DeadLock targets Polygon, fake exchanges in Ukraine, and a Wi-Fi attack on a plane: weekly cybersecurity digest

This week, the cyber threat landscape once again proved that criminals are not standing still. From physical scams at "exchange" offices to decentralized extortion schemes using blockchain, attackers are actively exploring new horizons. I analyzed the key incidents to highlight the main trends and risks for the crypto industry.
Ukrainian network of fake exchanges: an absurd theater with millions in turnover
Ukrainian law enforcement dismantled the fraudulent network Money 24/7, which mimicked a legitimate exchange point. The scheme is striking in its audacity: the attackers rented an office, registered a trademark, and ran an active Telegram channel, creating an illusion of reliability. Clients were invited to the office, where they handed over cash but never received cryptocurrency. To stall for time, the fraudsters paid out part of the amount and issued "written guarantees." As a result, over 20 searches across seven regions seized more than 20 million hryvnias in cash. The organizer faces up to 12 years in prison. This case is a stark reminder that even "physical presence" is no guarantee of honesty.
FBI warns: hunting for intimate content
The FBI, together with the National Collegiate Athletic Association, is raising the alarm over a surge in attacks targeting the theft of intimate photos from cloud accounts. The scheme is classic: phishing SMS and emails demanding a "password reset." After breaching accounts, hackers blackmail victims, threatening to publish the material. Even after the ransom is paid, the content is often sold on the dark web, triggering a new wave of harassment. Particular attention is being paid to student-athletes, indicating a targeted selection of victims.
Attack on board: DEF CON returns home with a "surprise"
The incident on a Delta Air Lines flight from Las Vegas became almost a detective story. Passengers returning from the DEF CON hacking conference faced an attack on the onboard Wi-Fi. The attackers forcibly disconnected passengers' devices and deployed a fake "Delta WiFi Fast" network with a phishing page to steal Google passwords. The crew was forced to cut power to the Wi-Fi for 30 minutes. After landing, police interrogated suspects and seized equipment. The very fact that such an attack is possible on board speaks to the growing vulnerability of even isolated systems.
Jewelbug: spies and crypto scammers in one
Symantec analysts uncovered the double life of the Jewelbug group. On one hand, they attacked government institutions in the Middle East and Asia, infecting webmail through compromised hosting. On the other, they simultaneously ran a large-scale crypto fraud campaign: neural networks generated fake articles, and botnets promoted counterfeit Binance and OKX sites. The group's database contained over a million logs and 580,000 stolen cookies. This is a perfect example of the convergence of state espionage and financial cybercrime.
DeadLock: extortionists on the Polygon blockchain
The DeadLock group, with around a hundred victims, has revolutionized the world of ransomware. Instead of traditional servers, they have fully transitioned to decentralized infrastructure. The key element is a ransom note in the form of an HTML file that works as a standalone web application. JavaScript inside the file interacts with smart contracts on Polygon to rotate proxy server addresses. This allows hackers to instantly bypass blocks by simply updating records in the contract. This approach makes the extortionists' infrastructure nearly indestructible.
Polish combined heat and power plant: attack via cellular network
CERT Polska revealed details of an attack on a combined heat and power plant supplying heat to 50,000 residents. The uniqueness lies in the fact that hackers penetrated critical infrastructure through the private cellular network of the power grid operator, using standard equipment functions. The attack chain included breaching a wind power station without MFA, a Teltonika router with an unknown password, and a WAGO controller with a factory default password. Ultimately, the attackers stopped a steam turbine, destroying evidence. This incident underscores that the security of industrial networks often depends on the most trivial configuration errors.
My verdict: The main trend of the week is the evolution of extortionists toward decentralization. Using blockchain to manage attack infrastructure is not just a passing fad but a fundamental shift that will require law enforcement to adopt radically new methods of combat. The crypto community should closely monitor the development of DeadLock — this approach could become the new standard for all RaaS groups.