> ## Content Index
> Fetch the complete content index at: https://www.russianhackers.co/llms.txt
> Use this file to discover other available public pages before exploring further.

# Fake FSB Officer Tried to Shake Down the Conti Ransomware Gang
- URL: https://www.russianhackers.co/fake-fsb-officer-conti-extortion/
- Published: 2026-07-13T20:14:59.000Z
- Updated: 2026-07-15T16:31:22.000Z
- Description: A Moscow man allegedly posed as an FSB officer and demanded money from one of the most dangerous ransomware crews in history. He is now in jail.
- Author: Martin
- Tags: News, Hackers, Ransomware

Russia's Investigative Committee is prosecuting Moscow resident Ruslan Satuchin, who investigators say impersonated an FSB officer and demanded a large sum of money from members of the Conti ransomware gang. RBC broke the story, citing two sources familiar with the case files.

The scheme, as investigators describe it, was simple. In September 2022 Satuchin contacted one of Conti's members and introduced himself as an FSB officer. For a price, he promised the hackers protection: no surveillance operations and no criminal charges. The case against him and "unidentified persons" landed three years later, in September 2025, under Part 4 of Article 159 of the Russian Criminal Code, fraud on an especially large scale.

Police detained Satuchin in Moscow in October 2025\. RBC's sources point out a curious detail: he knew about the criminal case and the ongoing probe, yet made no attempt to run and kept living at his registered address. A court sent him to pre-trial detention the next day, then extended the arrest by two more months in December. Investigators argued that the witnesses know the defendant personally, so he could pressure them if released. His lawyers asked for house arrest instead, citing his family and stable social ties. Satuchin denies the charges and remains in a Moscow detention center.

## The gang he picked

Conti, the crew Satuchin allegedly tried to squeeze, was no ordinary ransomware operation. It ran on the RaaS (Ransomware-as-a-Service) model and had ties to the Russian-speaking Wizard Spider group. Researchers at Group-IB called it a "criminal IT company": in-house HR, R&D and OSINT departments, regular salaries and a performance bonus system.

Conti first surfaced in February 2020\. Over the next two years it hit 859 organizations worldwide, from multinational corporations to government agencies. Its loudest strike came in May 2022, when an attack on Costa Rica's government systems pushed the country into a national state of emergency. The US responded with a reward of up to 15 million dollars for information on Conti's leaders and members.

The hackers styled themselves as "patriots" and claimed they never touched Russian companies. That stance ended up destroying them. In February 2022 Conti's leadership publicly backed the Russian government, the group split, and its internal chats leaked online. A Ukrainian member of the gang, or a security researcher with access to its infrastructure, is believed to have published them. The ransomware's source code, its control panels and the BazarBackdoor API followed. Conti soon dissolved, and its former members scattered across other crews.