Weekly cybersecurity highlights.
Here are the week’s top cybersecurity stories.
- Ukraine dismantled the Money 24/7 fake crypto exchange network; more than 20 million hryvnias seized.
- FBI: hackers are mass-hacking accounts to steal intimate photos and for cyberbullying.
- Hackers from DEF CON launched a cyberattack on passengers of a Delta Air Lines flight.
- Chinese hackers combined government espionage with crypto fraud.
Ukraine shuts down Money 24/7 fake crypto exchange network; over 20 million hryvnias seized
Ukrainian law enforcement detained the organizer of the Money 24/7 fraud ring, which operated under the guise of a legitimate service for exchanging fiat currencies and crypto assets. The country’s cyber police reported the case.
How the scheme worked:
- illusion of reliability. To disarm suspicion, the perpetrators built polished websites, ran an active Telegram channel, officially registered a trademark, and opened a presentable office outfitted as a cashier’s desk;
- in-person scam. Clients submitted an online order to buy cryptocurrency, were invited to the office, and asked to hand over cash. The money was taken, but the cryptocurrency never reached clients’ wallets;
- psychological tactics. To delay police reports, the scammers stalled victims. Some received a small portion of the agreed crypto amount and “written guarantees” that the transaction would be completed soon.


In one confirmed case alone, losses totaled nearly 1.6 million hryvnias. The exact number of victims was not known at the time of writing.
More than 20 searches across seven regions of Ukraine seized computer equipment, phones, documentation, and over 20 million hryvnias in cash.
The organizer faces up to 12 years in prison with asset confiscation.
FBI: hackers are mass-hacking accounts to steal intimate photos and for cyberbullying
The FBI warned of a surge in cyberattacks aimed at stealing intimate photos and videos from social media and cloud accounts.
In a joint statement, the bureau and the National Collegiate Athletic Association also emphasized that student-athletes have been singled out as targets.
The attack typically starts with a spoofed SMS or email. Victims are threatened with account lockout and urged to click a link to “reset the password” or forward a verification code.
After finding explicit content in a compromised account, attackers demand a ransom, threatening to send the images to family and friends or publish them publicly.
Even when victims pay, criminals often sell the stolen content on the dark web along with personal data such as name, date of birth, email, and phone number. This triggers new waves of harassment and extortion by other actors.
Hackers from DEF CON launched a cyberattack on passengers of a Delta Air Lines flight
Delta Air Lines, together with law enforcement, is investigating a cyber incident on Flight 591 from Las Vegas to Atlanta on August 10. Many attendees of the recently concluded DEF CON 34 hacking conference were on board, BleepingComputer reported, citing sources.
How the attack unfolded:
- forced disconnections. Attackers began sending spoofed packets that forcibly disconnected other passengers’ devices from the plane’s legitimate onboard Wi‑Fi;
- rogue network. In parallel, the hackers spun up their own network named Delta WiFi Fast;
- phishing and data theft. According to eyewitnesses, when connecting to the fake network, users saw a fraudulent login page designed to harvest personal data and Google account passwords.
DELTA FLIGHT 591 CARRYING PASSENGERS FROM DEF CON 34 IN LAS VEGAS HIT BY SUSPECTED WI-FI ATTACK MID AIR.
Delta Flight 591 from Las Vegas to Atlanta reportedly encountered a suspected Wi-Fi attack involving passengers returning from DEF CON 34, which concluded in Las Vegas on… pic.twitter.com/6cPqvbUFfz
— Turbine Traveller (@Turbinetraveler) August 11, 2026
An aircraft technician from Nairobi using the handle Turbine Traveller shared on X the view that messages sent by the Delta Air Lines Flight 591 crew via the Aircraft Communications Addressing and Reporting System (ACARS) indicate a rogue network was activated on board.
As an emergency precaution, the crew cut power and disabled the onboard Wi‑Fi for nearly 30 minutes. Delta Air Lines officially confirmed the incident but stressed that flight safety and the aircraft’s navigation systems were not threatened; onboard avionics are isolated from the passenger network. No alert was issued to controllers.
Once the plane reached the terminal in Atlanta, police boarded. Suspects were questioned on site, and their portable Wi‑Fi hacking equipment was seized.
Chinese hackers combined government espionage with crypto fraud
The group Jewelbug (also known as Earth Alux or REF7707) conducted complex cyberespionage while simultaneously stealing cryptocurrency. Symantec reported the group’s “double life.”
Analysts have high confidence that the financially motivated part of the attacks is tied to a legitimate Chinese company offering SEO services, suggesting the group may be working as hired hackers.
According to experts, in a recent campaign the attackers targeted government and military organizations in the Middle East, Southeast Asia, and South Asia. To do this, Jewelbug compromised a shared web-hosting platform of a state telecom provider, giving them access to webmail templates used by 15 different government ministries and agencies.
Injected JavaScript code opened a WebSocket connection to the attackers’ server at each login and stole session cookies.
If the algorithm flagged a target as especially valuable, the user saw a fake Adobe Flash update window. With the victim’s consent, the Antino backdoor and a malicious browser extension, PDF Viewer, were installed to intercept traffic and enable remote control.
After gaining access to Jewelbug’s management infrastructure, analysts found the hackers were also running a fraud operation:
- the group’s neural networks mass-generated fake articles published on hundreds of domains impersonating crypto exchanges Binance and OKX;
- botnets were used to push the scam sites to the top of search results;
- in addition to cryptocurrencies, the traffic was tied to scam resources, sports betting, pirated streams, and fake private investigators.


