Mikhail Matveev holding his left hand to the camera, showing that his ring finger is missing.
He opens the video by holding up the hand. The ring finger is the proof.

The Tolerated / File 05 / Mikhail Pavlovich Matveev

Four
Fingers

The United States wants him on eight counts across two indictments, and has offered ten million dollars for him. He printed the wanted poster on a shirt and captioned it "peekaboo." In February 2025 a court in Kaliningrad sentenced him to eighteen months of curfews and a ban on nightclubs. Nobody in Russia reported it.

01 / The signatureThe man who proves he exists by showing what is missing

Every claim on this page carries one of these.

ConfirmedCredibleAnalyst inference

The FBI's wanted notice carries a physical description most wanted notices do not. Under "Scars and Marks" it records a full-sleeve tattoo on the right arm with moons, planets, meteors, a large fish and sting rays, and then the line that does the work: he only has four fingers on his left hand, where he is missing his left ring finger. Confirmed

The FBI wanted poster for Mikhail Pavlovich Matveev, showing four photographs and the description of his scars and marks.
The federal wanted poster, a United States government work. Four photographs, the aliases, the date of birth, and the physical description quoted above. Every photograph of him on this page also appears here, which is what anchors the identification: the government published them.
Matveev photographed shirtless in a field, showing the full-sleeve tattoo on his right arm.
The sleeve itself: celestial objects and sea creatures, right arm, full length, exactly as the description has it.

He has turned the absence into a personal watermark. He opens his videos by holding the hand to the lens. When a reporter at TechCrunch asked him to prove he was really himself in 2023, he sent a photograph of the same four fingers and a selfie holding a sheet of paper with the reporter's name on it. Credible

Two accounts of how he lost it are on the record and they do not match. Brian Krebs relayed the story circulating on the forums, that he wagered the finger on a bet, lost, and severed it himself, and hedged it in the same breath: "It's unclear if that is the real story." Matveev himself later told TechCrunch something far more boring, that he crushed it in 2017 installing a 35 kilogram server cabinet and needed surgery. Which is true, if either, has never been established, and it will not be established from a photograph. Credible

In September 2023 he offered the story to a journalist and then walked away mid-sentence. TechCrunch had put a dozen questions to him about life as a wanted man. He answered none of them, objected instead to being called a hacker, and explained that "we are a separate type of specialist, practical and using our knowledge and resources without water and writing articles." Then, in the same message:

I was interested only in terms of financial motivation, roughly speaking, I was thinking about what to do, sell people or become. it, [sic] let me tell you how I lost my finger?

Direct message to TechCrunch, September 2023, quoted exactly as published. The [sic] is TechCrunch's, not ours: the sentence collapses in his own text. He offered the finger story and then stopped answering.

How the name was attached to the man

The attribution is unusually solid and it does not rest on a leak. In January 2022 Krebs on Security walked a chain of reused credentials: three passwords recurring across a decade of forum accounts, an old email address that also registered a VKontakte profile under "Mikhail Mix Matveev," a MegaFon phone number issued in Khakassia, and an ICQ number surfacing in a 2009 post from a town of about 4,400 people. Intel 471, asked to comment, said it had independently reached the same name. Credible

Then he confirmed it himself, on the record, to Recorded Future's Dmitry Smilyanets in an August 2022 interview, acknowledging Babuk, BorisElcin, unc1756 and Orange as his, and denying exactly one: Kajit. The United States adopted the identification wholesale in May 2023, using the same date of birth, 17 August 1992, that the open-source work had implied. Confirmed

He is from Khakassia in southern Siberia, and the trail runs through Abaza, Abakan and a village called Kopyovo. That origin has never been reported by a single Russian outlet. Every Russian story about him says only "a Kaliningrad resident, 32." It exists solely in Krebs's work. Credible

02 / The bitA comedian with a ten million dollar bounty

Most people in this line of work respond to being identified by going dark. Matveev responded by starting an account.

