The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The U.S. Department of Justice announced on February 10, 2025 that it had unsealed charges against two alleged members of a ransomware affiliate group that used the names “8Base” and “Affiliate 2803” and deployed Phobos ransomware against public and private organizations. The defendants are Roman Berezhnoy and Egor Nikolaevich Glebov. The charges are allegations. DOJ states that all defendants are presumed innocent until proven guilty beyond a reasonable doubt.
This article explains what DOJ alleges, how 8Base relates to Phobos, what the 11-count indictment covers, and what the coordinated international action involved. It also separates the February 2025 affiliate case from a related November 2024 case against an alleged Phobos administrator.
Who was charged
Roman Berezhnoy and Egor Nikolaevich Glebov were named in the indictment. DOJ describes them as operating an affiliate organization that went by “8Base” and “Affiliate 2803.” An affiliate, in DOJ’s description, is the party that carries out attacks using a ransomware strain run by someone else. Here, the strain was Phobos.
DOJ says the alleged conduct ran from May 2019 through at least October 2024. Because the announcement uses the phrase “at least,” the end date reflects the period DOJ could document at the time, not a confirmed endpoint.
#1 Best Overall
What DOJ alleges happened in each attack
According to the indictment as summarized by DOJ, the operation followed a consistent sequence. Each step below is an allegation.
1. Network intrusion
The defendants and others allegedly gained access to victim computer networks. DOJ does not describe a single entry method across all victims in the announcement, so the release should not be read as establishing one.
2. Copying and taking files
Once inside, the group allegedly copied and stole files and programs. This step matters for the extortion that followed, because the threat was not only to lock data but also to publish it.
Rank #2
3. Encryption with Phobos
The group allegedly encrypted the victims’ original data using Phobos ransomware, which left the victims unable to use the files without a decryption key.
Recommended Free Tools
4. Ransom demand and negotiation
DOJ alleges the group left ransom notes, demanded payment in exchange for decryption keys, and contacted victims directly to negotiate. The indictment also describes threats to expose stolen information publicly or to a victim’s customers, clients, or constituents. Those threats are the basis for the extortion and threat counts discussed below.
How 8Base relates to Phobos
The announcement presents 8Base and Affiliate 2803 as names for an alleged Phobos affiliate operation rather than as a separate malware family. The affiliate model, as DOJ describes it, worked like this:
- Phobos administrators provided the ransomware and the decryption infrastructure.
- Affiliates paid fees to Phobos administrators for decryption keys.
- Each deployment allegedly received a unique alphanumeric string, which was used to match a victim to its key.
- Affiliates were directed to pay a cryptocurrency wallet unique to that affiliate.
The indictment gives concrete examples of alleged attacks. They include an alleged attack on a Connecticut public school system in July 2023 and an alleged attack on an Ohio automotive company in May 2023. DOJ’s release also names a children’s hospital, healthcare providers, and educational institutions among the victims. The indictment separately describes a contractor for the U.S. Departments of Defense and Energy as a victim. These are the alleged facts in the charging document, not findings made at trial.
Reported scale and ransom figures
DOJ reported two headline figures in its February 2025 announcement:
| Measure | Figure reported by DOJ | How to read it |
|---|---|---|
| Affected entities | More than 1,000 public and private entities in the United States and around the world | DOJ’s count for the alleged scheme as of its 2025 announcement. It is not a count of confirmed trial findings. |
| Ransom payments | Over $16 million | DOJ’s total for the alleged scheme. It covers payments DOJ attributes to the operation, not a figure set by a court. |
Both numbers come from DOJ’s description of the case. Neither has been tested in court, and neither is a finding that any defendant is guilty.
Rank #4
The charges
The indictment contains 11 counts. Each count is an allegation, and the statutory maximum penalties DOJ listed apply only if a defendant is convicted. Any sentence would be set by a federal judge after considering the applicable sentencing factors.
| Count type | Number of counts | What it concerns |
|---|---|---|
| Wire fraud conspiracy | 1 | An agreement to commit wire fraud |
| Wire fraud | 1 | Use of interstate electronic communications in a fraud scheme |
| Conspiracy to commit computer fraud and abuse | 1 | An agreement to access protected computers without authorization |
| Causing intentional damage to protected computers | 3 | Damage allegedly caused by the encryption attacks |
| Extortion in relation to damage to a protected computer | 3 | Ransom demands tied to the alleged damage |
| Transmitting a threat to impair confidentiality of stolen data | 1 | Threats to publish stolen information |
| Unauthorized access and obtaining information from a protected computer | 1 | Access to protected computers and taking information from them |
The counts cover computer crime, fraud, and extortion. Because the charges combine these categories, the case is not limited to the encryption itself. The data-theft and threat elements are a central part of what DOJ alleges.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.The international disruption
DOJ said the arrests were part of a coordinated international operation with law enforcement partners. According to the announcement, the operation disrupted more than 100 servers associated with the criminal network. DOJ did not identify every partner country in the material summarized here, so readers should check the official release for the full list of agencies involved.
How this case differs from the November 2024 Phobos case
DOJ had separately announced in November 2024 that Evgenii Ptitsyn, an alleged Phobos administrator, had been extradited from South Korea and charged. That case concerns the alleged administrator of the Phobos platform. The February 2025 case concerns alleged affiliates who used it. The two actions are related, but they involve different defendants and different roles, and it is a mistake to treat them as one prosecution.
What the case does not establish
- It does not establish guilt. Every count is an allegation under the presumption of innocence.
- It does not establish the final outcome. The DOJ release was updated on February 20, 2025, and the case status after that update is not confirmed in the sources used here. Check the DOJ press release and the court docket for current status.
- It does not establish a complete victim list. The 1,000-plus figure is DOJ’s estimate for the alleged scheme.
Where to find technical guidance
DOJ’s announcement directs readers seeking information on protecting networks to StopRansomware.gov, which points to CISA Advisory AA24-060A. Technical mitigations, such as specific configuration or detection steps, should be taken from that advisory directly rather than from secondary summaries, including this one.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




