The past week in the world of cybersecurity was marked by a series of high-profile incidents that force a fresh look at vulnerabilities in both government structures and ordinary users. From secret bitcoin ransoms to mass surveillance disguised as VPN services, the situation is becoming increasingly alarming.
Ransom Scandal: US Authorities Paid Hackers 9.4 BTC
One of the most resonant episodes is the secret ransom payment to cybercriminals from the Kairos group. On June 13, 2025, a US government entity (presumably the administration of Union County, Ohio) transferred 9.44 BTC to the attackers. At that time, this amounted to about $1 million.
The peculiarity of the attack is that the hackers did not encrypt the victim's infrastructure. Instead, they stole 2 TB of confidential data, including information from the "prosecutor's office" folder, social security numbers, and fingerprints, and threatened to make it all public. Initially demanding $3 million, after a month of negotiations, the criminals agreed to $1 million. An on-chain data analysis showed that the received funds were fragmented and passed through a chain of wallets, including deposit addresses of the crypto exchanges Bybit, OKX, and the Russian service BELQI.
The Kairos group has already ceased public activity, but the wallets associated with it continued to move funds until May 2026. This case is a clear signal of a shift in cybercriminal tactics: from complex encryption to pure blackmail based on the fact of a leak.
Free VPNs: Protection or Surveillance Tool?
Researchers from the University of Michigan and the Indian Institute of Technology Delhi conducted a large-scale audit of over 280 free VPN applications from Google Play. The results are shocking: many services not only fail to protect users but actively spy on them.
The total number of downloads of the problematic utilities exceeded 2.4 billion. Among the identified defects are tunnel interception (five applications downloaded configurations via unsecured HTTP), DNS query leaks (29 applications), and a complete lack of traffic encryption in four programs. Over 80% of the applications contacted advertising servers, transmitting unique device identifiers and GPS coordinates. Meanwhile, 89% of services used only one authentication method, and every fifth relied on outdated ciphers.
It is obvious that "Verified" badges in app stores are not a mark of quality but a marketing gimmick. Users should be extremely cautious when choosing VPN services.
Inmate Outwits Justice: Withdrawing $290,000 from Prison
Another notable case is that of convicted Bulgarian citizen Rosen Iosifov, who is serving a 111-month sentence for laundering $5 million through his exchange RG Coins. He managed to orchestrate the withdrawal of $290,000 in cryptocurrency that had been confiscated from him. The incident occurred in January 2024. While in custody, Iosifov moved the funds through several exchanges and mixers to obscure the trail. He now faces up to 25 years of additional imprisonment.
Interpol Strikes: $293 Million and 5,800 Arrests
The global Operation First Light 2026, conducted by forces from 97 countries, yielded impressive results. Over 31,000 bank accounts and crypto wallets were blocked, 5,811 suspects were arrested, and the amount of intercepted assets reached $293 million. Particularly interesting is a case in Thailand, where a crypto wallet belonging to two suspects in a "romance scam" was discovered, through which $122.5 million in illegal funds had passed over 10 months.
Expert Opinion
The past week clearly demonstrates that cybersecurity is not only about protection from ransomware but also about combating leaks, blackmail, and covert surveillance. The use of free VPNs as Trojan horses is particularly alarming. Under current conditions, I recommend that users either switch to trusted paid solutions or completely abandon the use of dubious applications.