The person at the center of this case
Volodymyr Viktorovych Tymoshchuk (fugitive suspect)
Justice for Volodymyr Viktorovych Tymoshchuk (fugitive suspect) — the trail went cold in 2024, but the truth hasn't.
Start here
What is Tymoshchuk's current location given his known ties to Eastern Europe and Russia?
How many companies paid ransom to the LockerGoga, MegaCortex, and Nefilim operators, and what was the total financial impact?
Who were Tymoshchuk's co-conspirators in the ransomware operation, and have they been identified or apprehended?
Volodymyr Viktorovych Tymoshchuk is an alleged ransomware administrator who, between December 2018 and October 2021, deployed LockerGoga, MegaCortex, and Nefilim ransomware variants to compromise hundreds of companies worldwide, including over 250 in the United States, to extort ransom payments. A federal arrest warrant was issued on May 7, 2024, in the Eastern District of New York after charges including conspiracy to commit fraud, intentional damage to protected computers, unauthorized access, and transmitting threats to disclose confidential information. Tymoshchuk remains at large with suspected ties to Poland, Romania, Moldova, Türkiye, Russia, and Belarus, and a reward of up to $10,000,000 is offered for information leading to his capture.
Try asking
A one-time $10 claim transfers this imported case workspace to your account. You get 10 uploads for this case, 25 daily AI questions for this case, and public tips with files route to you.
This does not start a subscription. When the included limits are reached, the Personal plan unlocks more workspace capacity.
Beyond the top three above — each detail below could be the thread that pulls this case open.
What specific infrastructure or financial accounts can be traced to identify Tymoshchuk's whereabouts or associates?
Even the smallest detail could be the key to solving this case.
Official wording
Conspiracy to Commit Fraud and Related Activity in Connection with Computers; Intentional Damage to a Protected Computer; Unauthorized Access to a Protected Computer; Transmitting a Threat to Disclose Confidential Information Caution: Volodymyr Viktorovych Tymoshchuk is an alleged ransomware administrator of at least three different ransomware variants. From December of 2018, through October of 2021, Tymoshchuk and his co-conspirators allegedly deployed LockerGoga, MegaCortex, and Nefilim ransomware, which compromised the computer networks of hundreds of companies around the world, including more than 250 companies in the United States, in order to extort ransom payments from the victim companies.
On May 7, 2024, a federal arrest warrant was issued for Tymoshchuk in the United States District Court, Eastern District of New York, Brooklyn, New York, after he was charged with two counts of Conspiracy to Commit Fraud and Related Activity in Connection with Computers; multiple counts of Intentional Damage to a Protected Computer; Unauthorized Access to a Protected Computer; and Transmitting a Threat to Disclose Confidential Information. Remarks: Tymoshchuk has ties to Poland, Romania, Moldova, Türkiye, Russia, and Belarus.
Deployment of LockerGoga, MegaCortex, and Nefilim ransomware variants begins
Final known deployment of ransomware variants by Tymoshchuk and co-conspirators
Warrant issued in United States District Court, Eastern District of New York, Brooklyn, New York for charges including conspiracy to commit fraud and computer crimes
For information leading to the resolution of this case
For information leading to the resolution of this case