The tape

Krebs published the name on 12 January 2022. Someone registered the Twitter account @fuck_maze the same day. The handle was a shot at Maze, a ransomware crew that had already been dead for a year, which is roughly the energy of turning up to a fight that finished last Christmas. The header logo read "Waka Waka." The bio existed mainly to insult Dmitry Smilyanets. Credible

The account messaged Krebs a few times, then went quiet for thirteen days. On 25 January it posted three selfie videos.

Two of the three, uploaded by Brian Krebs to his own channel and titled by him. They are restricted so they cannot be played inside another page, so these open on YouTube. Krebs had published his name thirteen days earlier. He is slurring badly enough that YouTube's automatic captioning could not follow him at all: one reader, trying to keep up in the comments underneath, transcribed a stretch of it as "bitterly we drove here to disgrace a strand in the these languages ... roosters declare war on the US?" No timecodes were ever published.

The man in them is slurring badly. He begins by holding up his left hand, which in Krebs' phrasing "he smugly presents as evidence that he is indeed Wazawaka." It is a rare thing, a wanted man using a mutilation as a verified badge. Credible

He then works down a list. Obscenities at Smilyanets. Obscenities at Catalin Cimpanu, also of The Record. Obscenities at a researcher from Cisco Talos. He declares war on the United States and calls Americans петухи, which in Russian prison slang is not a word about sexuality but about rank: the lowest caste, men broken by sexual violence and untouchable afterwards. Credible

And then he turns to the man who had just stripped his anonymity, and becomes, briefly and bewilderingly, a fan:

Hello Brian Krebs! You did a really great job actually, really well, fucking great [...] it is great that journalism works so well in the US. By the way, it is my voice in the background, I just love myself a lot.

Video posted to @fuck_maze, 25 January 2022, reported by Krebs on Security. Six words that explain the entire career: I just love myself a lot.

He also announces, on camera, that he is about to drop exploit code. Later the same day he did: working code for a SonicWall virtual private network flaw, catalogued as CVE-2021-20028. Four months earlier, posting as Boriselcin, he had offered on the Russian crime forum XSS to pay handsomely for a working exploit for that exact vulnerability. So he bought it, sat on it, and then gave it away free to strangers to make a point about American journalism. When the Treasury sanctioned him sixteen months later, the designation noted that he had "disclosed exploit code to online criminals." ConfirmedCredible

The performance drew reviews. A Russian speaker in the comments supplied both a translation and a verdict: he "leaves an impression of a low-class crook from the streets, who also appears to be under drugs. I think I lost a few IQ points listening him talk." His former colleagues were shorter about it. Krebs opens the piece by reporting that Wazawaka had, in their assessment, "lost his mind." Credible

The shirt

In the autumn of 2023, from an account called @ransomboris, he posted a photograph of a garment printed with his own wanted poster, ten million dollar reward included. The caption was two words of Russian: Ку ку. Peekaboo. Minutes later he posted again, asking his followers whether they wanted merchandise. Credible

A white T-shirt printed with the FBI reward poster for Matveev, photographed and posted by him.
The reward notice, worn. He photographed it, captioned it "peekaboo," and asked his followers whether they wanted more. No shop, price or completed sale has ever been documented.

A fortnight after the shirt he posted a video of himself driving around listening to Metallica, on camera, talking about how good life was. He deleted it after TechCrunch published. Credible

The weather is good, the climate is good, everything is good. Even the sanctions make me happy. Lots of people saying fake stuff.

Selfie video, @ransomboris, around 17 September 2023, reported by TechCrunch.

Asked by the Click Here podcast in May 2023 how it felt to be on the FBI's cyber most wanted list with ten million dollars on his head, he produced a Russian proverb and a complaint about accounting: "It won't affect my work. The dog barks, but the caravan moves on." And then: "the money that DOJ attributes to me, I don't have this money, where did they get those numbers from? I'm interested." That second remark turns out to be closer to true than anything else he has said in public. Credible

The self-awareness runs deeper than the clowning suggests. Among the handles Intel 471 tied to him are arestedByFbi, posholnarabotu ("went off to work") and popalvprosak ("got into a jam"). He was naming accounts after his own arrest years before there was an indictment. He also knows exactly what the noise costs, because he diagnosed it in a rival and kept going anyway: "They made too much noise, probably like I'm doing now, at a time when it was not necessary to make such noise." Credible

03 / The billWhat the joke is attached to

Here is where the comedy stops paying for itself. In December 2022 a grand jury in the District of New Jersey returned a six-count indictment covering three ransomware conspiracies, and a second indictment followed in the District of Columbia covering the police attack. The first paragraph of the New Jersey filing has been misreported almost everywhere since.

