The world of cybersecurity continues to surprise: from secret ransoms in Bitcoin to large-scale Interpol operations. I have analyzed the key events of this week that directly affect the interests of the crypto community.

Secret Ransom: US Authorities Paid Hackers 9.4 BTC

A US government entity, presumably the administration of Union County, Ohio, on June 13, 2025, transferred a ransom of 9.44 BTC (approximately $1 million at the time of the transaction) to cybercriminals from the Kairos group. This is confirmed by on-chain data analysis from Ransom-ISAC.

The hackers did not use ransomware to encrypt infrastructure. Instead, they simply stole 2 TB of confidential data and blackmailed the victim with the threat of its publication. Initially demanding $3 million, during month-long negotiations they reduced the amount to $1 million. The received funds were fragmented and passed through a chain of wallets, including deposit addresses on Bybit, OKX, and the Russian service BELQI.

My expert opinion: This attack is a clear example of a shift in cybercriminal tactics. Abandoning complex encryption in favor of pure blackmail makes attacks faster and cheaper for attackers. Investors should remember: even large organizations may be forced to pay a ransom, confirming the vulnerability of any centralized data storage system.

Interpol: $293 Million Intercepted, 5,800 Arrested

The global special operation First Light 2026, coordinated by Interpol with the participation of 97 countries, yielded impressive results. During raids from January 15 to April 30, 2026, 5,811 suspects were arrested, over 31,000 bank accounts and crypto wallets were blocked, and assets worth $293 million were intercepted. Criminals actively used complex cross-chain swaps for money laundering, especially in "romance scam" schemes.

Free VPNs: Spies, Not Protectors

Researchers from the University of Michigan and other institutions analyzed 280 free VPNs from Google Play. The results are shocking: 89% of services use unreliable authentication methods, and 29 apps (with ~360 million installs) allow DNS request leaks. Moreover, 80% of apps communicate with ad servers, transmitting unique device identifiers and even GPS coordinates. This means a "free" VPN often becomes a surveillance tool itself.

My expert opinion: Crypto traders and investors using VPNs to access exchanges or private wallets should avoid free services. They not only fail to protect but can also compromise your data. A paid, verified VPN with open-source code is the only reasonable choice.

Inmate Withdrew $290,000 from Prison

Bulgarian citizen Rosen Yosifov, serving a 111-month sentence for fraud involving the cryptocurrency exchange RG Coins, managed to organize an illegal withdrawal of his confiscated $290,000 in cryptocurrency. To obscure the trail, he used multiple exchanges and mixers. He now faces up to 25 additional years for concealing assets.

Hackers Turn Your Devices into Proxy Nodes

The Lurking Lizard group infects computers and smartphones through fake installers of popular programs (7-Zip, WhatsApp) and turns them into residential proxies. These nodes are then rented out to other cybercriminals to hide attack traces. The network includes over 230 fake domains and has been operational since August 2022.

Analyst's final thought: This week showed that cybersecurity in the crypto world is not just about protecting against DeFi protocol hacks. It is a fight against government ransoms, fake VPNs, and global fraud networks. Investors need to be vigilant and use only verified tools, rather than relying on "free" solutions.