DeadLock masters Polygon, fake exchangers in Ukraine, and a Wi-Fi attack in the sky: cybersecurity digest

The week in cybersecurity was eventful: from the dismantling of a major fraud network in Ukraine to the innovative use of blockchain by ransomware operators. I break down the key events shaping the threat landscape for the crypto industry.
Ukrainian cyber police neutralized a network of fake exchangers
Law enforcement halted the activities of the fraudulent scheme Money 24/7, which skillfully mimicked a legitimate exchange service. The organizers created a convincing "storefront": quality websites, an active Telegram channel, a registered trademark, and even an office with a cash register. Clients were lured in with online applications and invited in person, where they handed over cash, after which contact was cut off and the cryptocurrency never arrived. To delay police reports, victims were returned a small portion of the sum and given "guarantee letters."
Damages from one episode exceeded 1.6 million hryvnias. During more than 20 searches across seven regions, over 20 million hryvnias in cash, equipment, and documentation were seized. The organizer faces up to 12 years in prison. This is a telling example of how classic offline scams adapt to cryptocurrency realities.
FBI reports an epidemic of hacks targeting intimate content
The Bureau warns of a sharp rise in attacks on social media and cloud storage accounts aimed at stealing explicit photos and videos. Attackers use phishing SMS and emails, scaring victims with account lockouts. Particular attention is paid to student athletes. After the hack, cybercriminals demand a ransom, threatening to publish the material. Even after payment, the content is often sold on the dark web, triggering new waves of extortion.
Wi-Fi attack on board Delta Air Lines
On Delta flight 591, traveling from Las Vegas after DEF CON, hackers used a deauthentication technique. They forcibly disconnected passengers' devices from the legitimate network and deployed a fake access point called "Delta WiFi Fast" with a phishing page to steal Google passwords. The crew cut power to the Wi-Fi for 30 minutes, and after landing, police seized equipment from suspects. The incident highlights the vulnerability of even isolated onboard systems to social engineering.
Jewelbug: espionage and crypto scam in one package
The China-linked group Jewelbug combined cyber espionage against government structures with large-scale crypto fraud. Analysts discovered that hackers, while breaching ministries' webmail, simultaneously used neural networks to generate hundreds of fake articles on domains masquerading as Binance and OKX. Botnets were used to promote the scam resources. The database contained over a million logs, 580,000 stolen cookies, and thousands of credentials. This confirms the convergence of state-sponsored cyber espionage and financial crime.
DeadLock moves infrastructure to Polygon
The ransomware group DeadLock introduced a revolutionary approach: it uses smart contracts on the Polygon blockchain to manage its infrastructure. Instead of a text note, the virus leaves an HTML file that functions as a standalone web application. Embedded JavaScript code reads the current proxy server IP address from the smart contract. If law enforcement blocks it, hackers simply update the record in the contract, and the chat works again. This creates "endless options" for bypassing blocks and raises infrastructure resilience to a fundamentally new level.
Cyberattack stopped a turbine at a Polish combined heat and power plant
CERT Polska revealed details of an attack on a heating plant that supplies heat to 50,000 residents. The uniqueness of the vector lies in the penetration through the private cellular network of the power grid operator. The hackers used standard protocols, starting with an unprotected MFA at a wind farm, then via a Teltonika router and a WAGO controller with a factory password reached the Siemens S7 PLC. They stopped the turbine and deleted evidence by resetting equipment settings. The incident demonstrates the critical importance of network segmentation and default password management in industrial environments.
My analysis: The use of blockchain in ransomware infrastructure is a wake-up call for the entire security industry. Decentralization makes fighting such groups fundamentally harder, requiring specialists to adopt new approaches to monitoring and response. Traditional methods of blocking domains and servers are losing effectiveness.