Ukrainian sentenced to 12 years and 9 months imprisonment for cyber attack on Stadler Rail

Zurich District Court sentenced a 52-year-old Ukrainian to a prison sentence of 12 years and 9 months. The damage from the attacks is estimated at 100 million Swiss francs.

Ukrainian sentenced to 12 years and 9 months imprisonment for cyber attack on Stadler Rail

Zurich court convicts hacker following ransomware attacks on Swiss company

Zurich District Court has sentenced a 52-year-old Ukrainian to 12 years and 9 months imprisonment for developing and distributing ransomware, according to SRF. In addition to the prison sentence, the court imposed a ten-year ban from the country.

"He was no mastermind," the judge explained when pronouncing the verdict. Nevertheless, the court found it proven that the defendant developed malicious software and passed it on to unknown masterminds. These individuals subsequently selected target companies in Switzerland and abroad and coordinated the extortion.

The defendant had always denied knowing about the criminal use of his software. He described himself as an IT consultant and explained the source code found in his possession in this way. The court rejected this argument — extortion letters were also found in his files.

The verdict even exceeds the prosecution's demand, which had only requested 12 years. The man, who was arrested in October 2021, remains in custody pending further proceedings. The verdict is not yet final; he can appeal it to the higher court and the Federal Court.

Stadler Rail and damage of 100 million Swiss francs

The Ukrainian developed key components of the malware families Lockergoga, Megacortex and Nefilim. In the attack on the rail vehicle manufacturer Stadler Rail, approximately 500 gigabytes of confidential data were stolen. The defendant threatened to publish the data if no ransom was paid. Stadler Rail refused — other companies, however, did pay. Total damage is estimated at 100 million Swiss francs.

Kremlin connections and Russian strategy

The trial, which took place in August, attracted additional attention because of a suspected ringleader within the hacker group who was said to have connections to the Kremlin. This man, also Ukrainian, allegedly had a cover identity of the Russian secret service FSB according to the prosecution. The United States placed a one million dollar bounty on him. In November 2022 he allegedly fell from a window in Moscow under mysterious circumstances.

The prosecutor emphasised that attacks on Western companies are part of a Russian strategy for economic destabilisation. The interests of criminal hackers and state actors would overlap; the Russian state would tolerate or promote this activity. According to the court, such connections to Russian secret services do not apply to the 52-year-old himself.

The defence attorney had requested a complete acquittal as well as compensation for detention. He argued that during the house searches his client was not sufficiently informed of his right to seal the data, and therefore all confiscated data carriers should be declared unusable. The court did not follow this reasoning.

Source: SRF

Read this article in the original language