European police have arrested two people suspected of playing key roles in the DoppelPaymer ransomware operation, one in Germany and another in Ukraine.
On Feb. 28, the German Regional Police and the Ukrainian National Police raided the homes of two suspected core members of the criminal group responsible for large-scale cyberattacks using the DoppelPaymer ransomware, according to a press release published yesterday by Europol.
In Germany, officers raided the house of a German national “believed to have played a major role in the DoppelPaymer ransomware group.” Investigators are currently sifting through the suspect’s computer equipment to determine the exact role in the structure of the cybercrime operation.
In war-torn Ukraine, officers located and interrogated a Ukrainian national who is also believed to be a member of the core DoppelPaymer group.
Ukrainian police searched two locations and seized electronic equipment, which is also under forensic examination to determine the suspect’s exact role in the organized cybercrime ring.
DoppelPaymer operators are known to have hit at least 37 organizations, inflicting tens of millions of dollars in damages.
The group relied on the infamous double extortion scheme, using a leak website to threaten to leak stolen data if ransom demands are not met.
Kia Motors America is one of the many victims of DoppelPaymer. In 2021, reports emerged that Kia Motors America was suffering a nationwide IT outage affecting its mobile UVO Link apps, phone services, payment systems, owner's portal and dealership websites. It was later revealed that DoppelPaymer operators had made their way into Kia’s servers by first hacking parent company Hyundai Motor America.