In the group’s database, specialists found over 1 million malware activity logs, 580,000 stolen cookies, thousands of credentials, and more than 2,300 emails.
To infect Linux servers and ASUS routers, the group used a custom Rust Trojan called ClientKing. To evade defenses, they hid malicious payloads in public Google Docs, blending traffic with legitimate content.
DeadLock ransomware leverages Polygon to protect its infrastructure
The DeadLock ransomware group, which has nearly 100 victims in the U.S., Europe, and Turkey, has radically changed how it builds its infrastructure. To defend against takedowns by authorities, the hackers moved entirely to decentralized solutions, Microsoft Threat Intelligence reported.
Analysts noted that DeadLock, now actively used by affiliates of other CaaS groups such as Lynx and INC, has abandoned traditional servers in favor of a blockchain ecosystem.
The most unusual element of their attacks is the ransom note format. Instead of a typical text file, the malware leaves a file named RECOVERY_CHAT.
Microsoft says this architecture takes infrastructure resilience to a new level, allowing operators to recover quickly from attempts by law enforcement to disrupt operations.
Experts at Group-IB detailed how this decentralization works.
JavaScript code inside the HTML file interacts directly with smart contracts on the Polygon blockchain to rotate addresses. The app reads from the contract the current IP address of a proxy server used to reach the operators. If law enforcement blocks it, the hackers do not need to re-register domains or change files on the victim’s machine — they only need to update the smart contract entry and the chat works again.
Posts about breaches and leaked data are also tied to smart contracts and distributed via the decentralized Wasabi protocol.
Specialists noted that this method lets attackers create “literally endless options” to bypass blocking.


Technical details of the malware:
- encryption. Uses a hybrid of Curve25519 elliptic-curve cryptography and the XChaCha20 stream cipher. Files receive the .dlock extension;
- process masking. To keep users from noticing slowdowns during encryption, the process pauses if CPU load exceeds 70% or RAM usage rises above 29%;
- cleanup. DeadLock is hard-blocked from running in CIS countries and some Middle Eastern states. After finishing, the malware deletes system logs, shadow copies (VSS), and self-destructs.
A turbine at a Polish combined heat and power plant shut down following a cyberattack
Poland’s national incident response team CERT Polska disclosed details of a cyberattack that disrupted a local combined heat and power plant supplying heat to about 50,000 residents. The incident occurred in December 2025, but the investigation results were published only now.
The case is notable for its penetration method: attackers reached critical infrastructure via a private cellular network of the local power distribution operator. Experts note this is the first recorded instance of this vector being used in a real attack on industrial facilities.
The campaign relied solely on standard equipment features and permitted protocols.
Key stages of the breach:
- It started at a wind farm where a critical system component lacked multi-factor authentication. The attackers obtained administrator rights.
- From the firewall, the attackers reached a Teltonika RUTX50 cellular router via a secondary Ethernet port and authenticated over SSH (the password was not default; how it was compromised is unknown).
- The main configuration error was in the distribution company’s private network: settings allowed direct client-to-client traffic. The attackers scanned the network and discovered a WAGO PFC200 controller at the target CHP plant.
- The WAGO device was protected only by the factory default password. Through it, the attackers tunneled directly into the plant’s internal network.


On December 29, the attackers put Siemens S7 programmable logic controllers into stop mode and changed passwords. This caused a physical shutdown of the steam turbine and water treatment system.
To complicate the investigation, the attackers systematically destroyed evidence: they deleted the partition table on the WAGO controller (it stopped booting) and reset servers, the Teltonika router, and a FortiGate firewall to factory settings, assigning unreachable IP addresses.
Prompt action by staff restored operations.
Also on ForkLog:
- The U.S. will step up efforts against cybercrime with support from the private sector.
- Trezor reported a data breach affecting nearly 14,000 customers.
- WSJ exposed a network of North Korean workers in U.S. companies.
- Taiwan government agencies suffered a cyberattack using AI.
- Boltz’s creators handed over the project to a group of “Bitcoin veterans” after AI-hacker attacks.
- A hacker drained $200,000 from an XRP cross-chain bridge.
- North Korea used scam networks to launder stolen crypto assets.
- BTCPay offered a bounty of up to 3 BTC for the return of stolen coins.
- North Korean hackers integrated local AI into attacks on crypto firms.
- Researchers disclosed details of the $8 million Coinsbuy hack.
- BitMart’s founder denied allegations of misappropriating user funds.
- Hackers drained Lightning nodes via a vulnerability in BTCPay.
What to read this weekend?
In a new ForkLog piece, we discuss how attacks on control are becoming the norm, and how the human factor combined with AI analysis is a gift to hackers.
Found a mistake in the text? Select it and press CTRL+ENTER
Click Here For The Original Source.
