Home › Intelligence › Brief
BREACH BRIEF 🟠 High Ransomware

Swiss Court Sentences Ukrainian Ransomware Developer to 12 Years 9 Months for LockerGoga, MegaCortex, and Nefilim Campaigns

A Zurich court sentenced a Ukrainian ransomware developer to nearly 13 years for creating LockerGoga, MegaCortex and Nefilim, which caused CHF 100 million in damage worldwide. The case underscores the importance of continuous control‑assurance and evidence‑ready incident response for audit readiness.

Verisq™ Intelligence · 📅 September 25, 2026 · 📰 bitdefender.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
bitdefender.com

Swiss Court Sentences Ukrainian Ransomware Developer to 12 years 9 months for LockerGoga, MegaCortex, and Nefilim Campaigns

What Happened – A Zurich court sentenced a 52‑year‑old Ukrainian man to 12 years 9 months in prison and a ten‑year ban from Switzerland for creating the LockerGoga, MegaCortex and Nefilim ransomware families. The malware was used against global enterprises—including Norsk Hydro, Stadler Rail, Hexion and Momentive—causing roughly CHF 100 million in damages and, in some cases, the theft of confidential data.

Why It Matters for Trust & Control Assurance

  • The case highlights the need for continuous monitoring of third‑party code and supply‑chain risk to detect malicious tooling before it is weaponised.
  • Effective incident‑response and evidence‑preservation processes are essential to demonstrate a defensible audit trail after a ransomware event.
  • Mapping ransomware‑related controls to a unified framework provides reusable proof for multiple compliance regimes.

Who Is Affected – Manufacturing (aluminium, chemicals, rail), industrial engineering, and any organisation that relies on on‑premise OT/IT networks.

Recommended Actions

  • Review and map your ransomware‑response controls (backup integrity, network segmentation, incident‑response playbooks) to the Verisq Common Framework.
  • Implement continuous evidence collection for backup testing, log retention, and third‑party code reviews.
  • Conduct tabletop exercises that simulate a LockerGoga‑style encryption event and capture audit‑ready documentation.

Source: Bitdefender Blog – Ukrainian ransomware developer jailed for nearly 13 years

Technical Notes

  • Ransomware families: LockerGoga, MegaCortex, Nefilim.
  • Damage estimate: ~CHF 100 million (≈ US $123 million).
  • Notable victim outcomes: network shutdown at Norsk Hydro; 500 GB data exfiltrated from Stadler Rail (no ransom paid).
  • Bitdefender released a free LockerGoga decryptor in 2022, enabling victims to recover files without paying.

Source: same as above

📰 Original Source
https://www.bitdefender.com/en-us/blog/hotforsecurity/ukrainian-ransomware-developer-jailed-for-nearly-13-years ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →