A Belarusian operator, an American courtroom, an Indian policy gap
On August 6, 2026, a federal court in the Eastern District of Virginia sentenced Maksim Silnikau, a 40-year-old Belarusian national who went by "J.P. Morgan," "targa," and "lansky" on cybercrime forums, to 16 years in prison. Silnikau built and ran Ransom Cartel, a ransomware-as-a-service platform that emerged in late 2021 and, according to court documents, was used by affiliates to hit at least 18 organizations across the US between 2021 and 2023, stealing data before encrypting victim networks and demanding payment to prevent both (The Record). He was arrested in Spain in July 2024 and extradited to face US charges.
The case has no direct India connection — the named victims were American. But it lands at a moment when India is one of the world's most-targeted ransomware markets, and it crystallizes a real policy question: what actually deters ransomware-as-a-service operators, and is India's domestic compliance apparatus built for that job or a different one?
The scale of the problem in India
CERT-In's own 2022 India Ransomware Report — cited in contemporaneous coverage — found a 53% year-on-year jump in ransomware incidents, with IT/ITeS, finance, and manufacturing the hardest-hit sectors and LockBit the dominant variant (Tribune India). That trajectory hasn't reversed: Cyble's H1 2025 global threat landscape data puts India third in the Asia-Pacific region for ransomware attacks, trailing only Taiwan and Singapore, with IT, BFSI, and manufacturing again the top targets (Cyble H1 2025 data via Analytics Insight).
The case for mandatory, fast reporting
India's central regulatory response is CERT-In's April 2022 Directions under Section 70B of the IT Act, which require service providers, intermediaries, data centres, and body corporates to report a defined list of incidents — ransomware among them — within six hours of noticing or being notified of the incident (CERT-In Directions, 70B, 28.04.2022).
The strongest case for this is straightforward: ransomware spreads fast, and a national CERT that only learns about an active campaign weeks later can't warn other likely targets, can't correlate infrastructure across victims, and can't feed threat intelligence to sector regulators in time to matter. Given LockBit-style affiliate models — where one kit gets reused against dozens of Indian firms in a short window — early, mandatory reporting has genuine public-safety value that a purely voluntary regime would not deliver. Regulators pushing hard reporting deadlines are responding to a real failure mode, not inventing paperwork for its own sake.
Where the regime overshoots
The six-hour clock is also, by wide consensus among Indian compliance practitioners, tighter than any comparable global regime — the EU's NIS2 directive gives 24 hours for an initial alert and 72 hours for a fuller report; the US SEC's cyber-disclosure rule runs on materiality, not a fixed clock. Six hours from noticing an incident, before forensic triage is even underway, all but guarantees Indian firms file reports built on incomplete information, which does little to improve CERT-In's actual threat picture while consuming incident-response bandwidth better spent containing the breach.
That burden has now stacked on top of a second, differently-timed obligation. MeitY notified the Digital Personal Data Protection Rules, 2025 on November 14, 2025, which impose a dual breach-notification duty: alert affected individuals "without delay" and file a detailed report to the Data Protection Board within 72 hours (PIB, DPDP Rules 2025 notification). The Act's Schedule sets a ₹200 crore penalty specifically for failing to notify under Section 8(6), on top of a separate ₹250 crore exposure for inadequate security safeguards under Section 8(5). A single ransomware incident involving personal data can now trigger two regulators, two clocks (six hours and 72 hours), and up to ₹450 crore in cumulative exposure — before the victim organization has finished figuring out what was actually taken.
Deterrence lives elsewhere
The Silnikau case is a useful counterpoint precisely because it shows where deterrence actually comes from: years of cross-border investigative work, an extradition from Spain, and a US prosecution capable of putting a ransomware operator behind bars for 16 years. None of that required the victim companies to file a report within six hours of discovering they'd been hit. India has real gaps on this front — it has not acceded to the Council of Europe's Budapest Convention on Cybercrime, citing sovereignty concerns over cross-border data access provisions that the Convention's own committee clarified as narrow back in 2014, leaving India reliant on slower, bilateral mutual legal assistance channels instead (ORF: India and the Budapest Convention).
A proportionate fix
None of this argues for weaker reporting. It argues for reporting rules designed to produce usable intelligence rather than compliance theater: align CERT-In's clock with the DPDP Board's 72-hour window so victims file one coherent report instead of two rushed ones, add a good-faith safe harbor that shields companies which report promptly and cooperate from being penalized for the breach itself, and redirect the enforcement energy currently spent chasing reporting-window violations toward the slower, harder work of cross-border attribution and extradition — the tools that actually took Ransom Cartel's creator off the board.