DeadLock moves to Polygon, Ukrainian cyberpolice busted a network of fake exchangers, and other events of the week.

The week in cyberspace was eventful: from physical scams at "crypto exchange" offices to sophisticated attacks on airline passengers and state power grids. I break down the key incidents shaping new trends in digital security.
Ukraine: "Physical" Scam Under the Money 24/7 Brand
Law enforcement dismantled a fraudulent network operating under the guise of a legitimate exchange service. The scheme was cynical in its simplicity: clients were lured into an office equipped as a cash desk, cash was accepted, but cryptocurrency was never sent. For credibility, the perpetrators even registered a trademark and ran an active Telegram channel. The scale is impressive: over 20 million hryvnias in cash was seized, and in one episode alone, damages exceeded 1.6 million hryvnias. The organizer faces up to 12 years in prison.
Cyber Threats in the Air and on the Ground
An incident on a Delta Air Lines flight from Las Vegas after DEF CON exposed the vulnerability of onboard Wi-Fi networks. Hackers forcibly disconnected passengers from the legitimate network, deploying a fake access point to harvest passwords. The crew was forced to power down Wi-Fi for 30 minutes. Notably, the attack did not affect navigation systems, but the very fact of such a scenario in the confined space of an aircraft is a warning signal for the entire aviation industry.
In Poland, details emerged of an attack on a combined heat and power plant supplying heat to 50,000 residents. The attackers infiltrated the network through the power grid operator's private cellular infrastructure, exploiting configuration vulnerabilities and factory passwords. This is the first documented case of such a vector being used against industrial facilities. The attack led to an actual shutdown of a steam turbine, underscoring the critical importance of network segmentation and changing default credentials.
DeadLock: Next-Generation Ransomware on the Blockchain
The DeadLock group, which targets companies in the US and Europe, has revolutionized its infrastructure. Instead of traditional servers, they use smart contracts on Polygon to rotate proxy server addresses. The ransom note is now a full-fledged HTML application with built-in chat and end-to-end encryption. This approach makes ransomware infrastructure nearly indestructible: even if law enforcement blocks a server, hackers simply update a record on the blockchain, and communication with the victim is restored. This is a serious challenge for the entire cybersecurity industry.
Chinese Espionage and Crypto Scam in One Package
Analysts uncovered the double life of the Jewelbug group. On one hand, they conducted sophisticated espionage operations against government structures, stealing cookies and installing backdoors via fake Adobe Flash updates. On the other, they simultaneously generated fake articles using AI to promote fraudulent sites masquerading as Binance and OKX. This hybridization of state-sponsored cyber espionage with commercial scamming is becoming the new norm, requiring a rethink of defense approaches.
My analysis: The shift of ransomware operators to decentralized infrastructure is not just a trend but a fundamental shift. Law enforcement agencies, accustomed to fighting servers and domains, will now face the need to monitor and block blockchain activities, which is significantly more complex. The industry must prepare for a new era of attacks where eliminating attackers' infrastructure becomes a nearly impossible task.