The week in cybersecurity was eventful: from a high-profile ransom paid in Bitcoin by U.S. authorities to large-scale Interpol operations and the exposure of dozens of free VPN services that turned out to be surveillance tools themselves.

U.S. Authorities Paid Hackers 9.4 BTC for Silence

In June 2025, a U.S. government agency (presumably the Union County administration in Ohio) transferred a ransom of 9.44 BTC (about $1 million at the time of the transaction) to cybercriminals from the Kairos group. This follows from an analysis of blockchain data and negotiation logs conducted by Ransom-ISAC experts.

The attack's peculiarity is that the hackers did not use classic ransomware. Instead of encrypting infrastructure, they stole 2 TB of confidential information, including data from the "prosecutor's office" folder, social security numbers, and fingerprints, and threatened to publish it. Initially, the criminals demanded $3 million, but after a month of negotiations, they reduced the amount to $1 million.

After receiving the funds, Kairos fragmented the transfer and routed it through a chain of wallets, directing it to deposit addresses on the crypto exchanges Bybit, OKX, and the Russian service BELQI.

Interpol Intercepted $293 Million and Arrested Nearly 6,000 People

Interpol's global special operation First Light 2026 led to the detention of 5,811 suspects and the interception of assets worth $293 million. Law enforcement from 97 countries participated in the operation, targeting organized groups specializing in investment scams, romance scams, and blackmail.

The I-GRIP mechanism allowed freezing both traditional bank transfers and cryptocurrency transactions. During the raids, over 31,000 accounts and crypto wallets were blocked, and more than 23,700 criminal cases were uncovered. One of the largest incidents was in Thailand, where two suspects were arrested for laundering proceeds from a "romance scam": over $122.5 million passed through their crypto wallet in 10 months.

Free VPNs: Protection or Espionage?

Researchers from the University of Michigan and the Indian Institute of Technology analyzed over 280 free VPN apps from Google Play. The results were alarming: many services not only fail to protect users but also collect and transmit their data.

Over 80% of the apps contacted ad servers, transmitting the device's unique advertising identifier and metadata. 29 apps (about 360 million installations) allowed DNS query leaks, and six leaked all browser traffic outside the encrypted tunnel. 89% of services used only one authentication method, and some relied on outdated and vulnerable ciphers like Blowfish and Triple DES.

Hackers Turn Devices into Proxy Nodes

The Lurking Lizard group infected millions of computers and smartphones, secretly turning them into residential proxy nodes. These proxies were then rented out to other cybercriminals to hide the traces of their attacks.

To spread the malware, infected installers of popular programs were used, including 7-Zip, WhatsApp, and VPN services. One of the group's mobile apps, wirevpn, has already exceeded 1 million downloads. Lurking Lizard's infrastructure includes over 230 fake domains, and the group disguises itself as well-known proxy providers, creating a network of fake sites with "independent reviews."

Expert Opinion

These incidents confirm a global shift in cybercriminal tactics: hackers are increasingly abandoning complex encryption in favor of pure blackmail and data theft. And free VPNs, which were supposed to be a shield for users, are turning into surveillance tools. In such conditions, the only way to maintain privacy is to carefully check the software you use and not trust "free" services.