A 20-year-old Russian hacker was part of a campaign that worked to extort tens of millions of dollars from more than 1,400 victims, federal prosecutors said Thursday.
Ruslan Astamirov, a citizen of the Russian-controlled Chechen Republic, was arrested by federal law enforcement at an unspecified date and faces charges of conspiracy to commit wire fraud and ransoming, New Jersey federal prosecutors said.
Astamirov allegedly deployed ransomware called LockBit to steal sensitive data from the servers of businesses, then lock those systems and demand payment of hundreds of thousands of dollars. If the victims didn’t pay, Astarimov allegedly threatened to release the data.
Department of Justice prosecutors allege Astamirov was directly responsible for five different attacks against U.S. businesses in Florida and Virginia, as well as international businesses based in France, Japan and Kenya.
At least one of the victims paid $700,000, the complaint says. Another victim refused to pay, and Astamirov uploaded its data to LockBit’s public server, according to the complaint.
LockBit-powered attacks account for 16% of ransomware attacks against state and local governments, according to the Department of Homeland Security.
“In securing the arrest of a second Russian national affiliated with the LockBit ransomware, the Department has once again demonstrated the long arm of the law. We will continue to use every tool at our disposal to disrupt cybercrime, and while cybercriminals may continue to run, they ultimately cannot hide,” Deputy Attorney General Lisa Monaco said.
LockBit was first identified in January 2020 on Russian-language cybercrime forums. It’s part of a class of hacking methods and technologies dubbed ransomware as a service (RaaS).
In RaaS, a technical team of developers exploits and maintains software to penetrate corporate or individual computers, then end users buy the software and deploy it against corporate networks. The end users pay either a fee or a percentage of their profits to the technical group behind LockBit.
Astamirov will face a federal judge Thursday, prosecutors said in a release announcing his arrest. He’s the third Russia-linked individual to be charged with crimes related to using LockBit.
His arrest comes as cybersecurity matters grow in size and importance. NBC News reported Thursday on a widespread cyberattack that has affected “several” federal agencies. CNBC previously reported on how a China-backed cyber group compromised U.S. Navy systems, according to Navy Secretary Carlos Del Toro.
In this photo illustration, a man seen holding a smartphone with the logo of US artificial intelligence company Cognition AI Inc. in front of website.
Timon Schneider | SOPA Images | Sipa USA | AP
Artificial intelligence startup Cognition announced it’s acquiring Windsurf, the AI coding company that lost its CEO and several other senior employees to Google just days earlier.
Cognition said on Monday that it will purchase Windsurf’s intellectual property, product, trademark, brand and talent, but didn’t disclose terms of the deal. It’s the latest development in an AI talent war, as companies like Meta, Google and OpenAI fiercely compete for top engineers and researchers.
OpenAI had been in talks to acquire Windsurf for about $3 billion in April, but the deal fell apart, and Google said on Friday that it hired Windsurf’s co-founder and CEO Varun Mohan. Google is paying $2.4 billion in licensing fees and for compensation, as CNBC previously reported.
“Every new employee of Cognition will be treated the same way as existing employees: with transparency, fairness, and deep respect for their abilities and value,” Cognition CEO Scott Wu wrote in a memo to employees on Monday. “After today, our efforts will be as a united and aligned team. There’s only one boat and we’re all in it together.”
Cognition didn’t immediately respond to CNBC’s request for comment. Windsurf directed CNBC to Cognition.
Cognition is best known for its AI coding agent named Devin, which is designed to help engineers build software faster. As of March, the startup had raised hundreds of millions of dollars at a valuation of close to $4 billion, according to a report from Bloomberg.
Both companies are backed by Peter Thiel’s Founders Fund. Other investors in Windsurf include Greenoaks, Kleiner Perkins and General Catalyst.
“I’m overwhelmed with excitement and optimism, but most of all, gratitude,” Jeff Wang, the interim CEO of Windsurf, wrote in a post on X on Monday. “Trying times reveal character, and I couldn’t be prouder of how every single person at Windsurf showed up these last three days for each other and for our users.”
