CASE DOSSIER
sentenced
U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware)
Docket: 3:21-cr-00314 Court: U.S. District Court for the Northern District of Texas Opened: 2021-08-11 Sector: Managed Service Providers, Information Technology, Retail, Education
Key Facts
Status
SENTENCED
Legal disposition
Loss Amount
$70.0 million
Extortion demands totaled $70 million for universal decryptor; extensive operational stoppage across schools, grocery stores, and local governments.
Techniques
5
Verified mappings
Defendants
2
Named in charges
- Legal Status: SENTENCED in U.S. District Court for the Northern District of Texas.
- Primary Target Sector: Managed Service Providers, Information Technology, Retail, Education.
- Documented Financial Loss: $70.0 million.
- 5 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
Ukrainian national and REvil ransomware affiliate responsible for deploying the ransomware attack that hijacked Kaseya VSA management software, instantly encrypting up to 1,500 downstream businesses on July 4th weekend.
Procedural & Incident Timeline
2021-10-08 arrest
Vasinskyi arrested by Polish authorities at the Polish-Ukrainian border.
2022-03-03 extradition
Extradited from Poland to the Northern District of Texas.
2022-11-01 plea
Pled guilty to conspiracy to commit computer fraud and damage, money laundering, and related charges.
2024-05-01 sentencing
Sentenced to 163 months (over 13 years) in federal prison and ordered to pay $16 million in restitution.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Yevgeniy Polyanin | Russian Federation | fugitive | Pending | $6.1 million | REvil affiliate indicted in N.D. Tex.; $6.1 million in ransom proceeds recovered by DOJ. |
| Yaroslav Vasinskyi | Ukraine | sentenced | 156 mo | None | REvil ransomware affiliate who carried out the Kaseya VSA attack. Sentenced to over 13 years in federal prison. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Vasinskyi exploited zero-day authentication bypass and SQL injection vulnerabilities in internet-facing Kaseya VSA servers." | Indictment ¶ 14, Page 7 | reviewed |
| T1574.002 | DLL Side-Loading Persistence | "The attacker used DLL side-loading with an outdated signed Windows Defender executable (MsMpEng.exe) to execute the REvil ransomware payload." | CISA Advisory AA21-189A | reviewed |
| T1486 | Data Encrypted for Impact Impact | "Over 1,500 downstream client networks were locked with Salsa20 encryption in a synchronized automated broadcast on July 2, 2021." | Indictment ¶ 16, Page 8 | reviewed |
| T1569.002 | Service Execution Execution | "Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks." | Indictment ¶ 15, Page 8 | reviewed |
| T1082 | System Information Discovery Discovery | "The REvil dropper checked host architecture and operating system language, aborting execution if Russian locale strings were detected." | CISA Advisory AA21-189A | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Yaroslav Vasinskyi (Kaseya VSA / REvil Ransomware), No. 3:21-cr-00314 (U.S. District Court for the Northern District of Texas 2021), https://cyberattackcaselibrary.pages.dev/cases/us-v-vasinskyi-kaseya-revil/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/us-v-vasinskyi-kaseya-revil" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>