DoJ Arrests Hacker Involved With REvil Group That Stole Apple's MacBook Pro Schematics - MacRumors
Skip to Content

DoJ Arrests Hacker Involved With REvil Group That Stole Apple's MacBook Pro Schematics

The United States Justice Department today announced that it has arrested Ukrainian Yaroslav Vasinskyi for his involvement with REvil, a group that executed ransomware attacks against businesses and government entities in the United States.

macbook pro sizes space gray
REvil in April targeted Apple supplier Quanta Computer and stole schematics of the design of the 14 and 16-inch MacBook Pro models that were later released in October. The schematics unveiled ‌MacBook Pro‌ features like additional ports and the design of the notch, and REvil extorted Apple by threatening to release additional documents if the Cupertino company didn't pay a $50 million fee.

The ransom situation fizzled out just days after REvil made its demand, and the group mysteriously removed all documents and extortion threats related to Apple from its website.

REvil continued on with its illicit activities and in May, was responsible for a cyberattack on the Colonial Pipeline that caused gas shortages on the East Coast of the United States. In July, REvil took advantage of a vulnerability in management software designed for Kaseya, targeting between 800 and 1,500 businesses worldwide.

The DoJ says that Vasinskyi was involved in the Kaseya attack, and it's not clear if he was also part of the attack on Apple supplier Quanta Computer. He was arrested in Poland and is awaiting extradition to the United States.

Along with Vasinskyi's arrest, the Department of Justice has seized $6.1 million received by Yevgeniy Polyanin, who was also involved with REvil and was responsible for attacks against multiple victims. Two other arrests have been made in Romania, but details have not been shared.

"The arrest of Yaroslav Vasinskyi, the charges against Yevgeniy Polyanin and seizure of $6.1 million of his assets, and the arrests of two other Sodinokibi/REvil actors in Romania are the culmination of close collaboration with our international, U.S. government and especially our private sector partners," said FBI Director Christopher Wray. "The FBI has worked creatively and relentlessly to counter the criminal hackers behind Sodinokibi/REvil. Ransomware groups like them pose a serious, unacceptable threat to our safety and our economic well-being. We will continue to broadly target their actors and facilitators, their infrastructure, and their money, wherever in the world those might be."

Both Vasinskyi and Polyanin have been charged with conspiracy to commit fraud and related activity in connection with computers, substantive counts of damage to protected computers, and conspiracy to commit money laundering. Vasinskyi is facing a maximum of 115 years in prison if convicted, while Polyanin could be facing up to 145 years. Though Vasinskyi is in custody, Polyanin has not been arrested and is believed to be abroad.

The U.S. government has been working with allies in other countries to put a stop to REvil. In October, Reuters reported that multiple government agencies teamed up to hack REvil and take its "Happy Blog" website used to leak stolen documents offline.

Popular Stories

iOS 26

iOS 26.5 Features: Everything New in iOS 26.5

Monday May 11, 2026 5:09 pm PDT by
Apple released iOS 26.5 after a few months of beta testing, and while it doesn't have the Siri features we were hoping for since those are being held until iOS 27, there are a handful of useful changes worth knowing about. Subscribe to the MacRumors YouTube channel for more videos. End-to-End Encryption for RCS Support for end-to-end encryption (E2EE) for RCS messages between iPhone and...
Dynamic Island iPhone 18 Pro Feature

11 Reasons to Wait for the iPhone 18 Pro

Monday May 11, 2026 9:01 am PDT by
We're only four months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year, adopting a...
Apple WWDC25 iOS 26 CarPlay Light mode 250609

Six Popular iPhone Apps Now Available on CarPlay

Thursday May 14, 2026 9:10 am PDT by
Apple's CarPlay system for accessing iPhone apps on a vehicle's dashboard screen has received six popular apps in recent weeks: ChatGPT, Perplexity, Grok, Google Meet, WhatsApp, and the indie artist streaming platform Audiomack. Make sure you have the latest version of each app and they will automatically appear on CarPlay. ChatGPT Starting with iOS 26.4, CarPlay supports voice-based...

Top Rated Comments

The Clark Avatar
59 months ago

REvil extorted Apple by threatening to release additional documents if the Cupertino company didn't pay a $50 million fee.
If you had just stolen the schematics and didn't attempt to extort Apple you probably wouldn't be in this mess.
Serves him right.
Score: 12 Votes (Like | Disagree)
DHagan4755 Avatar
59 months ago
Wow! I didn't think they'd ever get caught.
Score: 9 Votes (Like | Disagree)
JPack Avatar
59 months ago

Hackers are smart and stupid at the same time, its one thing to data mine and find a company's new products before release but to sit there and think any company will kneel to extortion is just ridiculous, it has never happened.
Apple obviously paid the ransom and the FBI followed the money.

This hacker's real mistake was he was in Poland. If was further east, he would still be on the wanted list.
Score: 7 Votes (Like | Disagree)
Shirasaki Avatar
59 months ago

6.1 million in ‘assets’? What exactly at this value is considered assets?
Usually just random valuation and vague claimed damage as long as Apple can get away with it.
Score: 7 Votes (Like | Disagree)
Killa Aaron Avatar
59 months ago
Hackers are smart and stupid at the same time, its one thing to data mine and find a company's new products before release but to sit there and think any company will kneel to extortion is just ridiculous, it has never happened.
Score: 7 Votes (Like | Disagree)
JPack Avatar
59 months ago

I figured for every case, the ransom IS PAID, we rarely, if ever, hear about it and the bad guys keep getting away with holding everybody & everything hostage because it pays. Boo!
Because for the vast majority of cases, the ransom is paid. From a business perspective, you go with the option that results in the lowest cost and the least amount of downtime. No business out there has time to make a political statement. Heck, the U.S. government openly negotiates with the Taliban. Everybody knows there's propaganda for the domestic voting audience vs. reality.
Score: 6 Votes (Like | Disagree)