Swiss Court Sentences Ukrainian Ransomware Developer to 12.75 Years

2 min readSources: The Register

Zurich court sentenced a Ukrainian ransomware developer to 12 years and 9 months in prison.

Why it matters: Cybersecurity lawyers and privacy professionals should monitor this rare, strict sentencing as it signals growing legal consequences for cybercrime. It illustrates intensified efforts to combat ransomware through criminal penalties.

  • On September 10, 2026, a 52-year-old Ukrainian IT specialist received a 12 years 9 months prison sentence from Zurich District Court.
  • The defendant also faces a 10-year ban from entering Switzerland.
  • He developed ransomware tools including LockerGoga, MegaCortex, and Nefilim, used in attacks from December 2018 to May 2020.
  • Damages from the attacks on companies like Stadler Rail, Meier Tobler, and Crealogix are estimated at 100 million Swiss francs (~$123 million).

On September 10, 2026, the Zurich District Court sentenced a 52-year-old Ukrainian IT specialist to nearly 13 years for his role in significant ransomware campaigns. The court also imposed a 10-year ban from Switzerland on the defendant, who had been residing in Basel-Landschaft and held in pre-trial detention since October 2021.

The attacks, which occurred between December 2018 and May 2020, targeted companies including Stadler Rail, Meier Tobler, and Crealogix. The financial damages are estimated at approximately 100 million Swiss francs (around $123 million). The defendant developed ransomware programs such as LockerGoga, MegaCortex, and Nefilim, which were used to extort ransoms from these firms.

The court's sentence exceeded the prosecution's request of 12 years, reflecting the seriousness of the offenses. According to Swissinfo, the court found that the defendant played a key role in orchestrating these attacks with the intent to extort.

This case represents a rare and significant conviction in the cybercrime arena, highlighting increased enforcement focus on ransomware operators. Legal professionals in cybersecurity and privacy sectors should consider its implications for risk management and compliance.

By the numbers:

  • 12 years and 9 months — prison sentence for the defendant
  • 10 years — ban from Switzerland imposed by the court
  • 100 million Swiss francs ($123 million) — estimated damages from ransomware attacks