MATVEEV and the other members of these three ransomware conspiracies attacked at least as many as 2,800 victims in the United States and around the world and made ransom demands to these victims of at least $400 million. Actual ransom payments from these victims to these perpetrators amounted to over $200 million.

Indictment, District of New Jersey, paragraph 1, unsealed 16 May 2023. $400 million is demands. $200 million is payments. Both are totals for LockBit, Babuk and Hive combined, across hundreds of people. Neither is his.

OperationCharged windowAttacksDemandedReceived
LockBitJan 2020 onward~1,400~$100Mup to $75M
BabukDec 2020 to Sep 2021~65~$49Mup to $13M
HiveJun 2021 onward~1,400~$270Mup to $120M

Source: District of New Jersey indictment, paragraph 2(b). Babuk, the operation he is most associated with and the one he actually helped run, is the smallest of the three by an order of magnitude. Confirmed

The first attack charged against him, on 25 June 2020, was on a police department. Not a large one: Prospect Park, New Jersey, a borough of some 5,800 people. The indictment declines to name it, local reporting did, and he discussed it himself. Ten months later came a considerably bigger police force. ConfirmedCredible

Washington DC, April 2021

On 26 April 2021 Babuk ransomware was deployed against the Metropolitan Police Department of the District of Columbia. The intrusion is reported to have begun around 19 April, and Matveev, posting as Boriselcin, later claimed on XSS that the way in was the department's virtual private network. ConfirmedCredible

Roughly 250 gigabytes came out. Credible

The Treasury described the contents in its own words when it sanctioned him:

The hackers stole the home addresses, cellphone numbers, financial data, medical histories, and other personal details of police officers, along with sensitive information about gangs, suspects of crimes, and witnesses.

US Department of the Treasury, 16 May 2023. Primary text. Confirmed

Reporting at the time added disciplinary records, polygraph results, psychological evaluations, credit histories and a gang database, in personnel files running past 100 pages each. Credible

Babuk demanded four million dollars and threatened, if the department did not respond within three days, to contact DC street gangs directly and identify police informants to them. Credible

An informant is a person who has agreed to talk about people who kill for less. Their protection is not a password or a firewall. It is the fact that nobody knows. The threat was not to publish a database. It was to walk the names to the people the names would get killed by, and it was made in writing, with a deadline, as a negotiating tactic.

The department, according to screenshots Babuk itself published, offered one hundred thousand dollars. Credible

Our final proposal is an offer to pay $100,000 to prevent the release of the stolen data. If this offer is not acceptable, then it seems our conversation is complete. I think we both understand the consequences of not reaching an agreement. We are OK with that outcome.

The Metropolitan Police Department to Babuk, per the group's own published screenshots, May 2021. The department has never confirmed or denied them. We are OK with that outcome is a police force deciding, in writing, what its informants are worth.

The department did not pay. Around 29 April five officers' files went up. On 11 May, twenty-two more. On 13 May the full 250 gigabytes was dumped, posted with a Police Academy meme and the line "Look at this wall of shame, you have every chance of not getting there, just pay us!" The joke and the informant list went out in the same upload. Credible

Collection gap: the downstream harm

This is among the most damaging police data breaches in US history and there is essentially no public accounting of what it cost. NBC News found two affected officers who said the department had never told them their information was taken. We could locate no public record of resulting discipline, resignations, harm to any named informant, or litigation.

Routes in, for a later update: District of Columbia Council oversight hearings, the department's Inspector General, and any breach notifications obtainable under freedom of information law.

