- What: Armenian border officers detained Russian tourist Aleksandr Yuryevich Ermakov at Yerevan's Zvartnots airport on June 28 under a U.S. extradition request and 30-day Interpol detention order for a REvil ransomware suspect named Aleksandr Ermakov.
- Impact: His lawyers say the U.S. wants Aleksandr Gennadievich Ermakov, the sanctioned Medibank hacker who stole 9.7 million health records, is serving a two-year Russian sentence, and cannot leave Russia, while the man in the cell is a former prison-service lawyer from Omsk.
- Fix / mitigation: The defense says fingerprints or full passport data would settle identity and neither has been produced; the structural fix is that OFAC's SDN entry omits the patronymic that Australia's and the UK's sanctions lists both carry.
- Who's at risk: Anyone who shares a name with a sanctioned or wanted individual, and any organization whose compliance or threat-intel workflows match identities on incomplete name fields.
On June 28, border officers at Yerevan's Zvartnots airport pulled a Russian tourist out of the departure hall. According to his wife, Maria Yurova, speaking to REN TV, they held up a phone showing a photo taken from his VKontakte page and walked him into a side room. He has been in an Armenian detention center ever since, held on a 30-day Interpol detention order while a court decides whether to extradite him to Dallas. His name is Aleksandr Ermakov. That, his lawyers argue, is the entire problem.
The Aleksandr Ermakov the United States wants is Aleksandr Gennadievich Ermakov, sanctioned by Australia, the U.S., and the UK in January 2024 for stealing 9.7 million records from Medibank Private, one of Australia's largest private health insurers, and dumping some on the dark web. Per TASS and case files two Russian outlets say they have read, he is serving a two-year Russian sentence that bars him from leaving the country. The man in the Armenian cell, his lawyers say, is Aleksandr Yuryevich Ermakov of Omsk, a former prison-service lawyer who does not speak English. Same given name, same surname, different patronymic, different life.
A warrant, a notice, and an escalating story
The U.S. charging document, which RIA Novosti says it holds, accuses Ermakov of participating in Sodinokibi/REvil attacks from roughly April 2019 to July 12, 2021, with more than 1,000 victims spanning private companies, law enforcement, government offices, schools, and hospitals, some in the Northern District of Texas. Channel Five dates the warrant to that district's federal court on June 26, two days before the airport stop. That court knows REvil: DOJ charged Yevgeniy Polyanin there in 2021 over attacks on Texas businesses and government entities.
But the claims grow as they move through the system. Treasury's 2024 designation placed Ermakov at REvil's edge, an actor 'believed to be linked' to the gang. The Interpol notice built on the U.S. paperwork, which Izvestia says it has, puts him at its center: one of the platform's administrators, with a take of over $13.7 million. And the Medibank breach itself, the event that made his name public, happened in October 2022, fifteen months after the charged REvil window closes. The U.S. has never announced a charge against Ermakov over Medibank at all.
Russian passports carry a patronymic, and it is the field that distinguishes one Aleksandr Ermakov from the next. Australia's consolidated sanctions list has it: Aleksandr Gennadievich Ermakov, born 16 May 1990. The UK's entry has it. OFAC's SDN record does not. It runs: ERMAKOV, Aleksandr, Moscow, DOB 16 May 1990, one Yandex address, four handles. Given name, surname, nothing in between.
Dylan Rajavi, one of the detained man's lawyers, told Izvestia the defense's working theory is that the U.S. paperwork carried a given name and a surname, no more, and an automated check did the rest. He also said there are standard ways to settle who someone is, fingerprints or full passport data, and that neither has been produced. 'There is only an arrest warrant,' he said. That is the defense's account, not a finding. Armenian authorities have said nothing and the Justice Department has announced no charges. Worth weighing too: Izvestia, REN TV, and Channel Five all sit under National Media Group, and Izvestia's newsroom has supplied the news for the other two since 2017. Three outlets holding documents is really one.
The identification that actually worked
The irony is that the original attribution of the sanctioned Ermakov was rigorous. Australia's signals directorate and federal police spent 18 months on Operation Aquila before naming him. Once the nicknames were public, Intel 471 went back through years of collected forum data: SHTAZI and shtaziIT were among his handles, and his alias JimJones had spent 2019 and 2020 on the Exploit forum hawking malware development through a dev shop called Shtazi-IT. A month later, Russian police rolled up the SugarLocker ransomware crew operating behind Shtazi-IT, with @GustaveDore in the contact field of its developer job ads. A U.S. vendor and Russia's interior ministry reached the same shopfront from opposite ends. In October 2024 a Moscow court gave Ermakov two years of restriction of freedom under Article 273(2), Russia's malware statute, for co-writing SugarLocker. He pleaded guilty.
The RedEye take
Take the defense's account with appropriate salt; it comes through one Kremlin-adjacent newsroom wearing three mastheads, and Moscow has every incentive to make a U.S. ransomware extradition look like a farce. But the checkable parts check. OFAC's SDN entry really does lack the patronymic its Australian and UK counterparts carry, and that is not a Russian talking point, it is a data-quality defect in a U.S. government record that downstream systems treat as authoritative. If the theory is right, the pipeline worked exactly as built: thin identifier in, automated match, warrant, airport. Two and a half years of sanctions, an 18-month intelligence operation, and a new federal warrant have, between them, put exactly one Aleksandr Ermakov in a cell, while the man the warrant describes reports monthly to the prison service the detainee spent his career working for. Whether or not Armenia's court sends him to Dallas, and his brother told RIA the family expects it will, the lesson stands: attribution is only as good as the weakest field it is keyed on, and claims harden as they travel. 'Believed to be linked' became 'administrator' somewhere between a Treasury designation and an Interpol notice, with no new public evidence in between.
What defenders should learn
- Audit what your screening actually matches on. Sanctions and watchlist tooling inherits the source record's gaps; OFAC's entry here lacks the disambiguating patronymic that Australia's and the UK's carry. If your compliance stack keys on name plus date of birth, you can generate the same false positive this case alleges, against a customer or an employee.
- Treat identifier escalation as a red flag in threat intel. 'Believed to be linked' in one document becoming 'platform administrator' in the next, with no new evidence cited, is confidence inflation. Track the provenance of each claim in your intel products separately, not just the entity.
- Count newsrooms, not mastheads. Izvestia, REN TV, and Channel Five look like three corroborating sources and are one National Media Group newsroom. Apply the same dedup discipline to vendor reports that recycle a single upstream finding.
- Model the Operation Aquila pattern for high-stakes attribution: 18 months of signals work, then independent corroboration from an opposite-incentive party, with Intel 471's forum archaeology and Russian police converging on the same Shtazi-IT shopfront. One-source attribution keyed on a handle or a name is not attribution.
- Demand biometric or document-grade confirmation before acting on identity matches. The defense's core complaint, that fingerprints and full passport data exist and were never checked, is the same failure mode as disabling MFA because the caller knew the username.
Swati Khandelwal, 'Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man,' The Hacker News, July 17, 2026. https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us