Karakurt’s leverage was not limited to stolen data and leak threats. Prosecutors say the gang used access to Russian government databases and law-enforcement connections to pressure victims who resisted payment, which adds intimidation power beyond the usual ransomware playbook.
The DOJ said the case involved more than 54 companies and at least $15 million in ransoms. It also tied Karakurt to attacks on U.S. government entities, including disrupted 911 dispatch systems, and to theft of children’s health information.
The bigger risk is that extortion can be amplified by outside coercive access, not just by the intrusion itself. That makes containment of the technical event only part of the problem for government and healthcare victims.