One qualification matters and it cuts in his favour. He told Recorded Future he did not carry out the attack, that a Babuk affiliate did the whole thing, and that when the police data landed the affiliates "shat their pants and ran" and begged him not to publish. The Treasury's own wording is careful in the same direction: it says he claimed responsibility for posting the stolen data, not for the intrusion. He is charged as a conspirator, which does not require him at the keyboard. ConfirmedCredible

The argument that broke Babuk

The group did not split over money. It split over whether to dump the police files for publicity. A Babuk member told BleepingComputer that the admin wanted the leak and everyone else did not.

We're not good guys, but even for us it was too much.)

A member of Babuk, to BleepingComputer, 2021. The closing bracket is a Russian smiley, the equivalent of a colon and a bracket with the eyes left off. He is smiling as he says it. Matveev published anyway, and the group fractured within weeks.

This was doctrine for him, not impulse. Two years earlier, posting as Uhodiransomwar, he had laid it out: "the information that you steal should never be sold. The community needs to receive it absolutely free of charge if the ransom isn't paid." It is the one principle he appears to have actually held, and it is the one that destroyed his own organisation. Credible

Two sets of victims paid him and got nothing

In the same interview he described a bug in Babuk's decryptor for VMware ESXi, the software that runs a company's virtual servers. It zeroed the disks it was supposed to restore. At least two companies paid and lost their data anyway. One, a Dutch logistics firm, paid two million dollars, a sum he says he had never handled before: "I have never had such an amount in my wallet." They asked for the money back. Credible

They just weigh zero KB. Well, everything is fucked. [...] And they asked to return the money. Well, we had no choice but to block them. We scammed them for this money. I still blame myself for this.

To Recorded Future, August 2022. The man whose stated principle was that stolen data should never be sold also took two million dollars for a decryptor he knew did not work.

He also claims the attack on the games company Capcom, entered through a Fortinet flaw, and says that is where the name Babuk came from: a disused domain administrator account on Capcom's network called Babak. Credible

What followed the split was worse for everyone else. In September 2021 the full Babuk source code was posted to a Russian forum by a member claiming to be dying. SentinelLabs later counted at least ten ransomware families built on that leaked code, several of which individually out-earned Babuk. Matveev made nothing from any of it. Credible

04 / The moneyEvery figure attached to him belongs to somebody else

The $400 million in demands and the $200 million in payments are totals for LockBit, Babuk and Hive combined, across hundreds of people and five years. Neither number is his, and the indictment does not claim they are. Confirmed

He has said as much himself, and on this narrow point he is right:

The money that DOJ attributes to me, I don't have this money, where did they get those numbers from? I'm interested.

To the Click Here podcast, Recorded Future News, May 2023. Nobody has ever published an answer.

The only granular figure he has ever put on his own earnings is a boast on a criminal forum: roughly $500,000 in LockBit commissions across the six months to September 2020. Before ransomware he was charging about $80 a day for denial-of-service attacks and stealing from drug dealers' payment accounts. Credible

Blockchain analysis firms say they have identified wallets belonging to him. None has published a total. Intel 471 estimated at the time of his detention that he held "tens of millions of dollars in cryptocurrency," an assessment offered without arithmetic. What can actually be traced, by whom, and whether any of it is ransom money rather than the proceeds of the years before, is not in the public record. Analyst inference

Collection gap: what he is worth

Nobody outside a grand jury room has published a figure for what Matveev personally took. We hold partial wallet attribution that we are not publishing, because a partial view of one cluster cannot carry a claim about a man's wealth and would be worse than saying nothing.

What would settle it: a published cluster total with an active date range. The date range matters more than the sum. If the traceable money stops before mid-2020, it is not ransomware money at all, and none of the actual ransoms has ever been followed.

