To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


Total Tests:
485,773,462
737,046
130,956

Cybercrime Weekly – October 2026, Week 1 – Issue #192

October 1, 2026

Six cases this week: the Snowflake extortion campaign, the Rydox marketplace, a ShinyHunters arrest, a €1M payment-tampering scheme, and a Bitcoin theft inside the UK’s National Crime Agency.

Views: 2.9k Read Time: 5 min.

Cybercrime Weekly – October 2026, Week 1 – Issue #192

US soldier gets 70 months for the Snowflake extortion campaign

Threat Actor
Malicious Actor
Dates of Activities
2024
Jurisdiction
United States
Offense
Hacking and extortion campaign
Victims
165 organizations
Financial Losses
Unknown

Former US Army soldier Cameron John Wagenius, 21, has been sentenced to 70 months in prison for his role in a hacking and extortion campaign targeting at least 10 US technology and telecommunications companies. Wagenius, who used the online names “kiberphant0m” and “cyb3rph4nt0m,” was arrested in Texas in December 2024 and pleaded guilty to hacking AT&T and Verizon, along with aggravated identity theft, wire fraud conspiracy and computer-related extortion.

Court documents say Wagenius and his accomplices stole login credentials and breached corporate networks, then threatened to release stolen data on cybercrime forums unless victims paid ransoms. The group tried to extort at least $1 million and used some stolen information in other fraud schemes.

He is the third person prosecuted over the 2024 Snowflake campaign, which also involves Connor Riley Moucka and John Erin Binns, accused of helping breach more than 165 organizations through accounts linked to Snowflake’s cloud data platform. Victims included AT&T, Ticketmaster, Santander, Los Angeles Unified, LendingTree, Pure Storage, Advance Auto Parts and Neiman Marcus. Moucka pleaded guilty in August 2026 and faces up to 30 years; sentencing is set for 27 October 2026.

Also: two former US Air Force members jailed for business email fraud

Two former US Air Force members were sentenced to a combined 189 months for phishing and business email compromise. While stationed at Dover Air Force Base, they stole email and financial information and used fake emails to redirect victims’ payments to accounts controlled by their accomplices.

Rydox marketplace admin pleads guilty after 7,600 deals

Threat Actor
Malicious actor
Dates of Activities
Active since 2016
Jurisdiction
United States
Offense
ID theft, money laundering
Victims
7,600+ transactions
Financial Losses
$232,000 or more

Ardit Kutleshi, 28, a Kosovar national, has pleaded guilty to charges linked to Rydox, an illicit marketplace used to buy and sell stolen personal information and cybercrime tools. According to court documents, Rydox carried out more than 7,600 transactions since at least 2016, generating at least $232,000 in revenue.

Kutleshi pleaded guilty in the US District Court for the Western District of Pennsylvania to aggravated identity theft and conspiracy to commit money laundering. He was arrested in Kosovo in December 2024 and extradited to the United States in 2025; that same month US authorities seized the Rydox[.]cc domain. He faces a mandatory minimum of two years for aggravated identity theft and up to 20 years on the laundering charge.

Dutch police arrest a ShinyHunters suspect in Amsterdam

Threat Actor
Hacker group
Dates of Activities
Unknown
Jurisdiction
Netherlands
Offense
Involvement with hacker group
Victims
Unknown
Financial Losses
Unknown

Dutch police have arrested a 24-year-old man from Amsterdam suspected of involvement with the ShinyHunters hacker group. The man was apprehended on 15 September 2026. During a search, police found a large amount of information on his laptop, including details about two planned murders abroad, and suspect he may have ordered the killings; that part of the investigation is separate from the ShinyHunters case. Police also seized several data carriers and have not ruled out further arrests. Authorities have not released the man’s name or further details.

ImmuniWeb Newsletter
Be the first to get the most recent issue of the Cybercrime Weekly in your inbox
Join 50,000+ cybersecurity, forensics, law enforcement and legal professionals

Private and Confidential Your data will stay private and confidential

US man sentenced to 40 years for sextortion of minors via a hacked Snapchat account

Malachi Morgan Thomas, a US resident, has been given a 40-year prison sentence for sexual exploitation of children and possession of child sexual abuse material. The US Department of Justice says Thomas used a hacked Snapchat account to coerce girls aged 12 to 17 into performing explicit acts, threatening to hack the victims’ accounts or harm them and their families if they did not comply. Prosecutors said he knew that several victims had a history of anxiety, depression and other mental health issues, that many had previously been subjected to sexual abuse, and that at least one was in foster care.

Spain arrests a suspect behind a €1M parameter-tampering scheme

Threat Actor
Malicious Insider
Dates of Activities
Unknown
Jurisdiction
Spain
Offense
Online scam
Victims
Major companies, payment gateways
Financial Losses
More than €1 million

Spanish National Police have arrested a man allegedly responsible for a network of online scams targeting major companies, with combined losses estimated at more than €1 million. According to authorities, the suspect manipulated communications between users and payment gateways using parameter tampering: by altering transaction parameters, he caused payment systems to validate transactions that had not actually been paid for in full.

The scheme allowed him to obtain concert and event tickets, airline tickets, hotel bookings and other services, including food deliveries from high-end restaurants. He also accessed internal corporate platforms to obtain employee-only benefits and redirect transactions. Police said he used numerous email accounts, identities and payment methods to conceal his activity, and was eventually arrested in a suite at a luxury hotel in Madrid’s Salamanca district.

Ex-NCA officer ordered to repay £1.8M after stealing seized Bitcoin

Threat Actor
Malicious Insider
Dates of Activities
2025
Jurisdiction
United Kingdom
Offense
Money theft and laundering
Victims
Unknown
Financial Losses
50 BTC, worth ~£60,000

A former officer of the UK’s National Crime Agency has been ordered to repay more than £1.8 million after stealing Bitcoin seized during an investigation into a dark web crime network. Paul Chowles, 44, was jailed for five years and six months in 2025 after admitting theft and money laundering. While working on the investigation, Chowles had access to digital devices seized by authorities and helped analyse cryptocurrency found on them.

He stole 50 Bitcoin, worth about £60,000 at the time, then moved it through a series of transactions in an attempt to hide the trail. Police recovered 30 Bitcoin. The cryptocurrency had been seized during the investigation into Silk Road 2.0, and a confiscation order of £1,810,678.93 was secured against Chowles, an amount that includes the current value of the recovered Bitcoin.

What’s next:

Talk to an Expert