September 17, Priced ₹94-₹99 Per Share

Sonaselection India's IPO opens on September 17. The price band is set at ₹94-₹99 per share.

By Mumbai Alert · Markets Desk · 1 hr ago

Markets

Dilip Buildcon Sells Mekhali Power Project For ₹2,914 Crore

Dilip Buildcon divests stake in Mekhali Power Transmission, Alpha Alternatives to acquire 51% equity. Deal valued at ₹2,914 crore.

By Mumbai Alert · Markets Desk · 2 hr ago