The forum he built and gave away

RAMP, which he founded in July 2021 on Babuk's old Tor address, was for four and a half years the only significant place on the internet where ransomware could be openly advertised. By his own account it never turned a profit, was constantly knocked offline, and cost him money and patience: "God, why did I sign myself up for this?" Credible

His account of how he got rid of it is worth having in his own words, because it is usually reported wrongly. He did not hand the forum to its eventual administrator. He recruited a moderator called Kajit, told him "be a moderator, verify everyone, and I will toss some cash your way," and then, in his telling, hit the bottle hard and lost interest: "That's how the forum actually fell into the hands of Kajit." Screenshots of affiliate control panels then leaked, operators complained to him directly, and he opened a formal complaint against Kajit on another forum. The XSS administrator told Kajit to pass the site on. What happened next Matveev only reports second hand: "as far as I know, Stallman got it." Credible

The FBI seized RAMP on 28 January 2026, in coordination with the United States Attorney's Office for the Southern District of Florida. The seizure banner reproduced the forum's own slogan, THE ONLY PLACE RANSOMWARE ALLOWED, beside a winking Masha from the Russian children's cartoon Masha and the Bear. No formal announcement was ever made and the FBI declined to comment. Matveev was not named and said nothing publicly when it fell. Credible

05 / CorrectionThe Conti claim, tested

A large number of outlets have written that the 2023 indictments named Matveev as an affiliate of five gangs including Conti and DarkSide. They do not. We read the New Jersey indictment. It names LockBit, Babuk and Hive and nothing else. Conti and DarkSide appear nowhere in it, nor in the Justice Department release, nor in the sanctions designation, nor on the State Department reward page. Confirmed

The Conti claim traces to a single vendor report published by Prodaft in December 2023, based on communications the firm says it intercepted that year. The DarkSide claim traces to one boast Matveev made on the Exploit forum, uncorroborated by anything since, and it is his own boast rather than a finding. CredibleAnalyst inference

Original work: we searched the Conti leaks ourselves

The largest primary corpus of Conti internal communications is public. We took the complete translated release of the February 2022 leaks, 583,830 rows spanning June 2020 to February 2022 across the two Jabber archives and the Rocket.Chat archive, and searched it for twenty-seven handles attributed to Matveev by the FBI, by the Treasury and by Intel 471.

boriselcin, uhodiransomwar, unc1756, tetyasluha, biba99, matveev, Матвеев, бориселцин and the rest of the Intel 471 set: zero hits. Every apparent hit on m1x is a fragment inside a block of encoded text or a Tor address, and all 43 hits on orange are artifacts of a victim's network, a colour, or a fruit. None refers to a person.

wazawaka appears exactly once in 583,830 rows, and it is not a colleague talking. On 14 February 2022 a Conti member pastes the Krebs article about him into the general channel with a jeer: "magic mushrooms will bring you to tsugunder, it would be better if you, wazawaka, took up physical education."

Babuk appears three times, all in Conti's internal news digest. On 1 May 2021 the member handled "mango" reports upward, to Stern and to Reshaev, that Babuk had announced it was closing and had published its locker source, and repeats it to Stern on 5 May. Stern is already a file on this site. The corpus supplies no English for those three rows; the translation is ours.

The corpus ends in February 2022, so it cannot speak to anything Conti did afterwards, including Costa Rica in April. It does mean that in the single richest primary record of Conti's inner life, Matveev is not a member, not a partner and not a contact. He is a news item, and the tone is contempt. The search result is reproducible by anyone. The reading of it is ours. Confirmed Analyst inference

Costa Rica, and the credit he never claimed in public

In April 2022 Conti attacked the government of Costa Rica, took 672 gigabytes from the finance ministry and other agencies, demanded ten million dollars and then twenty, and told Costa Ricans it intended "to overthrow the government by means of a cyber attack." On 8 May, his first day in office, President Rodrigo Chaves declared a national state of emergency, the first any country has declared over ransomware. Weeks later Conti dismantled itself. Confirmed

The attack was claimed on Conti's leak site by an actor calling himself unc1756. Matveev is widely credited with it. That credit rests on a thinner thread than almost anyone repeating it realises.

