DeadLock moves to Polygon, Ukrainian cyber police dismantled a network of fake exchangers and other events of the week

Another week brought a whole range of incidents—from the takedown of an offline scam to the innovative use of blockchain in the extortionists' arsenal. I break down the key events in the world of cybersecurity.
Ukraine: Fake exchange Money 24/7 operated "offline"
Ukraine's cyber police neutralized the activities of the fraudulent network Money 24/7, which masqueraded as a legitimate exchange office. The organizers took a thorough approach: they registered a trademark, created a high-quality website, ran a Telegram channel, and even rented an office with a cash register. Clients who submitted online applications to buy cryptocurrency were invited "in person," where they handed over cash but never received the assets. To prevent victims from immediately contacting the police, the scammers practiced partial payments and issued "written guarantees." During more than 20 searches across seven regions, over 20 million hryvnias in cash were seized. The organizer faces up to 12 years in prison. This is a telling example of how classic scams adapt to the crypto market by leveraging trust in "physical" presence.
FBI warns of a wave of hacks targeting intimate content
The Bureau and the National Collegiate Athletic Association are recording a surge in attacks aimed at stealing personal photos and videos from cloud accounts. The scheme is standard: phishing SMS or emails threatening account blocking, theft of credentials, and then blackmail. Particular attention is paid to student-athletes. Even after the ransom is paid, the content is often sold on the dark web, triggering a new wave of harassment. This is a reminder that digital hygiene is not just a recommendation but a necessity.
Cyberattack onboard a Delta Air Lines flight
Flight 591, traveling from Las Vegas to Atlanta after DEF CON 34, became the scene of an attack on passengers. The attackers, presumably on board, used spoofed data packets to disconnect devices from the legitimate Wi-Fi and deployed a fake network called "Delta WiFi Fast" with a phishing login page. The crew was forced to cut off the onboard internet for 30 minutes. After landing, police interrogated the suspects and seized equipment. The incident highlights vulnerabilities even in closed environments, where trust in a network's name can be used against passengers.
Jewelbug: The double life of Chinese hackers
The Jewelbug group (Earth Alux) combined government espionage with large-scale crypto fraud. Symantec analysts found that the hackers attacked government institutions in the Middle East and Asia using a compromised web hosting platform. In parallel, they ran a network of fake sites masquerading as Binance and OKX, promoting them through botnets. Their database contained over a million logs, hundreds of thousands of stolen cookies, and thousands of credentials. This is a striking example of the convergence of state-sponsored cyberespionage and financial crime.
DeadLock: Extortionists on the Polygon blockchain
The DeadLock group, which targets companies in the US and Europe, took a revolutionary step by fully moving its infrastructure to decentralized solutions. Instead of traditional servers, they use smart contracts on Polygon to rotate proxy server addresses. The ransom note is now a standalone HTML application with built-in chat and a browser for stolen data. This approach makes blocking the infrastructure practically pointless: restoring communication only requires updating a record in the contract. This is an alarming signal for the entire security community.
Attack on Poland's power grid via the cellular network
CERT Polska revealed details of an incident at a combined heat and power plant providing heat to 50,000 people. The attackers breached the system through the power grid operator's private cellular network, using standard equipment functions. The attack chain began at a wind farm without MFA and led to the shutdown of a steam turbine via Siemens S7 controllers. This is the first documented case of such a vector being used, underscoring the growing complexity of threats to critical infrastructure.
My conclusion: The week showed that cybercrime is becoming increasingly hybrid and tech-savvy. The shift of extortionists to blockchain is not just a trend but a fundamental change in their resilience. Regulators and companies will have to rethink their defense strategies, paying attention not only to the perimeter but also to decentralized channels now used to manage attacks.