Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
17APR

FBI seizes E-Note, $70m ransomware rail

2 min read
13:56UTC

Michigan State Police co-led. German BKA and Finnish KRP ran infrastructure. A Russian national is charged with running the exchange since 2017.

TechnologyAssessed
Key takeaway

The enforcement focus has moved up the supply chain from operators to the cash-out services they depend on.

The US Federal Bureau of Investigation (FBI) and Michigan State Police seized cryptocurrency exchange and payment processor E-Note and charged Russian national Mykhalio Petrovich Chudnovets with conspiracy to launder more than $70 million in ransomware and account-takeover proceeds through E-Note since 2017 1. The German Federal Criminal Police (Bundeskriminalamt, BKA) and Finnish National Bureau of Investigation (Keskusrikospoliisi, KRP) cooperated on the infrastructure seizure. Account-takeover proceeds are the funds stolen from hijacked bank or crypto accounts; ransomware proceeds are the extortion payments victims send to recover encrypted files.

E-Note had operated openly for years despite visible ties to the ransomware ecosystem. Its role in the supply chain is the off-ramp: the service that converts bitcoin, monero or stablecoins paid by victims into cash, clean tokens or traditional fiat held in jurisdictions beyond Western reach. Take the off-ramp out and the attackers' business model runs into a working-capital problem. The operational interest for FBI Cyber in 2026 is the laundering rail rather than the operator, because there are far fewer cash-out services than there are ransomware affiliates, and each seizure reaches hundreds of downstream crimes.

A state police force co-leading a takedown alongside the Bureau and two European national police services is an operational template worth noting. Michigan State Police brought the local jurisdictional hook that the federal case needed; the BKA and KRP brought the overseas server infrastructure. For the cash-out services still running, the enforcement geography just widened.

Deep Analysis

In plain English

When ransomware criminals extort money from victims, they typically demand payment in cryptocurrency. But cryptocurrency is traceable on the blockchain. Criminals need to convert it into regular money (or different, harder-to-trace cryptocurrency) through an exchange. E-Note was a cryptocurrency exchange that, according to US prosecutors, knowingly processed payments for ransomware gangs and other online criminals since 2017. Over that period, it laundered more than $70 million. The FBI and Michigan State Police seized E-Note and charged Russian national Mykhalio Petrovich Chudnovets with running the operation. German and Finnish police also cooperated in seizing E-Note's technical infrastructure.

Deep Analysis
Root Causes

Ransomware proceeds require conversion from cryptocurrency to spendable currency. Exchanges that accept large volumes of cryptocurrency without robust KYC and AML checks, and operate from jurisdictions with limited regulatory cooperation, provide this conversion service. E-Note operated from a regulatory grey zone for nine years because the US, German, and Finnish investigative cooperation required to build a prosecutable case across multiple jurisdictions took time to assemble.

The $70m+ figure, spread across nine years, represents roughly $7-8 million per year in laundered ransomware proceeds, which is small relative to the overall ransomware ecosystem but substantial in absolute terms. The seizure's significance is partly about precedent and partly about recovering criminal proceeds.

What could happen next?
  • Consequence

    The three-country coordination (US, Germany, Finland) in the E-Note seizure reinforces the Five Eyes and EU pattern of coordinated cryptocurrency exchange seizures, increasing operational tempo compared to the 2017-2019 period when such operations were primarily US-led.

First Reported In

Update #1 · Stryker MDM wipe exposes identity perimeter

The Record· 17 Apr 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.