DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Conti member indicted for role in 2021 Scripps Health ransomware attack

Posted on September 12, 2023 by Dissent

On September 7, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), in coordination with the United Kingdom, sanctioned 11 individuals who are alleged to be part of the Russia-based Trickbot cybercrime group. At the same time, the U.S. Department of Justice (DOJ)  unsealed indictments against nine individuals in connection with the Trickbot malware and Conti ransomware schemes, including seven of the 11 individuals designated that day.

One of those individuals was Maksim Galochkin. As described by the government in its press announcement, Galochkin, who was also known by the online monikers “Bentley,” “Crypt,” and “Volhvb,” led a group of testers with responsibilities for development, supervision, and implementation of tests. The National Crime Agency also lists “Max17” as one of his monikers.

Additional information on him, provided by OFAC, includes that he is male, was born May 19,1982, and is a Russian national. Email Address: [email protected]; alt. Email Address [email protected]; alt. Email Address [email protected]; alt. Email Address [email protected]; Secondary sanctions risk: Ukraine-/Russia-Related Sanctions Regulations, 31 CFR 589.201 (individual) [CYBER2].

Additional context and background on Galochkin can be found in a fascinating piece by Matt Burgess and Lily Hay Newman of Wired. Their ability to unmask Galochkin was greatly enabled by research by NISOS.

Criminal Charges

Galochkin was originally charged in a sealed indictment filed in June 2023. The now-unsealed indictment charges that he and co-conspirators were responsible for accessing and damaging the computers of more than 900 victims worldwide. One of those victims was Scripps Health in the Southern District of California which was attacked in May 2021.

Story continues below the break.


Previous coverage of the Scripps Health ransomware incident can be found on DataBreaches at:

  • Scripps begins notifying more than 147,000 people of ransomware records breach
  • Healthcare provider expected to lose $106.8 million following ransomware attack
  • Scripps Breach Too California Heavy for Federal Courtroom
  • Update on Scripps’ ransomware incident
  • Even More Patient Data May Have Been Stolen in 2021 Ransomware Attack: Scripps Health
  • Updating Scripps Health ransomware incident: litigation settlement

The three counts of Galochkin’s indictment charge:

  • Unauthorized access to a protected computer in violation of Title 18, United States Code, Sections 1030 (a) (2) (C), (c) (2) (B), and 2;
  • Damage to a protected computer by transmission of Conti malware, in violation of Title 18, United States Code, Sections 1030 (a) (5) (A), (c) ( 4 ) (B), and 2. “The offense caused loss resulting from a related course of conduct affecting one or more protected computers aggregating at least $5,000 in value, the modification and impairment of the medical examination, diagnosis, treatment, and care of one or more individuals, a threat to public health and safety, and damage affecting 10 or more protected computers during a one-year period; and
  • Threatening to damage a protected computer by aiding and abetting the transmission of a ransom note, in violation Title 18, United States Code, Sections 1030 (a) (7) (C), (c)(3)(A), and 2.

Galochkin has been indicted but is not has not been caught or arrested at this point.


Related:

  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • How a hacking gang held Italy’s political elites to ransom
  • NY: Gloversville hit by ransomware attack, paid ransom
  • UN Cybercrime Convention to be signed in Hanoi to tackle global offences
  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
Category: Health DataMalwareOf NoteU.S.

Post navigation

← Texas Medical Liability Trust updates its data breach notification; now provides notification on behalf of almost 60,000 individuals
MO: Cyberattack causes multiple court systems to shut down some public safety computer servers →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.