In recent days, the cybersecurity world has been shaken by a series of high-profile incidents that directly affect the interests of the crypto community. From secret Bitcoin ransoms to mass espionage via free VPNs, let's break down the key events.
U.S. Government Paid Hackers 9.4 BTC
On June 13, 2025, the administration of Union County, Ohio, transferred a ransom of 9.44 BTC (~$1 million) to the Kairos group. This is not a classic data-encrypting attack: the attackers simply stole 2 TB of confidential information and blackmailed the victim with the threat of publication. Initially, they demanded $3 million, but after a month of negotiations, the amount was reduced to $1 million. The hackers fragmented the received funds and routed them through Bybit, OKX, and the Russian service BELQI. Notably, Kairos ceased activity, but associated wallets continued moving funds until May 2026. This confirms a global trend: cybercriminals are abandoning complex encryption in favor of pure blackmail—it's simpler and cheaper.
Free VPNs: Protection or Surveillance?
Researchers from the University of Michigan and other institutions analyzed 280 free VPNs from Google Play. The findings are alarming: 29 apps (360 million installations) allowed DNS request leaks, and six leaked browser traffic outside the tunnel. Over 80% of services contacted ad servers, transmitting unique device identifiers and GPS coordinates. 89% use only one authentication method, and some rely on outdated Blowfish and Triple DES ciphers. Essentially, such VPNs do not protect but instead spy on users, negating the very idea of anonymity.
Interpol Seized $293 Million and Arrested 5,800 People
Operation First Light 2026, involving 97 countries, resulted in the confiscation of $293 million in assets and the blocking of 31,000 accounts and crypto wallets. A key tool was the I-GRIP system, which allows freezing cryptocurrency transactions in real time. A notable case in Thailand involved a single wallet processing over $122.5 million from "romance scams" over 10 months, converted through cross-chain swaps. This demonstrates that law enforcement is adapting to crypto tools faster than many think.
Hackers Turn Devices into Proxy Nodes
The Lurking Lizard group infects computers and smartphones through fake installers of popular programs (7-Zip, WhatsApp) and uses them as residential proxies. The botnet includes over 230 fake domains, and one of their apps—wirevpn—has been downloaded over 1 million times. These proxies are rented out to other cybercriminals to hide attack traces. The problem is that legitimate traffic from ordinary users may be blocked by providers as a result, creating a false sense of guilt for owners of infected devices.
Inmate Withdrew Confiscated $290,000 in Cryptocurrency
Rosen Iosifov, serving a 111-month sentence for fraud, managed to organize the withdrawal of previously confiscated $290,000 in cryptocurrency. He used mixers and several exchanges to obscure the trail. He now faces up to 25 additional years in prison. This case highlights that even in prison, crypto assets remain vulnerable to skilled manipulation if proper controls are not in place.
My expert opinion: The cybersecurity market in the crypto sphere is undergoing a tectonic shift. The transition of hackers from encryption to data theft and blackmail requires investors and companies to rethink their protection strategies. Free VPNs are a trap, not a salvation. The only path is to use proven open-source solutions and hardware wallets for storing assets. Ignoring these trends could cost millions.