cybercrime
Ukrainian hacker receives nearly 13-year sentence for Swiss ransomware attacks
A Zurich court sentenced a Ukrainian IT specialist to 12 years and nine months for his role in ransomware attacks that allegedly caused around CHF100 million in damage, including to Stadler Rail.

Zurich court delivers a landmark ransomware sentence
A Zurich court has sentenced a Ukrainian IT specialist to 12 years and nine months in prison, delivering one of Switzerland's most significant ransomware convictions. The court also ordered a 10-year ban from Switzerland. The judgment was handed down on Thursday, September 10, and reported by Keystone-SDA on September 11, 2026.
The 52-year-old defendant, who lived in Basel Country, was convicted over his role in attacks against Swiss and international companies. Prosecutors estimated the resulting damage at around CHF100 million, or about $123 million. The campaign targeted firms including rail manufacturer Stadler Rail, heating and building technology company Meier Tobler, and software provider Crealogix.
The court found that the defendant developed ransomware used to lock corporate data and helped make the extortion operation possible. Prosecutors had requested a 12-year sentence. Judges imposed a longer term after assessing the defendant's contribution to the attacks.
He has been in pre-trial detention since October 2021. The ruling places responsibility on a technical specialist who, according to the court, supplied the tools and expertise that enabled attacks far beyond any single victim.
Stadler Rail breach exposed the value of stolen data
Around 500 gigabytes of Stadler Rail data was stolen during one attack, according to the case record. The hackers threatened to publish the confidential material and demanded a ransom. Stadler Rail refused to pay.
The attack placed a major Swiss industrial company at the centre of a criminal model that combines data theft with encryption. Ransomware operators first disrupt internal systems, then use stolen files to increase pressure on executives, customers and suppliers. The prosecution linked the wider campaign to losses estimated at CHF100 million, although some targeted companies did pay.
Stadler Rail, based in Bussnang, Thurgau, manufactures trains for markets around the world. A breach at a company with complex production, engineering and supply-chain systems can affect more than office computers. Confidential designs, commercial documents and information exchanged with partners can all become leverage in an extortion campaign.
The 2020 incident also showed how quickly a Swiss corporate breach can become an international story. In an earlier report, Swissinfo said attackers demanded $6 million in Bitcoin for the return of Stadler documents. The current conviction gives the episode a courtroom conclusion, while leaving the stolen data and the wider criminal network in focus.
The court separates the coder from the operators
The court identified three ransomware families at the centre of the case: Lockergoga, Megacortex and Nefilim. Judges described the defendant as their lead developer. These programmes encrypted data belonging to targeted companies and formed the technical backbone of the extortion attempts.
The ruling drew a line between software development and the people who selected victims, coordinated attacks and issued demands. The judge said the defendant was not the mastermind. He developed the malware and passed it to instigators who remain unknown. That distinction shaped the court's account of the operation, but it did not remove his criminal responsibility.
The defendant denied knowing that his software would be used for crime. He said he worked as a consultant for an unknown client in IT security, explaining that source code was found at his home. Prosecutors countered with evidence that extortion messages were also stored among his data. The court rejected his explanation.
The case illustrates the difficulty investigators face when cybercrime is divided among coders, brokers, operators and negotiators. A developer may never enter a victim's network, yet the tools he creates can determine the scale and speed of an attack.
A shadow network remains outside the courtroom
The case also introduced a suspected link to Russian intelligence services and an alleged instigator who died in Moscow. During the August trial, prosecutors said the defendant's alleged contact had cooperated with Russian secret services before falling from a window in Moscow in November 2022.
The man was reportedly a Ukrainian hacker using a false identity supplied by Russian intelligence services. The United States had offered a bounty for information about him, according to the prosecution's account. These claims formed part of the trial's wider picture of overlapping criminal and state interests, though the Zurich judgment focused on the defendant's own conduct.
Prosecutors connected the ransomware attacks to a Russian strategy of creating disorder and economic damage in Western countries. Criminal groups can operate in an environment where state actors tolerate or exploit their activity. Attribution remains difficult because attackers conceal identities, use intermediaries and move infrastructure across jurisdictions.
The alleged instigator is dead and other organisers remain unidentified. That leaves Swiss investigators and prosecutors with a conviction against one participant, while the people who allegedly directed the attacks remain outside the courtroom.
Switzerland faces the next wave of attacks
Switzerland faced roughly 200 ransomware attacks attributed to the Akira group in a separate 2025 assessment, showing that the Zurich conviction addresses one campaign within a continuing threat. Swiss authorities said Akira had intensified its activity and targeted companies across the country.
The cases affect more than large industrial firms. Ransomware can interrupt hospitals, manufacturers, municipalities, retailers and smaller suppliers whose systems connect to larger corporate networks. The Stadler case demonstrates the additional risk created when attackers copy sensitive files before encrypting systems. Refusing payment may avoid financing criminals, but it does not guarantee that stolen information will remain private.
The Zurich ruling also reinforces the importance of preserving digital evidence. Source code, extortion messages and records held on personal devices helped prosecutors challenge the defendant's account. International cooperation remains essential because the attackers, servers, victims and cryptocurrency transactions can span several legal systems.
The sentence will not identify the unknown organisers or recover every loss linked to the campaign. It does establish that Swiss courts can impose substantial penalties when a technical specialist knowingly enables ransomware attacks, even when that person is not the final decision-maker.