True Crime
Related: About this forumRobbinhood ransomware: Iranian pleads guilty to ransomware attacks that affected Baltimore, other cities
Also: Iranian Man Pleaded Guilty to Role in Robbinhood Ransomware (U.S. Attorney's Office, Eastern District of North Carolina)
________________________________________________
Source: Associated Press
Iranian pleads guilty to ransomware attacks that affected Baltimore, other cities
Updated 4:56 PM EDT, May 27, 2025
WILMINGTON, N.C. (AP) An Iranian national pleaded guilty on Tuesday in North Carolina federal court for his role in a ransomware and extortion operation that prosecutors say targeted computer networks for Baltimore and other U.S. cities, a scheme that led to work disruptions and financial losses.
Sina Gholinejad, 37, pleaded guilty to one count of computer fraud and abuse and one count of conspiracy to commit wire fraud, according to a U.S. Department of Justice news release. A plea hearing for Gholinejad had been scheduled for Tuesday morning before U.S. District Judge Richard Myers in Wilmington. Gholinejad faces a maximum of 30 years in prison, with a sentencing hearing set for August, the release said.
The Justice Department said court documents and statements made in court show Gholinejad and unidentified coconspirators caused cyberattacks in which they encrypted files on the targeted networks with the RobbinHood ransomware variant to extort ransom payments. Attack recipients included city governments of Greenville, North Carolina in April 2019, and of Baltimore a month later. Corporations and other entities were targeted.
-snip-
Read more: https://apnews.com/article/ransomware-plea-federal-court-iran-cities-aab689b79d5c9eb4ea78c9a77a997ffd
________________________________________________
Source: U.S. Attorney's Office, Eastern District of North Carolina
Iranian Man Pleaded Guilty to Role in Robbinhood Ransomware
Tuesday, May 27, 2025
For Immediate Release
U.S. Attorney's Office, Eastern District of North Carolina
WILMINGTON, N.C. An Iranian national pleaded guilty today to participating in an international ransomware and extortion scheme involving the Robbinhood ransomware.
According to court documents and statements made in court, Sina Gholinejad, 37, and his co-conspirators compromised the computer networks of cities, corporations, health care organizations, and other entities around the United States, and encrypted files on these victim networks with the Robbinhood ransomware variant to extort ransom payments. These cyber-attacks caused significant disruptions and tens of millions in losses, including to the City of Greenville, North Carolina, and the City of Baltimore, Maryland. Baltimore lost more than $19 million from the damage caused to their computer networks and the resulting disruption to several essential city services, including online services for processing property taxes, water bills, parking citations, and other revenue-generating functions, which lasted many months. The conspirators used the damage they caused these cities to threaten subsequent victims.
Gholinejad and his co-conspirators all of whom were overseas caused tens of millions of dollars in losses and disrupted essential public services by deploying the Robbinhood ransomware against U.S. cities, health care organizations, and businesses, said Matthew R. Galeotti, Head of the Justice Departments Criminal Division. The ransomware attack against the City of Baltimore forced the city to take hundreds of computers offline and prevented the city from performing basic functions for months. Gholinejads conviction reflects the Criminal Divisions commitment to bringing cybercriminals who target our cities, healthcare system, and businesses to justice no matter where they are located. There will be no impunity for these destructive attacks.
-snip-
Beginning in January 2019, Gholinejad and others gained and maintained unauthorized access to victim computer networks and then copied information from the infected victim networks to virtual private servers controlled by the conspirators. The conspirators also deployed Robbinhood ransomware to encrypt the victims files and extort Bitcoin from victims in exchange for the private key required to decrypt the victims computer files.
Gholinejad and his co-conspirators attempted to launder the ransom payments through cryptocurrency mixing services and by moving assets between different types of cryptocurrencies, a practice known as chain-hopping. They also hid their identities and activities through a number of technical methods, including the use of virtual private networks and servers that they operated. The indictment identifies multiple additional victims of Robbinhood ransomware, including, but not limited to, the City of Gresham, Oregon and the City of Yonkers, New York.
-snip-
Read more: https://www.justice.gov/usao-ednc/pr/iranian-man-pleaded-guilty-role-robbinhood-ransomware