The person at the center of this case
Multiple organizations across critical infrastructure, healthcare, transportation, and government sectors
Justice for Multiple organizations across critical infrastructure, healthcare, transportation, and government sectors — the trail went cold in 2018, but the truth hasn't.
Start here
How were the ransom payments tracked and traced across the cryptocurrency and financial systems used by the suspects?
What is the current location and status of Mohammad Mehdi Shah Mansouri and Faramarz Shahi Savandi in Iran?
What specific vulnerabilities in computer networks were exploited by the SamSam ransomware to achieve such widespread success?
Mohammad Mehdi Shah Mansouri and Faramarz Shahi Savandi are wanted for operating the SamSam ransomware operation, which encrypted hundreds of computer networks across critical infrastructure, healthcare, transportation, and government sectors since December 2015. The two Iranian nationals allegedly extorted over $6 million in ransom payments from their victims. Both men remain at large in Tehran, Iran, and were indicted in November 2018 by a federal grand jury in New Jersey.
Try asking
A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.
This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.
Beyond the top three above — each detail below could be the thread that pulls this case open.
Are there any known associates or accomplices in the United States or elsewhere who facilitated the ransom collection?
Even the smallest detail could be the key to solving this case.
Official wording
Conspiracy to Commit Fraud and Related Activity in Connection with Computers; Conspiracy to Commit Wire Fraud; Intentional Damage to a Protected Computer; Transmitting a Demand in Relation to Damaging a Protected Computer Mohammad Mehdi Shah Mansouri and Faramarz Shahi Savandi are wanted for allegedly launching SamSam ransom ware, aka MSIL/Samas.A attacks, which encrypted hundreds of computer networks in the United States and other countries. Since December of 2015, Shah Mansouri and Shahi Savandi have received over $6 million in ransom payments from victims across several sectors, including critical infrastructure, healthcare, transportation, and state/local governments.
On November 26, 2018, a federal grand jury sitting in the United States District Court for the District of New Jersey, Newark, New Jersey, indicted Shah Mansouri and Shahi Savandi on charges of conspiracy to commit fraud and related activity in connection with computers, conspiracy to commit wire fraud, intentional damage to a protected computer, and transmitting a demand in relation to damaging a protected computer. The District of New Jersey issued a federal arrest warrant for both men.
Remarks: Mohammad Mehdi Shah Mansouri is an Iranian male with a date of birth of September 24, 1991. He has brown hair and brown eyes and was born in Qom, Iran.
Faramarz Shahi Savandi is an Iranian male who was born in Shiraz, Iran, on September 16, 1984. Both men are known to speak Farsi and reside in Tehran, Iran.
Mohammad Mehdi Shah Mansouri and Faramarz Shahi Savandi begin launching SamSam ransomware attacks against computer networks
A federal grand jury in the United States District Court for the District of New Jersey indicted both men on charges of conspiracy to commit fraud, wire fraud, intentional damage to protected computers, and transmitting ransom demands