DeadLock is mastering Polygon, Ukrainian fake exchangers have been shut down, and other cybersecurity events of the week.

The week was packed with events in the world of cybersecurity. From physical scams in Ukraine to decentralized extortion schemes using blockchain for invulnerability. I break down the key incidents shaping new trends in digital threats.
Ukrainian network of fake exchangers: 20 million hryvnias seized
Ukrainian law enforcement neutralized the fraudulent network Money 24/7, which masqueraded as a legitimate exchange office. The organizers created a full illusion of reliability: quality websites, an active Telegram channel, a registered trademark, and even an office with a cash register. Victims were lured with online applications and invited to the office, where cash was collected, but cryptocurrency was never transferred. To stall for time, some were paid a small portion of the amount and given "written guarantees." Damages from one episode exceeded 1.6 million hryvnias. During 20 searches in seven regions, more than 20 million hryvnias were seized. The organizer faces up to 12 years in prison.
FBI: hunting for intimate photos and cyberbullying
The FBI is recording a surge in attacks targeting the theft of intimate materials from social media and cloud storage. Special attention is paid to student athletes. The scheme is classic: phishing SMS and emails demanding a password reset. After the breach, attackers demand a ransom, threatening publication. Even upon payment, the stolen content is often sold on the dark web along with personal data, triggering a wave of repeat extortion. This is a reminder: two-factor authentication is not a luxury, but a necessity.
Attack aboard Delta Air Lines: hackers from DEF CON
On Delta flight 591, traveling from Las Vegas to Atlanta, passengers encountered a cyberattack. The attackers, likely DEF CON 34 attendees, sent fake data packets, disconnecting devices from legitimate Wi-Fi, and deployed a fake network called "Delta WiFi Fast." Upon connecting, a phishing page opened to steal Google passwords. The crew turned off the onboard Wi-Fi for 30 minutes. Police interrogated suspects right at the jet bridge, seizing their equipment. This case highlights the vulnerability of even isolated onboard systems to social engineering.
Jewelbug: the double life of Chinese hackers
The Jewelbug group combined government espionage with crypto fraud. Analysts link their financially motivated activities to a legitimate SEO company, indicating a "hackers for hire" model. They compromised a government operator's web hosting platform, gaining access to the email of 15 ministries. Injected JavaScript stole session cookies, and for valuable targets, the Antino backdoor was installed via a fake Adobe Flash update. Simultaneously, botnets generated fake articles on hundreds of domains masquerading as Binance and OKX to steal cryptocurrencies. The database contains over a million logs and 580,000 stolen cookies.
DeadLock: extortionist on the Polygon blockchain
The DeadLock group, attacking the US, Europe, and Turkey, has fully transitioned to decentralized infrastructure. Instead of traditional servers—smart contracts on Polygon. The ransom note is now a standalone HTML file (RECOVERY_CHAT.html) that runs in the browser and interacts with the blockchain to rotate proxy server addresses. If law enforcement blocks a server, hackers simply update the record in the smart contract. This creates "endless options" for bypassing blocks. Technically, the malware uses Curve25519 and XChaCha20, disguises itself as legitimate load, and self-destructs. This is a troubling signal: blockchain is becoming a shield for cybercrime.
Polish thermal power plant halted via cellular network
CERT Polska revealed details of an attack on a combined heat and power plant providing heat to 50,000 people. The attackers infiltrated through the power grid operator's private cellular network—the first documented case of such a vector. The chain: breaching a wind farm without MFA, accessing a Teltonika router via SSH, scanning the network, and discovering a WAGO controller with a factory password. Through it, hackers stopped a Siemens S7 turbine and the water treatment system. Evidence was methodically destroyed, including resetting equipment settings. This incident is a vivid example of how the human factor and outdated configuration become the main vulnerabilities of critical infrastructure.
My conclusion: The trend toward decentralization of attacks—DeadLock and Jewelbug—shows that traditional blocking methods are becoming obsolete. The industry needs to rethink protection approaches, betting on proactive monitoring and staff training rather than reactive measures. Blockchain, which we consider a tool of freedom, is increasingly becoming a weapon in the hands of attackers.