Swiss Prosecutors Seek 12-Year Sentence for Ukrainian Dev in Multi-Million Dollar Ransomware Case
A Ukrainian software developer faces a 12-year prison sentence in Switzerland for his alleged involvement in an international ransomware operation that inflicted hundreds of millions of dollars in damages. The trial at Zurich District Court links the defendant to attacks utilizing **LockerGoga**, **MegaCortex**, and **Nefilim** ransomware, impacting major European companies.
# Swiss Prosecutors Seek 12-Year Sentence for Ukrainian Dev in Multi-Million Dollar Ransomware Case
Swiss prosecutors are pushing for a 12-year prison sentence and the recovery of 1.8 million Swiss francs ($2.2 million) in alleged criminal proceeds from a Ukrainian software developer. The 52-year-old defendant, whose name remains undisclosed by Swiss authorities, is currently on trial at Zurich District Court.
## Allegations of Ransomware Involvement
The prosecution alleges the defendant played a key role in an international ransomware operation. Victims of the attacks, which utilized **LockerGoga**, **MegaCortex**, and **Nefilim** ransomware, include Swiss train manufacturer **Stadler Rail**, banking software developer **Crealogix**, and building technology company **Meier Tobler**.
The defendant has been in custody since October 2021 and denies developing malware or participating in the attacks. He claims that ransomware source code found on his devices originated from a cybersecurity client for whom he consulted.
## International Investigation Uncovers Extensive Damage
The case stems from an investigation launched in 2019 following ransomware attacks against companies in Zurich. This probe quickly expanded into a multinational effort involving authorities from Switzerland, France, the Netherlands, Norway, Ukraine, and the United States.
Zurich prosecutors accuse the defendant of direct participation in attacks against 10 companies across Switzerland and other countries between December 2018 and May 2020. These incidents are estimated to have caused over 130 million Swiss francs ($160 million) in losses, encompassing lost revenue and system rebuilding costs.
## Alleged Ties and Denials
Prosecutors further allege that another Ukrainian hacker, **Oleksandr Ieremenko**, operating from Moscow, directed attacks carried out by the defendant in Switzerland. Swiss journalists attending the hearing reported testimony from a Ukrainian source claiming Ieremenko received protection from Russia's **Federal Security Service (FSB)**.
Ieremenko reportedly died in 2022 after falling from a Moscow window, though prosecutors could not definitively determine the cause of death. Crucially, the prosecution did not present evidence directly linking the defendant to Russian intelligence.
## Digital Evidence Under Scrutiny
The defense has challenged the digital evidence presented, arguing that investigators failed to maintain complete records of the data seized during the probe.
## Additional Charges
Beyond the ransomware allegations, the defendant also faces charges related to child sexual abuse material. Swiss media reported that investigators discovered nearly 7,000 images and over 500 videos depicting child sexual acts within an encrypted file container during a search. Earlier Federal Supreme Court records confirm these pornography offenses are part of the criminal proceedings.
A verdict in the case is anticipated in September.