# Wrong Name, Wrong Man: Armenia Detains Russian Tourist in Apparent Extradition Mix-Up Over REvil Ransomware
Armenia has detained a Russian tourist identified as Aleksandr Ermakov since June 28 following a U.S. extradition warrant, but his legal team claims authorities have apprehended the wrong man—a case of mistaken identity that exposes dangerous gaps in international cybercrime investigation procedures.
The detained individual, Aleksandr Yuryevich Ermakov from Omsk, is a former prison service lawyer who reportedly does not speak English. His arrest was triggered by a U.S. federal warrant alleging involvement in REvil ransomware operations. However, his lawyers argue the actual target of the investigation is a different Aleksandr Ermakov—Aleksandr Gennadievich Ermakov—who was sanctioned by the United States, Australia, and the United Kingdom in January 2024 for orchestrating the Medibank Private hack that compromised 9.7 million records from one of Australia's largest private health insurers.
## The Two Men With the Same Name
The case hinges on a critical distinction lost in translation and bureaucratic processing: patronymics, the middle names derived from a father's name that form an essential part of Russian identity documents.
The Wanted Man:
The Detained Man:
The patronymic—the part that distinguishes one Aleksandr Ermakov from another—appears to have been stripped from the U.S. warrant documents before they reached Armenian authorities. According to defense lawyers cited by Russian media outlets, the paperwork contained only the given name and surname, with no patronymic identifier. An automated database match then flagged the first Aleksandr Ermakov it could find.
## The REvil Investigation and Charges
The charges against Ermakov relate to REvil's (also known as Sodinokibi) extensive criminal operations spanning from April 2019 through July 2021. During that period, the ransomware-as-a-service operation victimized over 1,000 organizations, including private companies, law enforcement agencies, government offices, schools, and hospitals.
According to the U.S. charging documents referenced by Russian outlets, the warrant was issued by the U.S. District Court for the Northern District of Texas on June 26, 2026—just two days before the arrest at Yerevan's Zvartnots airport. The same court previously handled high-profile REvil cases, including charges against Yevgeniy Polyanin in 2021 for attacks on Texas businesses and government entities.
A critical timeline issue complicates the case further: the Medibank hack occurred in October 2022, months after the prosecution window for the REvil charges allegedly closes in July 2021. The U.S. government has never publicly announced charges against either Aleksandr Ermakov for the Medibank breach; only the January 2024 sanctions designation connects Gennadievich Ermakov to that operation.
## Verification Failures and Due Process Gaps
The defense's most damaging assertion is straightforward: authorities skipped standard identity verification procedures. Defense attorney Dylan Rajavi told Russian media that fingerprints and full passport data—standard methods for confirming someone's identity in extradition cases—were never provided or compared.
"There is only an arrest warrant," Rajavi stated, according to reporting from Izvestia.
This oversight is particularly troubling given Russia's strict naming conventions. Every Russian passport includes:
These three elements together form the unique identifier. The patronymic is not optional; it appears on all official documents and is how individuals are properly distinguished in criminal records, sanctions lists, and international warrants.
Australia's official designation of the sanctioned Ermakov explicitly includes "Aleksandr Gennadievich Ermakov, DOB 16 May 1990." The UK's sanctions list carries the same information. OFAC's Specially Designated Nationals (SDN) record, however, lists only "ERMAKOV, Aleksandr" with a Moscow address and associated online handles—conspicuously omitting the patronymic that would have immediately distinguished him from Ermakov Yuryevich.
## Broader Implications for International Extradition
This incident raises systemic questions about how law enforcement agencies handle identity verification in international cybercrime cases, where suspects may operate across multiple jurisdictions and information systems may not be harmonized.
Key concerns include:
| Issue | Impact |
|-------|--------|
| Name standardization | Different countries record names differently; no unified format for international warrants |
| Patronymic handling | Russian, Eastern European, and Middle Eastern naming conventions not properly accounted for |
| Database matching | Automated systems may match on partial information without human verification |
| Cross-border communication | Information lost or degraded during translation and relay between agencies |
| Burden of proof | Detained individuals must prove they are NOT the wanted person, rather than authorities proving they ARE |
The detained Ermakov has been held on a 30-day Interpol detention order while Moscow requests consular access and presumably works to clear up the confusion. His family has largely learned about his detention through media reports rather than formal notification channels.
## The Source Material and Context Questions
The reporting on this case comes almost entirely from Russian state-aligned media outlets under the National Media Group holding: Izvestia, REN TV, and Channel Five. Since 2017, Izvestia's newsroom has supplied reporting for the other two outlets, meaning the story effectively has one source told through multiple voices.
All outlets reference access to U.S. charging documents and Interpol notices, but none have disclosed how they obtained these materials. Neither Armenian nor U.S. authorities have made official statements about the case. The Justice Department has issued no public charges, and Armenian authorities have remained silent on the matter.
## HackWire Analysis
This case exemplifies a dangerous intersection of automation, insufficient verification, and international bureaucracy. Law enforcement agencies have become reliant on database matching as the first and sometimes only filter for identifying suspects, but those databases were never designed to handle cases where multiple individuals share identical given and family names across different countries with different naming conventions.
What's particularly damning is the asymmetry of burden: the man detained in Armenia must now prove he is not the criminal that the U.S. warrant is seeking, despite never being shown the evidence or allowed to properly contest the identification. Standard extradition procedure requires that authorities establish probable cause that the detained person is indeed the individual named in the warrant. Here, there's no indication that fingerprints were checked, that witnesses were consulted, or that language capabilities were verified—all simple steps that would have immediately revealed the mismatch.
The case also exposes gaps in how U.S. sanctions designations are communicated to international law enforcement. OFAC's SDN list is a critical reference document for extradition requests, yet it lacks the patronymic information that would have prevented this confusion entirely.
For defenders and security professionals, the lesson is more subtle: this is what happens when international cybercrime investigation databases aren't properly maintained or standardized. If law enforcement can't reliably distinguish between two suspects with the same name, how confident should we be in other aspects of their investigations? How many other cases might suffer from similar information hygiene problems?
The practical impact extends beyond this one person. Until this mix-up is resolved—and it likely will be, given the overwhelming evidence of misidentification—it casts doubt on the efficiency of international law enforcement cooperation in cybercrime cases and provides a powerful argument for better identity verification standards across borders. — HackWire Editorial
## Recommendations for Organizations and Policymakers
For law enforcement and judicial authorities:
For organizations investigating cybercrime:
For diplomatic services:
## Related Coverage