On 20 July 2022 the research collective vx-underground said the Costa Rica claimant was on Twitter. Fifteen minutes later another researcher posted the link to Wazawaka. Five weeks after that, Dmitry Smilyanets read Matveev a list of six aliases, hyperlinking the word "unc1756" to that same tweet, and asked whether they were all his. Matveev said yes to the list and denied exactly one name, Kajit. Every subsequent report that he claimed Costa Rica traces back through those two afternoons. Credible

Three things sit awkwardly with it. unc1756 was a two-month-old account on the Exploit forum, while Boriselcin had a decade of standing, and no one has ever published a technical bridge between them. Costa Rica is not mentioned once in the interview that supposedly confirms the claim, and neither is Conti; Smilyanets asked him about the police attack, about RAMP, about the security services, and never about the country that had just declared a state of emergency. And the label itself is borrowed plumage: "UNC" followed by four digits is the naming convention Mandiant uses for threat groups it has not identified, and Mandiant never had a UNC1756. Credible

The firm with the deepest visibility into Conti's internal communications, AdvIntel, says the intrusion was run by one of Conti's own operators, and that while the public demand climbed to twenty million dollars the sum discussed internally was under one million. On that account the ransom was theatre, staged so a dying brand could perform its own death loudly. A persona claiming credit for a performance is not the same as a man who did the work. Credible

Against all of that sits the one piece of evidence that does not depend on the alias at all. Prodaft, reading intercepted communications in 2023, reports that Matveev admitted in a private conversation to orchestrating the Conti attack on Costa Rica, and records a member of his own team joking about getting his copy of a Group-IB report signed as a souvenir. That is him claiming it under his own name, to his own people, with nobody to impress. Credible

So the position is this. He has never claimed Costa Rica in public, across four on-record interviews, which for a man who printed his own wanted poster on a shirt is a remarkable omission. He appears to have claimed it in private. No government document connects him to Conti or to Costa Rica, and the reporting that does connect him rests on him agreeing to a list of names. He is credited with the last act of the largest ransomware brand in history on evidence that would not survive a preliminary hearing. Analyst inference

06 / The roofEighteen months of no nightclubs

The reason this file exists is that none of the above has cost him very much.

The structural facts require no conspiracy at all. There is no extradition treaty between the United States and Russia, and Article 61 of the Russian Constitution forbids the extradition of Russian citizens under any circumstances. The only realistic route to a US courtroom runs through a third country, which is the route he closed himself. He told TechCrunch in October 2023 that he had burned his foreign travel passport, and that the sanctions were, in his reading, a security feature. ConfirmedCredible

My life has changed for the better after the sanctions, I don't feel them on me, as well as sanctions are a plus for my security, so sanctions help us.

To TechCrunch, 3 October 2023. His last foreign trip was Thailand in 2014, where he reports having eaten a scorpion. "Delicious."

There is a detail in the sanctions listing worth pausing on, and it is not the money. The Treasury published a current residential address for him, down to the apartment number. The United States government knows exactly which flat this man sleeps in, said so in public, and cannot reach him. The same entry records a Russian passport for a man who says he destroyed his passport so that no country with an extradition treaty could ever hand him over. ConfirmedAnalyst inference

The fear, and then the relief

The best evidence of how his impunity works is not a boast. It is the moment he thought he was about to lose it. In late 2021, when Moscow and Washington briefly cooperated on cybercrime, he describes genuine panic, and then describes what fixed it. Credible

I crapped myself and then I was very afraid, I was drinking a lot. I re-read our Constitution and understood that they'll leave me, damn well, in Russia, but it was scary. I had already forgotten about the money, and then the special operation had begun. I was fucking happy. [...] I started to rejoice, you know, with impunity.

To Recorded Future, August 2022, on the invasion of Ukraine. He is describing the war as the thing that restored his impunity, and he is aware enough of how it reads to add that Ukrainians will read the interview too, and that he is "even a little ashamed of it."

On the state itself he is consistent and unglamorous. Asked directly whether any Russian service had ever approached him: "I was even surprised that in the entire history of my career since 2011, no one has ever come to me. Neither the FSB nor the Ministry of Internal Affairs. I've just lived an ordinary life." His stated fear is not a raid. It is cooperation: "if these two structures start cooperating with each other, then I'll get fucked up, with at least three life sentences." Credible

His own doctrine, posted to Exploit in January 2021 in a thread about a colleague arrested abroad, is the cleanest statement of the arrangement anyone in this ecosystem has written down. Credible

Don't shit where you live, travel local, and don't go abroad. Mother Russia will help you. Love your country, and you will always get away with everything.

Exploit forum, January 2021, a quoted post reported by Krebs on Security.

