• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
moldovan police arrest suspect in €4.5m ransomware attack on dutch

Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency

You are here: Home / General Cyber Security News / Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency
May 13, 2025

Moldovan law enforcement authorities have arrested a 45-year-old foreign man suspected of involvement in a series of ransomware attacks targeting Dutch companies in 2021.

“He is wanted internationally for committing several cybercrimes (ransomware attacks, blackmail, and money laundering) against companies based in the Netherlands,” officials said in a statement Monday.

In conjunction with the arrest, police seized over €84,000 ($93,000) in cash, an electronic wallet, two laptops, a mobile phone, a tablet, six bank cards, two data storage devices, and six memory cards.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The suspect’s name was not disclosed. But he is said to have been detained after a search of his residence in Moldova. In at least one instance, the individual conducted a ransomware attack on the Netherlands Organization for Scientific Research (NWO), causing material damage worth approximately €4.5 million.

The attack took place in February 2021, resulting in the leak of internal documents after the organization refused to pay up. It was attributed to a ransomware crew known as DoppelPaymer.

Cybersecurity

“The attacker blocked network drives, rendered documents inaccessible, and stole some of our files,” NWO disclosed at the time. “Following a demand for a ransom, which NWO cannot and will not accept on principle, the organization published some of the stolen files.”

DoppelPaymer, a ransomware family that first appeared in June 2019, is believed to be based on the BitPaymer ransomware, due to similarities in their source code, ransom notes, and payment portals.

In March 2023, law enforcement authorities from Germany and Ukraine targeted suspected core members of a cybercrime group that has been behind large-scale attacks using DoppelPaymer ransomware.

Germany also issued arrest warrants against three alleged DoppelPaymer operatives – lgor Olegovich Turashev, Igor Garshin (aka Igor Garschin), and Irina Zemlianikina – who are said to be the “masterminds of the criminal group.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «türkiye hackers exploited output messenger zero day to drop golang backdoors Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
Next Post: North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress north korean konni apt targets ukraine with malware to track»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.