The week in cybersecurity was eventful: from a brazen withdrawal of confiscated funds right from prison to a global police operation intercepting hundreds of millions of dollars. Let's break down the key events.

Inmate Outsmarts the System and Withdraws $290,000 in Cryptocurrency

Bulgarian citizen Rosen Iossifov, serving time for online auction fraud, managed to orchestrate the withdrawal of confiscated digital assets worth $290,000. The owner of the RG Coins exchange was sentenced to 111 months in prison in 2021 for laundering about $5 million. However, while behind bars in January 2024, he conspired and, using mixers and several exchanges, obscured the transaction trail. He now faces up to 25 years of additional imprisonment. A telling case demonstrating that physical isolation does not always guarantee control over digital assets.

Interpol Strikes Record Blow: $293 Million and Nearly 6,000 Arrests

The global operation "First Light 2026" yielded impressive results. Law enforcement from 97 countries coordinated attacks on transnational fraud networks. Over three and a half months, 5,811 people were detained, and assets worth $293 million were confiscated or intercepted. The key tool was the I-GRIP system, which allowed instant freezing of both fiat transfers and cryptocurrency transactions. Particularly notable was a case in Thailand, where over $122.5 million from "romance scams" passed through a single crypto wallet in 10 months — criminals actively used cross-chain swaps to hide their tracks.

Free VPNs: Protection or Trojan Horse?

A large-scale study of over 280 free VPN apps from Google Play, collectively downloaded more than 2.4 billion times, revealed a critical threat. Instead of promised anonymity, many of them spied on users themselves. Over 80% of the apps contacted ad servers, transmitting unique device identifiers and GPS coordinates. 29 apps allowed DNS request leaks, revealing browsing history. And 169 services did not mask traffic, making users easy targets for blocking. The conclusion is clear: there's no such thing as a free lunch, and in the VPN world, this rule works flawlessly.

US Authorities Secretly Paid Ransom to Kairos Hackers

On June 13, 2025, a US government entity, presumably the Union County (Ohio) administration, transferred a ransom of 9.44 BTC (about $1 million) to the Kairos group. The attack was unconventional: the hackers did not encrypt data but simply stole 2 TB of information and blackmailed the victim with the threat of publication. The initial demand of $3 million was reduced to $1 million during month-long negotiations. The criminals split the payment and routed it through Bybit, OKX, and the Russian service BELQI. This is a vivid example of a new trend: abandoning complex ransomware in favor of "pure" blackmail, which does not require maintaining malicious software.

Hackers Turn Your Devices into Proxy Farms

The Lurking Lizard group infects computers and smartphones through trojanized installers of popular programs (7-Zip, WhatsApp), turning them into residential proxy nodes. These proxies are then rented out to other cybercriminals to conceal their attacks. The group's infrastructure includes over 230 fake domains, and one of their apps (wirevpn) has already been downloaded more than 1 million times. Illegal proxy networks are becoming a serious threat, as legitimate traffic from ordinary users may be mistakenly blocked due to activity originating from their IP addresses.

My expert opinion: This week clearly demonstrates the evolution of cyber threats. We are seeing a shift away from technically complex attacks (ransomware) towards simpler and more effective methods of blackmail and social engineering. Regulators and users need to adapt: trust in "free" services should be reduced to zero, and data protection must extend beyond simple antivirus software.