Unauthorized news on hackers, data breaches, zero-day exploits, ransomware and AI. Original reporting and analysis for people who actually read the source.

Hackers

A $10 Million Price Tag: Meet Wazawaka, One of the FBI's Most Wanted

Mikhail Matveev is accused of ransomware attacks around the world, and the US will pay up to 10 million dollars for information on him. He lives openly in Russia, taunts the FBI, and has now been charged by the Kremlin too.

A $10 Million Price Tag: Meet Wazawaka, One of the FBI's Most Wanted
Wanted poster. Source: FBI (public domain).

The FBI's Cyber Most Wanted list runs to dozens of names, but few carry themselves as brazenly as Mikhail Pavlovich Matveev, known online as Wazawaka. The FBI has wanted him since May 2023 for his role in ransomware operations, and the US State Department is offering a reward of up to 10 million dollars for information on him.

What he is wanted for

US prosecutors tie Matveev to several well-known ransomware crews at once: Babuk, LockBit and Hive, as well as Conti and DarkSide. In Babuk, prosecutors say, he was one of the leaders.

He was charged back in December 2022, in two separate indictments. A federal grand jury in Washington accused him over the Babuk attack on the Metropolitan Police Department of the District of Columbia on April 26, 2021. The second indictment, in New Jersey, carries six counts tied to deploying the LockBit, Babuk and Hive ransomware variants. The charges rest on the US Computer Fraud and Abuse Act.

Ten million, and a list full of Russians

The State Department does not attach a 10 million dollar reward to just anyone. Matveev sits in that heavier weight class: the US offers the same sum for only five of the ten names on its cyber most-wanted roster. The list itself is crowded with Russians, among them officers of GRU Unit 29155, recently sanctioned by the EU and the UK.

Living in the open

What makes Matveev's case unusual is that he does not hide. After landing on the wanted list he gave interviews to Western outlets, mocked the FBI in public, and said his status as a most-wanted man had no effect on his work. By his own account he destroyed his foreign travel passport to remove any temptation to leave the country, and claimed that life under sanctions had only improved. As long as he stays in Russia, the US warrant and the reward are little more than paper.

The twist: Russia charged him too

The bet on safety at home cracked in late 2024. Russian authorities opened their own criminal case against Matveev, accusing him of creating malicious software. According to reports, the case concerned a ransomware strain aimed in part at domestic targets. The irony was complete: a man the FBI will pay 10 million dollars to reach, and cannot, found himself in the crosshairs of his own state.

How the Russian case ends is not yet clear. But the Wazawaka story maps the current geography of cybercrime cleanly enough: as long as the accused sits in the right country, warrants and rewards stop at the border.

Based on statements from the FBI, the US State Department and the US Department of Justice, and reporting by TechCrunch, The Record and CyberScoop.

Share this article
Share

Written by

Martin
Martin
Editor of Russian Hackers. Unauthorized news on hackers, breaches, exploits and AI.

Read next

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack

On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Comic-poster cover: a cracked security shield shattering under 570 flaws and two zero-days

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
Comic-poster cover: a hacker prying open a Windows registry hive, the LegacyHive zero-day