The prosecution

On 29 November 2024 the Kaliningrad police and prosecutor announced that a criminal case against a 32 year old local had been signed off and sent to the Central District Court. Western headlines said Russia had arrested its most wanted hacker.

What actually happened is narrower. He was detained on the evening of Friday 29 November and released by the night of Sunday 1 December, and was never held before trial. The charge was Article 273 part 1 of the Russian Criminal Code, creating malicious software, which carries a maximum of four years and is the lightest of that article's three parts. There was no fraud count and no unauthorised access count, the charges Russian prosecutors stack when they intend to put a cybercriminal away. The malware in question was allegedly written in January 2024, which is not the conduct the United States charged, and the prosecutor named no victims and no nationality. Russia did not accuse him of attacking Russian companies, whatever the headlines implied. ConfirmedCredible

The sentence, which nobody reported

On 28 February 2025 he was sentenced to eighteen months of "ограничение свободы," restriction of freedom. Not prison. Not a fine. A curfew, a ban on leaving his city, check-ins with a probation officer, and prohibitions on bars, nightclubs, gambling venues and protests.

Set that against the American position: eight counts across two federal indictments, more than twenty years of exposure, and a ten million dollar reward that is still live, with the FBI's wanted page updated as recently as March 2026.

No Russian outlet has ever reported the sentence. Not the state agencies that covered the arrest, not the Kaliningrad local press, not the prosecutor's own newsroom. Neither have any of the Western journalists who covered the arrest. It surfaced in a single post by the malware research collective vx-underground on the day it happened, and has been repeated once, by a threat intelligence firm paraphrasing that post. Credible

How firm is this. Two published sources, but they trace to one origin, so treat it as single-sourced. The case file itself is public and addressable at the Central District Court of Kaliningrad, and the defendant's name on it is redacted in the ordinary way. We could not open it: the court blocks automated access, and the record would settle the date, the sentence and any confiscation order. That is the check we would most like a person with a browser in Kaliningrad to run.

Through an intermediary he also said he had paid two fines and had cryptocurrency confiscated. That claim reaches the press through one researcher on Telegram on 1 December 2024, and the outlet that carried it noted plainly that it could not be independently verified. It has never had a second source, no amount has ever been specified, and a sentence of restricted freedom is not a fine. Analyst inference

The rebrand

Two weeks after the indictment he was describing a new career. Not ransomware: a project to teach Russian children cyber-hygiene and to keep American agencies away from them. "For example, the CIA and the FBI try to recruit our citizens openly [and I want to protect them from that]. I want to take IT in Russia to the next level." In the same conversation he wanted it understood that he had never run anything, only rented: "In all projects I am an affiliate, like a contractor, I am not running these operations," and that the coverage had inflated him: "they made me look like a co-owner of these partnership programs, which I am not." Credible

A criminal recasting himself as a national asset, weeks after a foreign government priced him at ten million dollars, is a well-worn move in this ecosystem. What makes it worth recording here is that it was not only his own idea. The people around him had already arrived at the same reading of him. Analyst inference

The part that is not about the state at all

The most telling evidence of it is not a document. In October 2023 Prodaft, which had been inside his circle's communications, described the reception at home after the United States indicted him and put ten million dollars on his head. Most of his neighbourhood, the firm said, shook his hand to congratulate him. His girlfriend's father called him a national hero. Credible

In the same account, Prodaft reported that when the indictment landed he went looking for advice from someone who had been living under an American bounty since 2014: Evgeniy Bogachev, the creator of GameOver Zeus. Bogachev has his own file here. Two men on the FBI's cyber most wanted list, one asking the other how you carry it. Credible

That is what impunity looks like without a patron. There is no handler here and no roof held over him by anyone: a constitution that cannot extradite you, a police force that charges you with the smallest available offence and releases you in forty-eight hours, a court that gives you a curfew, a press that does not report the outcome, and a street that shakes your hand. Nobody protected him. Nobody had to. Analyst inference

What we will not claim

No source alleges that the FSB or the GRU tasked, recruited, ran or protected Matveev, and no source publishes a formal finding that they did not. Serious analysts stop at association, alignment and awareness. Kaspersky's Vladimir Dashchenko said in December 2024 that Russian law enforcement already knew about him and had been in contact, which is the strongest named-expert statement on the record and is still a long way from tasking.

