DeadLock expands onto Polygon, Ukrainian cyber police dismantle a network of fake exchangers, and other key events of the week.

The week was packed with cybersecurity events: from the takedown of a major fraud scheme in Ukraine to a revolutionary approach by extortionists to using blockchain. I break down the key incidents shaping new trends in digital threats.
Ukraine: Fake exchange Money 24/7 operated "offline"
Ukrainian cyber police shut down the activities of a sprawling network of fraudsters operating under the Money 24/7 brand. The organizers created a complete illusion of legitimacy: they registered a trademark, rented an office with a cash register, and ran an active Telegram channel. However, in reality, it was a classic "physical" scam — clients handed over cash at the office but never received cryptocurrency. To stall for time, victims were partially refunded and given fake "guarantee letters." During more than 20 searches, over 20 million hryvnias in cash were seized. The organizer faces up to 12 years in prison. This is a striking example of how fraudsters adapt traditional schemes to the realities of the crypto market, relying on psychological pressure and offline presence.
FBI warns: hunting for intimate content
The American bureau reports a surge in attacks targeting the theft of personal photos and videos from cloud services and social networks. Attackers use phishing emails and fake login pages. After breaching accounts, they demand ransom, threatening to publish the materials. A particular risk group is student athletes. Even after payment, victims' data is often sold on the dark web, triggering a wave of secondary attacks and cyberbullying. This is a reminder that digital hygiene is not just a recommendation but a necessity.
Attack on board: DEF CON takes to the skies
An incident on a Delta Air Lines flight showed that hackers know no boundaries. Passengers flying from the DEF CON conference were attacked via the onboard Wi-Fi. The attackers used spoofed packets to disable the legitimate network and deployed a fake access point called "Delta WiFi Fast," which harvested passwords for Google accounts. The crew was forced to cut power to the Wi-Fi for 30 minutes. Upon landing in Atlanta, police detained suspects and seized equipment. Notably, the aircraft's navigation systems are isolated, so flight safety was not threatened, but the very fact of such an attack on board is an alarming signal.
Jewelbug: espionage and crypto scam in one package
Symantec analysts uncovered the double life of the Jewelbug group. On one hand, they conducted sophisticated cyber-espionage operations against government institutions in the Middle East and Asia, breaching webmail through compromised hosting. On the other, they simultaneously profited from crypto fraud: their neural networks generated fake articles, and botnets promoted fake websites disguised as Binance and OKX to the top of search engines. The group's database contained over a million logs and 580,000 stolen cookies. This confirms that the line between state-sponsored cyber-espionage and mundane financial fraud is becoming increasingly blurred.
DeadLock: extortionists move to Polygon
The DeadLock group has made a breakthrough in infrastructure resilience. Instead of classic servers, they use the Polygon blockchain for dynamic rotation of proxy server addresses. The ransom note is a standalone HTML application that directly communicates with smart contracts. Blocking a single IP address is irrelevant: operators simply update the data in the contract, and the chat works again. This creates "endless options" for bypassing blocks. The malware itself is written in Rust and uses hybrid encryption. This approach makes fighting extortionists a fundamentally more complex task.
Polish CHP plant: attack via cellular network
CERT Polska revealed details of an attack on a combined heat and power plant providing heat to 50,000 people. The uniqueness of the vector lies in penetration through the private cellular network of the power grid operator. The hackers used standard equipment functions and permitted protocols, starting from an unsecured wind farm and ending with a factory password on a WAGO controller. Ultimately, they stopped a steam turbine and then methodically destroyed evidence. This case is a serious warning that critical infrastructure is vulnerable through seemingly secondary network elements.
My conclusion: The main trend of the week is the convergence of methods. Cybercriminals are no longer limited to a single tactic: they combine phishing, espionage, physical presence, and decentralized technologies. The use of blockchain by extortionists is not just an experiment but a paradigm shift that will require fundamentally new solutions from the security industry.