Crypto news

15.08.2026
11:11

DeadLock is mastering Polygon, Ukrainian scammers lose millions, and hackers attack airplanes: cybersecurity digest

security_new4

Another week brought a whole range of threats—from run-of-the-mill scams to attacks on critical infrastructure. I break down the key events shaping the digital security landscape.

Ukrainian network of fake exchangers: a show with an office and "guarantees"

Law enforcement dismantled the fraudulent network Money 24/7, which mimicked a legitimate exchange office. The scheme was thought through to the smallest detail: polished websites, an officially registered trademark, and even an office with a cash register to project credibility. Clients were lured online, asked to hand over cash in person, after which the cryptocurrency, of course, never arrived. To stall for time, some victims were even sent partial payments and given "written guarantees." The result—more than 20 million hryvnias seized, and the organizer faces up to 12 years in prison. This is a clear example of how classic "physical" scams adapt to the crypto industry.

FBI warns: theft of intimate photos is becoming widespread

The Bureau is recording a surge in attacks on social media and cloud accounts for extortion purposes. Particular attention is being paid to student athletes. The scheme is simple: phishing messages threatening account suspension, password theft, and searches for compromising content. Then comes blackmail. Notably, even after the ransom is paid, the data is often resold on the dark web, triggering a new wave of harassment. This is a reminder that digital hygiene is not just about protecting money, but also about protecting your personal life.

Hacker attack aboard an airplane: the DEF CON flight

The incident on a Delta Air Lines flight from Las Vegas is the epitome of irony. Passengers flying from the DEF CON hacking conference became victims of an attack themselves. Attackers forcibly disconnected devices from the legitimate Wi-Fi and deployed a fake network with a phishing page to steal Google passwords. The crew was forced to cut power to the onboard internet. Police detained suspects right at the jet bridge. This case demonstrates the vulnerability of even seemingly the most protected environments.

Jewelbug: the double life of Chinese hackers

The group Jewelbug, known for espionage on behalf of the government, turned out to be involved in run-of-the-mill crypto fraud. Analysts discovered that the same infrastructure used to hack government agencies in the Middle East generates fake articles and websites masquerading as Binance and OKX. Botnets are used to promote scam resources. This is a dangerous symbiosis: state-sponsored cyberespionage and financial fraud operating under one roof.

DeadLock: next-generation ransomware on the blockchain

The most technologically advanced move of the week was made by the group DeadLock. Instead of traditional servers, they use smart contracts on the Polygon network to manage their infrastructure. The ransom note is not a text file, but a full-fledged HTML application that communicates with operators through a decentralized network. This makes blocking their infrastructure practically pointless, as communication addresses can be changed instantly via the blockchain. A sad but important trend: criminals are the first to adopt the most cutting-edge technologies to protect their operations.

Cyberattack on a combined heat and power plant in Poland: a new penetration vector

CERT Polska revealed details of an attack on a combined heat and power plant supplying heat to 50,000 people. Attackers infiltrated the network through the private cellular network of the power grid operator, exploiting configuration vulnerabilities and default factory passwords. They managed to stop a steam turbine. This is the first documented case of using such a vector to attack industrial facilities, highlighting the need to rethink approaches to critical infrastructure security.

My take: This week showed that the boundaries between cybercrime, espionage, and even the physical world are blurring. The use of blockchain by ransomware actors is a wake-up call for the entire security industry. We need to think one step ahead, or we will forever be chasing criminals who have already mastered decentralization.