The week in the world of cybersecurity was eventful: from daring thefts within prison walls to mass arrests and the exposure of the false anonymity of free VPNs. I have analyzed the key events and am ready to present you with an exclusive overview.

Inmate Pulls Off $290,000 Crypto Scam

Bulgarian citizen Rossen Iossifov, serving a 111-month sentence for online auction fraud and laundering $5 million, managed to orchestrate the withdrawal of his confiscated $290,000 in cryptocurrency. The incident occurred in January 2024. To cover his tracks, Iossifov routed the funds through several exchanges and mixers. He now faces up to 25 additional years in prison for concealment of assets and conspiracy. This is a stark example of how inventive criminals can be, even under strict isolation.

Interpol Delivers Record Blow: $293 Million and 5,800 Arrests

Operation First Light 2026, which ran from January to April, was one of the largest in history. Law enforcement from 97 countries participated. The results are impressive: 5,811 suspects were detained, $293 million in assets were intercepted, and over 31,000 bank accounts and crypto wallets were blocked. The I-GRIP mechanism deserves special attention, as it allowed for the real-time freezing of transactions, including transfers to crypto wallets. The largest case was in Thailand, where over $122.5 million in illegal funds, laundered through complex cross-chain swaps, passed through a single wallet over 10 months.

Free VPNs: Protection or Trojan Horse?

Researchers from the University of Michigan and the Indian Institute of Technology Delhi analyzed 280 free VPN applications from Google Play. The findings are discouraging: over 80% of them transmit data to ad servers, and 29 apps (around 360 million installations) allow DNS query leaks. Worse still, 169 services do not mask traffic, making them useless for bypassing blocks, despite loud claims in their advertising. Essentially, users pay not with money, but with their data, receiving only an illusion of security in return.

US Secretly Paid Hackers 9.4 BTC

On June 13, 2025, a US government entity (presumably the administration of Union County, Ohio) paid the Kairos group a ransom of 9.44 BTC (~$1 million). Notably, the attack did not involve data encryption — the hackers simply stole 2 TB of confidential information and blackmailed the victim with the threat of publication. Initially, they demanded $3 million, but after a month of negotiations, the amount was reduced to $1 million. The funds were split up and passed through wallets linked to Bybit, OKX, and the Russian service BELQI. This confirms a global trend: hackers are moving from complex ransomware to pure blackmail, which reduces their costs and risks.

Lurking Lizard: How Your Computer Becomes a Proxy Node

The Lurking Lizard group, active since August 2022, infects users' devices through fake installers of popular programs (7-Zip, WhatsApp, VPN) and turns them into residential proxies. The botnet includes over 230 fake domains, and one of the mobile apps — wirevpn — has already been downloaded over 1 million times. These proxies are rented out to other cybercriminals, making tracking attacks nearly impossible. Victims risk not only their privacy but also having their IP addresses blocked by providers.

My Expert Opinion: This past week demonstrates that cybercrime is evolving faster than protective measures. The shift from encryption to blackmail, the use of proxy botnets, and the mass collection of data through "free" services are new challenges requiring fundamentally different approaches to security from the industry and regulators. Cryptocurrencies remain a convenient tool for ransoms, but their transparency on the blockchain is a double-edged sword that law enforcement has already learned to use.