📈 Markets
GSPC 7585.73 ▼ -0.45% DJI 52093.11 ▼ -0.63% IXIC 25981.57 ▼ -0.78% GC 4364.50 ▼ -0.33% CL 104.79 ▲ 0.46% GSPC 7585.73 ▼ -0.45% DJI 52093.11 ▼ -0.63% IXIC 25981.57 ▼ -0.78% GC 4364.50 ▼ -0.33% CL 104.79 ▲ 0.46%
Business

U.S. Charges Russians in Alleged Terror Financing and Assassination Network

Federal prosecutors say the RIS Network operated as an arm of Russia’s state apparatus, targeting dissidents and Ukraine’s allies abroad.

E
Editorial Team
September 16, 2026 · 4:25 AM · 3 min read
Photo: Deutsche Welle

U.S. federal prosecutors have charged several Russian nationals and alleged associates in a case that frames a purported global assassination and sabotage network as both a national security threat and an instrument of Russian state power. The indictment, announced in the Southern District of New York, accuses the defendants of terrorism financing and conspiring to carry out contract killings around the world, including on U.S. territory.

According to the U.S. Department of Justice, the defendants worked for Russian intelligence services through a network identified as RIS Network. Prosecutors allege the group funded terrorist attacks against countries allied with Ukraine and prepared killings of Russian dissidents. The Justice Department said the charges were made public on Tuesday, September 15, and that the FBI participated in the investigation.

The case places the alleged operation in a broader business and policy context for American executives, boards, banks and multinational firms: Washington is treating state-linked covert activity not only as espionage, but as a financing and operational network with cross-border logistics. That framing can raise compliance exposure for companies that handle payments, travel, communications, procurement or other services that may be exploited by sanctioned or clandestine actors.

Prosecutors Describe a Global Operational Network

The indictment, as summarized by the Justice Department, alleges that the defendants paid individuals in the United States and other countries to conduct preliminary reconnaissance and carry out targeted killings. Prosecutors also say the defendants directed accomplices to commit and attempt terrorist attacks against civilian and military infrastructure in European countries that support Ukraine or are viewed as supporting it.

Assistant Attorney General for National Security John Eisenberg said the defendants “attempted to recruit U.S. citizens and foreign nationals to commit killings on behalf of the Kremlin.”

The Justice Department described RIS Network as a unit of the Russian state apparatus involved in attacks abroad, including assassinations. Prosecutors said the network had operated inside the United States and had focused on Russian dissidents and defectors, while more recently turning attention toward countries considered allies of Ukraine.

ABC News, citing U.S. Attorney General Todd Blanche, reported that the charges also concern alleged attempts to kill an unnamed Russian dissident whom the defendants believed was located in Washington, D.C. That allegation, if proven, would underscore the U.S. government’s contention that the network’s activities were not confined to Europe or to conflict-adjacent regions, but extended directly into the American capital.

Named Defendants and Alleged Roles

U.S. authorities identified three of the defendants as holding senior positions inside RIS Network. They include Yuri Khrameev, also known by the nickname “Colonel Yuri.” Prosecutors described him as a former colonel in Russian intelligence services who participated in recruiting multiple people to carry out killings of Russian dissidents.

Kirill Khrameev, Yuri Khrameev’s son, was described by U.S. prosecutors as an officer of Russia’s Federal Security Service, the FSB. Another defendant, Oemis Romagoza Durruti, a Cuban resident in Russia, is suspected of coordinating the network’s attacks.

Also named among those suspected of recruiting people to execute tasks for the network are Cuban national Yaidel Delgado Suarez, known by the nickname “Viking,” and Venezuelan national Angel Eduardo Castro.

The Justice Department said the five named defendants face up to 20 years in prison on the terrorism financing charge. Yuri Khrameev, Suarez and Castro are also charged with conspiracy to commit murder-for-hire, which carries a potential sentence of up to 10 years. Prosecutors said the defendants are currently wanted.

Boardroom Implications of a Security Case

For corporate leaders, the allegations sharpen a familiar post-Ukraine invasion risk: geopolitical conflict can surface through private-sector systems. Financial institutions, logistics providers, technology vendors, communications platforms and travel-related companies can all become points of vulnerability when alleged state-backed networks try to move money, recruit personnel, gather intelligence or support operations across borders.

The charges also reinforce the importance of beneficial ownership reviews, sanctions screening, enhanced due diligence and escalation procedures for unusual cross-border activity. While the indictment names specific individuals and an alleged network, the operational pattern described by prosecutors is wider: intermediaries, payments, recruitment, reconnaissance and attempted attacks across jurisdictions.

For boards, the issue is not limited to legal compliance. A company that unknowingly facilitates activity tied to terrorism financing or targeted violence could face enforcement scrutiny, reputational harm, operational disruption and political pressure. The case may therefore prompt risk committees and general counsel to revisit how their organizations identify state-linked threats, particularly where Russia-related exposure intersects with Ukraine, dissident communities or sensitive infrastructure.

The Justice Department’s public framing also signals that U.S. law enforcement intends to connect overseas covert action to domestic criminal statutes where alleged activity touches American territory, personnel or financial channels. That approach may expand the practical burden on companies to recognize warning signs that sit outside traditional commercial risk categories.

At the same time, the allegations remain allegations unless proven in court. The defendants are wanted, and prosecutors have outlined potential penalties rather than convictions. Still, the case adds to the U.S. government’s broader effort to characterize Russian state-linked activity abroad as a hybrid threat combining intelligence work, violence, infrastructure targeting and financing networks.

Written by

The newsroom team.

Related Reads

Join the conversation