# Wrong Name, Wrong Man: Armenia Detains Russian Tourist in Apparent Extradition Mix-Up Over REvil Ransomware


Armenia has detained a Russian tourist identified as Aleksandr Ermakov since June 28 following a U.S. extradition warrant, but his legal team claims authorities have apprehended the wrong man—a case of mistaken identity that exposes dangerous gaps in international cybercrime investigation procedures.


The detained individual, Aleksandr Yuryevich Ermakov from Omsk, is a former prison service lawyer who reportedly does not speak English. His arrest was triggered by a U.S. federal warrant alleging involvement in REvil ransomware operations. However, his lawyers argue the actual target of the investigation is a different Aleksandr Ermakov—Aleksandr Gennadievich Ermakov—who was sanctioned by the United States, Australia, and the United Kingdom in January 2024 for orchestrating the Medibank Private hack that compromised 9.7 million records from one of Australia's largest private health insurers.


## The Two Men With the Same Name


The case hinges on a critical distinction lost in translation and bureaucratic processing: patronymics, the middle names derived from a father's name that form an essential part of Russian identity documents.


The Wanted Man:

  • Aleksandr Gennadievich Ermakov (born May 16, 1990)
  • Moscow resident
  • Sanctioned by OFAC, Australia, and the UK for the October 2022 Medibank hack
  • Allegedly a senior REvil administrator with $13.7 million in proceeds
  • Currently serving a two-year Russian sentence that bars him from leaving the country

  • The Detained Man:

  • Aleksandr Yuryevich Ermakov
  • From Omsk, a city in southwestern Siberia
  • Former prison service lawyer
  • Does not speak English
  • Accused of participating in REvil operations from April 2019 to July 2021

  • The patronymic—the part that distinguishes one Aleksandr Ermakov from another—appears to have been stripped from the U.S. warrant documents before they reached Armenian authorities. According to defense lawyers cited by Russian media outlets, the paperwork contained only the given name and surname, with no patronymic identifier. An automated database match then flagged the first Aleksandr Ermakov it could find.


    ## The REvil Investigation and Charges


    The charges against Ermakov relate to REvil's (also known as Sodinokibi) extensive criminal operations spanning from April 2019 through July 2021. During that period, the ransomware-as-a-service operation victimized over 1,000 organizations, including private companies, law enforcement agencies, government offices, schools, and hospitals.


    According to the U.S. charging documents referenced by Russian outlets, the warrant was issued by the U.S. District Court for the Northern District of Texas on June 26, 2026—just two days before the arrest at Yerevan's Zvartnots airport. The same court previously handled high-profile REvil cases, including charges against Yevgeniy Polyanin in 2021 for attacks on Texas businesses and government entities.


    A critical timeline issue complicates the case further: the Medibank hack occurred in October 2022, months after the prosecution window for the REvil charges allegedly closes in July 2021. The U.S. government has never publicly announced charges against either Aleksandr Ermakov for the Medibank breach; only the January 2024 sanctions designation connects Gennadievich Ermakov to that operation.


    ## Verification Failures and Due Process Gaps


    The defense's most damaging assertion is straightforward: authorities skipped standard identity verification procedures. Defense attorney Dylan Rajavi told Russian media that fingerprints and full passport data—standard methods for confirming someone's identity in extradition cases—were never provided or compared.


    "There is only an arrest warrant," Rajavi stated, according to reporting from Izvestia.


    This oversight is particularly troubling given Russia's strict naming conventions. Every Russian passport includes:

  • Given name (first name)
  • Patronymic (derived from father's name)
  • Family name (surname)

  • These three elements together form the unique identifier. The patronymic is not optional; it appears on all official documents and is how individuals are properly distinguished in criminal records, sanctions lists, and international warrants.


    Australia's official designation of the sanctioned Ermakov explicitly includes "Aleksandr Gennadievich Ermakov, DOB 16 May 1990." The UK's sanctions list carries the same information. OFAC's Specially Designated Nationals (SDN) record, however, lists only "ERMAKOV, Aleksandr" with a Moscow address and associated online handles—conspicuously omitting the patronymic that would have immediately distinguished him from Ermakov Yuryevich.


