This week, the world of cybersecurity was shaken by a series of high-profile incidents. From a brazen cryptocurrency withdrawal from behind prison walls to large-scale police operations and the exposure of "free" VPNs. Let's break down the key events.

Inmate Crypto Magnate: $290,000 Vanished from Custody

Bulgarian citizen Rosen Iossifov, serving a 111-month sentence for a $5 million fraud, managed to orchestrate the withdrawal of $290,000 in cryptocurrency that had previously been confiscated by the government. The incident occurred in January 2024. While behind bars, Iossifov conspired to move the digital assets. To cover his tracks, he used a chain of crypto exchanges and mixers. He now faces up to 25 years of additional prison time.

Interpol Strikes: $293 Million and 5,800 Arrests

The global Operation First Light 2026, coordinated by Interpol, yielded staggering results. Law enforcement from 97 countries participated. Between January 15 and April 30, 2026, 5,811 suspects were arrested, and assets worth $293 million were seized. A particular focus was placed on blocking crypto wallets — over 31,000 accounts and wallets were frozen. In Thailand, a network that laundered $122.5 million through a crypto wallet in just 10 months using cross-chain swaps was uncovered.

Free VPNs: Protection or Surveillance?

Researchers from the University of Michigan and IIT Delhi analyzed 280 free VPNs from Google Play. The results are shocking: 80% of the apps communicated with ad servers, transmitting unique device identifiers and GPS coordinates. 29 apps (360 million installs) allowed DNS query leaks. Moreover, 89% of the services used only one authentication method, and some relied on outdated ciphers like Blowfish and Triple DES. As I have repeatedly warned, "free cheese" in the VPN sector almost always results in your data being leaked.

US Paid Ransom in Bitcoin: 9.44 BTC to the Kairos Group

On June 13, 2025, the administration of Union County (Ohio) paid a ransom of 9.44 BTC (~$1 million) to hackers from the Kairos group. The attack was unique: the attackers did not use ransomware but stole 2 TB of data and blackmailed the victim by threatening its publication. After a month of negotiations, the amount was reduced from $3 million to $1 million. The funds were fragmented and passed through Bybit, OKX, and the Russian service BELQI. This confirms a global trend: hackers are abandoning complex encryption in favor of pure blackmail, which reduces their costs and increases the effectiveness of attacks.

Lurking Lizard: Your Computer as a Proxy Node for Criminals

The Lurking Lizard group infected users' devices with malicious installers of popular programs (7-Zip, WhatsApp), turning them into residential proxy nodes. These nodes were then rented out to other cybercriminals. The infrastructure includes over 230 fake domains. One of the mobile apps, wirevpn, has already surpassed 1 million downloads. This is a dangerous trend: your IP address could be used for attacks, after which your traffic may be blocked by providers.

My Analysis: The week showed that cryptocurrencies remain a double-edged sword. On one hand, they allow for fast and anonymous transfers of funds, which is actively used by criminals. On the other hand, the blockchain provides unique opportunities for tracking transactions, which Interpol successfully leverages. The main takeaway for investors: never trust free VPNs and always remember that your assets can become a target, even if you are in custody.