German police identify alleged Black Basta leader as Europol and Interpol target

THE BRIEF
CyberScoop reported that German police identified Oleg Evgenievich Nefedov, a 35-year-old Russian national, as the alleged leader of the Black Basta ransomware group. Authorities said Nefedov allegedly formed and ran the group from 2022 and accused him of extorting more than 1—an incomplete figure in the supplied report. He was subsequently added to Europol and Interpol most-wanted lists. Officials in Ukraine and Germany also said they raided the homes of two unnamed Russian nationals living in Ukraine who were accused of participating in Black Basta’s crimes, and said the raids effectively halted their operations. The law enforcement activity follows the leak of Black Basta’s internal chat logs nearly a year earlier, which exposed details about the group’s operations. CyberScoop also reported that agencies across Europe continue pursuing leads on people linked to the group, nearly six months after Black Basta last claimed responsibility for new attacks, according to the supplied account.
WHY IT MATTERS
The report signals continued European law enforcement attention on Black Basta after leaked internal chats provided insight into the group’s operations. Identifying an alleged leader and placing him on Europol and Interpol most-wanted lists may shape future investigative and disruption efforts, while raids involving two other alleged participants show that authorities are pursuing multiple individuals. The supplied account does not establish whether Nefedov was arrested, where he is located, or the outcome of any prosecution. Organizations should therefore treat the development as an enforcement update, not evidence that the ransomware threat has ended.
WHO SHOULD CARE
Security leaders, incident-response teams, law enforcement liaison staff, and organizations with ransomware exposure should follow the reported actions and review whether their response plans account for continuing activity by Black Basta-linked individuals.
WHAT TO DO NOW
- Monitor official notices from Europol, Interpol, and relevant national law enforcement agencies for verified updates.
- Review ransomware response plans, including escalation paths for suspected Black Basta-related activity.
- Preserve relevant logs, forensic evidence, and communications if an incident may involve the group.
- Brief legal, security, and executive stakeholders on the reported allegations and the need for cautious attribution.