Compare Black Basta, where leaked chats in February 2025 produced direct evidence of a "green corridor" for a ransomware leader. Matveev has no equivalent.

07 / OpenWhere this file is thin

This page is a living record. These are the holes, stated plainly so a later find can slot in without a rewrite.

Five unresolved threads

The sentence, from the court rather than from a researcher. The case file is public and we could not open it. It would confirm the date, the sentence and whether anything was confiscated.

Whether he paid fines at all. Russia's bailiff database is public and would corroborate or contradict the claim. It is captcha-gated and we could not query it.

The airline. The Treasury states he has been linked to intrusions against numerous US businesses "including a U.S. airline." It has never been named.

Where the ransom money went. The attributed cluster appears to die in March 2020, before the charged conduct begins. If that holds, none of the actual ransom proceeds has ever been traced.

Is he still working? His last documented post is 1 December 2024. Silence since. That fits retirement, a gag, the conditions of a restricted-freedom sentence, and simply operating under new handles. We cannot distinguish between them. The "Babuk 2.0" activity from early 2025 is assessed by multiple firms as impersonators recycling the brand, and is not him.

One prediction on the record is worth keeping. In December 2024 an anonymous senior figure in the Russian-speaking criminal community told Gazeta.ru that Wazawaka would stay free, but only if he left cybercrime and stopped showing off in public. Everything since is consistent with that having been correct. Analyst inference

He is 34 years old. He remains on the FBI's cyber most wanted list, on the United States sanctions list, and subject to a ten million dollar reward. He is not on the United Kingdom or European Union sanctions lists, and he does not appear on any Russian wanted list. No documented detention of him has ever run longer than two nights. Confirmed

Sourcing and method

Claims are labelled Confirmed where they rest on a primary document, Credible where they rest on reputable reporting, and Analyst inference where they are our reading rather than a fact. Three findings on this page are our own, produced by direct examination of public records rather than by citation: the search of the leaked Conti corpus, the on-chain verification of the wallet cluster, and the collation of the February 2025 sentence.

  1. US Department of the Treasury, press release JY1486, and the sanctions designation, 16 May 2023
  2. United States v. Matveev, indictments, District of New Jersey and District of Columbia, unsealed 16 May 2023
  3. US Department of State, Transnational Organized Crime Rewards Program notice
  4. FBI Cyber Most Wanted, Mikhail Pavlovich Matveev, page updated 16 March 2026
  5. Krebs on Security, January 2022, February 2022 and December 2024
  6. The Record, interview with Wazawaka by Dmitry Smilyanets, 26 August 2022
  7. The Record, Click Here podcast, 31 May 2023
  8. TechCrunch, 18 September 2023 and 3 October 2023
  9. BleepingComputer, Babuk source code leak 2021, Russian charges 2024, RAMP seizure January 2026
  10. SentinelLabs, Babuk-derived hypervisor lockers, 11 May 2023
  11. Washington Post, StateScoop, Forbes and the Daily Beast, Metropolitan Police leak, April to May 2021
  12. Prodaft, "Smoke and Mirrors: Understanding The Workings of Wazawaka", December 2023, and public thread October 2023
  13. AdvIntel on the Costa Rica intrusion and the end of Conti, May and July 2022; Searchlight Cyber on UNC1756, 18 May 2022
  14. Chainalysis, OFAC sanctions tracker and commentary on the Matveev designation
  15. CloudSEK, "The Rise and Fall of RAMP", February 2026
  16. RIA Novosti and the Kaliningrad regional prosecutor, 29 November 2024; The Insider; Xakep; Gazeta.ru
  17. vx-underground, 28 February 2025, and SOCRadar, 11 April 2025, on the sentence
  18. ContiLeaks complete translated corpus, public mirror, searched July 2026
  19. Bitcoin blockchain, address records retrieved directly, August 2026
  20. OpenSanctions, and the Council of the European Union cyber sanctions package, 13 July 2026