This week, the world of cybersecurity is shaken by high-profile revelations: from secret payments by the U.S. government to hackers to mass espionage by free VPN services. We break down the key events.

Inmate Outsmarts Justice: Withdraws $290,000 in Cryptocurrency from Prison

Bulgarian citizen Rosen Iosifov, serving a sentence for fraud, managed to organize an illegal withdrawal of $290,000 in digital assets previously confiscated from him. The incident occurred in January 2024. To cover his tracks, Iosifov used a chain of crypto exchanges and mixers. If found guilty on new charges, his prison term could increase to 25 years. This is a clear example of how even behind bars, criminals continue to use cryptocurrency for manipulation.

Interpol Strikes Record Blow: $293 Million and 5,800 Arrests

The global special operation First Light 2026 led to the arrest of 5,811 suspects and the seizure of assets worth $293 million. Law enforcement from 97 countries participated in the operation. Special emphasis was placed on blocking crypto wallets using the I-GRIP system. Notable episodes include uncovering a scheme in Thailand where over $122.5 million from a "romance scam" passed through a single wallet in 10 months, and the discovery of a fake police station in Brazil used for video blackmail.

Free VPNs: Protection from Surveillance or a Spy Tool?

Researchers from the University of Michigan and IIT Delhi analyzed over 280 free VPN applications from Google Play. The results are shocking: 80% of services transmit data to advertising networks, and some even share GPS coordinates. 29 apps (360 million installations) allow DNS query leaks. Additionally, many services use outdated Blowfish and Triple DES ciphers. Marketing security badges in the app store, it turns out, often guarantee nothing but a false sense of security.

U.S. Paid Ransom to Hackers: 9.44 BTC for Silence

On June 13, 2025, a U.S. government entity (presumably the Union County administration in Ohio) transferred about 9.44 BTC ($1 million) to hackers from the Kairos group. The uniqueness of the attack lies in the fact that the attackers did not encrypt data but simply blackmailed the victim with the threat of leaking 2 TB of confidential information. Initially demanding $3 million, they reduced the amount after a month of negotiations. The funds were fragmented and passed through wallets on exchanges Bybit, OKX, and the Russian service BELQI. This incident confirms a global trend: hackers are shifting from ransomware with encryption to pure blackmail.

Scammers Turn User Devices into Proxy Botnets

The Lurking Lizard group infects computers and smartphones through fake installers of popular programs (7-Zip, WhatsApp), turning them into residential proxy nodes. These proxies are then rented out to other cybercriminals to conceal attacks. The group's infrastructure includes over 230 fake domains, and one of their apps, wirevpn, has already been downloaded more than 1 million times. As an analyst, I see this as a serious threat: legitimate traffic from ordinary users risks being blocked because their IP addresses are used in criminal schemes.