Wu said that the acquisition ensures all Windsurf employees are “treated with respect and well taken care of in this transaction.” All employees will participate financially in the deal, have vesting cliffs waived for their work to date and receive fully accelerated vesting for their, according to the memo.
“There’s never been a more exciting time to build,” Wu wrote.
The Grok logo is being displayed on a smartphone with Xai visible in the background in this photo illustration on April 1, 2024.
Jonathan Raa | Nurphoto | Getty Images
The European Union on Monday called in representatives from Elon Musk‘s xAI after the company’s social network X, and chatbot Grok, generated and spread anti-semitic hate speech, including praise for Adolf Hitler, last week.
A spokesperson for the European Commission told CNBC via e-mail that a technical meeting will take place on Tuesday.
xAI did not immediately respond to a request for comment.
Sandro Gozi, a member of Italy’s parliament and member of the Renew Europe group, last week urged the Commission to hold a formal inquiry.
“The case raises serious concerns about compliance with the Digital Services Act (DSA) as well as the governance of generative AI in the Union’s digital space,” Gozi wrote.
X was already under a Commission probe for possible violations of the DSA.
Read more CNBC tech news
Grok also generated and spread offensive posts about political leaders in Poland and Turkey, including Polish Prime Minister Donald Tusk and Turkish President Recep Erdogan.
Over the weekend, xAI posted a statement apologizing for the hateful content.
“First off, we deeply apologize for the horrific behavior that many experienced. … After careful investigation, we discovered the root cause was an update to a code path upstream of the @grok bot,” the company said in the statement.
Musk and his xAI team launched a new version of Grok Wednesday night amid the backlash. Musk called it “the smartest AI in the world.”
xAI works with other businesses run and largely owned by Musk, including Tesla, the publicly traded automaker, and SpaceX, the U.S. aerospace and defense contractor.
Despite Grok’s recent outburst of hate speech, the U.S. Department of Defense awarded xAI a $200 million contract to develop AI. Anthropic, Google and OpenAI also received AI contracts.
Meta CEO Mark Zuckerberg looks on before the luncheon on the inauguration day of U.S. President Donald Trump’s second presidential term in Washington on Jan. 20, 2025.
Evelyn Hockstein | Reuters
Meta on Monday said it has removed about 10 million profiles for impersonating large content producers through the first half of 2025 as part of an effort by the company to combat “spammy content.”
The crackdown is part of Meta’s broader effort to make the Facebook feed more relevant and authentic by taking action against and removing accounts that engage in “spammy” behavior, such as content created using artificial intelligence tools.
As part of that initiative, Meta is also rolling out stricter measures to promote original posts from creators, the company said in a blog post.
Facebook also took action against approximately 500,000 accounts that it identified to be engaged in inauthentic behavior and spam. These actions included demoting comments and reducing distribution of content, which are intended to make it harder for these accounts to monetize their posts.
Meta said unoriginal content is when images or videos are reused without crediting the original creator. Meta said it now has technology that will detect duplicate videos and reduce the distribution of that content.
The action against spam and inauthentic content comes as Meta increases its investment in AI, with CEO Mark Zuckerberg on Monday announcing plans to spend “hundreds of billions of dollars” on AI compute infrastructure to bring the company’s first supercluster online next year.
This mandate comes at a time when AI is making it easier to mass-produce content across social media platforms. Other platforms are also taking action to combat the increase of spammy, low-quality content on social media, also known as “AI slop.”
Google’s YouTube announced a change in policy this month that prevents content that is mass-produced or repetitive from being eligible for being awarded revenue.
This announcement sparked confusion on social media, with many users believing this was a reversal on YouTube’s stance on AI content. However, YouTube clarified that the policy change is aimed at curbing unoriginal, spammy and repetitive videos.
“We welcome creators using AI tools to enhance their storytelling, and channels that use AI in their content remain eligible to monetize,” said a spokesperson for YouTube in a blog post to clarify the new policy.
YouTube’s new policy change will take effect on Tuesday.