Security News

Ransomware Coder Behind LockerGoga, MegaCortex and Nefilim Jailed in Switzerland

The Register · 15 Sept 2026
Key Takeaway This case is a reminder that ransomware operations involve organised networks of specialists, so businesses should maintain strong backups and incident response plans rather than assume attackers are lone amateurs.

A Zurich District Court has sentenced a 52-year-old Ukrainian man to 12 years and nine months in prison for developing the LockerGoga, MegaCortex, and Nefilim ransomware strains. The court found he was not the mastermind of the operations, but played a key technical role, and he has also been banned from Switzerland for ten years. The judgment can still be appealed.

The man, held in pretrial detention since October 2021, claimed the ransomware source code found at his home came from legitimate IT security consulting work. The court rejected this defence after investigators also found extortion messages among his data. He was found guilty of involvement in attacks on Swiss firms including Stadler Rail in 2020, as well as HVAC company Meier Tobler and software company Crealogix.

Swiss prosecutors previously linked the broader criminal network to attacks on more than 1,800 victims across 71 countries, with losses estimated in the hundreds of millions of Swiss francs. Other alleged members of the operations have not been publicly named, though a separate individual, Volodymyr Tymoshchuk, was indicted in the US last year and described as the mastermind behind all three ransomware crews.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.