    ## Broader Implications for International Extradition


    This incident raises systemic questions about how law enforcement agencies handle identity verification in international cybercrime cases, where suspects may operate across multiple jurisdictions and information systems may not be harmonized.


    Key concerns include:


    | Issue | Impact |

    |-------|--------|

    | Name standardization | Different countries record names differently; no unified format for international warrants |

    | Patronymic handling | Russian, Eastern European, and Middle Eastern naming conventions not properly accounted for |

    | Database matching | Automated systems may match on partial information without human verification |

    | Cross-border communication | Information lost or degraded during translation and relay between agencies |

    | Burden of proof | Detained individuals must prove they are NOT the wanted person, rather than authorities proving they ARE |


    The detained Ermakov has been held on a 30-day Interpol detention order while Moscow requests consular access and presumably works to clear up the confusion. His family has largely learned about his detention through media reports rather than formal notification channels.


    ## The Source Material and Context Questions


    The reporting on this case comes almost entirely from Russian state-aligned media outlets under the National Media Group holding: Izvestia, REN TV, and Channel Five. Since 2017, Izvestia's newsroom has supplied reporting for the other two outlets, meaning the story effectively has one source told through multiple voices.


    All outlets reference access to U.S. charging documents and Interpol notices, but none have disclosed how they obtained these materials. Neither Armenian nor U.S. authorities have made official statements about the case. The Justice Department has issued no public charges, and Armenian authorities have remained silent on the matter.


    ## HackWire Analysis


    This case exemplifies a dangerous intersection of automation, insufficient verification, and international bureaucracy. Law enforcement agencies have become reliant on database matching as the first and sometimes only filter for identifying suspects, but those databases were never designed to handle cases where multiple individuals share identical given and family names across different countries with different naming conventions.


    What's particularly damning is the asymmetry of burden: the man detained in Armenia must now prove he is not the criminal that the U.S. warrant is seeking, despite never being shown the evidence or allowed to properly contest the identification. Standard extradition procedure requires that authorities establish probable cause that the detained person is indeed the individual named in the warrant. Here, there's no indication that fingerprints were checked, that witnesses were consulted, or that language capabilities were verified—all simple steps that would have immediately revealed the mismatch.


    The case also exposes gaps in how U.S. sanctions designations are communicated to international law enforcement. OFAC's SDN list is a critical reference document for extradition requests, yet it lacks the patronymic information that would have prevented this confusion entirely.


    For defenders and security professionals, the lesson is more subtle: this is what happens when international cybercrime investigation databases aren't properly maintained or standardized. If law enforcement can't reliably distinguish between two suspects with the same name, how confident should we be in other aspects of their investigations? How many other cases might suffer from similar information hygiene problems?


    The practical impact extends beyond this one person. Until this mix-up is resolved—and it likely will be, given the overwhelming evidence of misidentification—it casts doubt on the efficiency of international law enforcement cooperation in cybercrime cases and provides a powerful argument for better identity verification standards across borders. — HackWire Editorial


    ## Recommendations for Organizations and Policymakers


    For law enforcement and judicial authorities:

  • Implement mandatory patronymic fields in all Interpol notices and international extradition warrants for Russian and Eastern European suspects
  • Require biometric verification (fingerprints, facial recognition, or passport data) before any extradition detention order
  • Create standardized naming conventions across OFAC, Europol, and Interpol to eliminate ambiguity
  • Establish a verification checklist that includes language proficiency when charges allege international cybercrime

  • For organizations investigating cybercrime:

  • Maintain complete suspect identifiers including patronymics in threat intelligence databases
  • Cross-reference multiple sources when identifying threat actors across borders
  • Document all investigative evidence linking a specific individual to a specific handle or persona

  • For diplomatic services:

  • Provide immediate consular access to detained nationals to verify identity claims
  • Implement secondary verification processes before accepting international detention orders
  • Train staff on patronymic and naming convention issues in Eastern European cases

  • ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)