Issue #193 | October 2026, Week 2
8 de octubre de 2026Five cases this week: MonsterCloud LLC owner accused of cooperation with ransomware gangs, KillSec cybercriminal gang dismantled, Qilin member extradited to Germany, Former CIA officer pleads guilty to financial fraud scheme.

Ransomware recovery company owner charged with fraud for secretly paying cybercriminals
- Jurisdicción
- Estados Unidos
- Actor de amenazas
- Individual
- Incriminated Activity
- Wire fraud
- Estimated Damage
- $11 million
- Enforcement Action
- Arresto
- Case Status
- Investigation pending
El propietario de una empresa de recuperación de ransomware ha sido acusado de supuestamente estafar a las víctimas pagando en secreto a ciberdelincuentes por claves de descifrado, mientras afirmaba que su empresa poseía tecnología propia para recuperar archivos cifrados.
La fiscalía afirma que Zohar Pinhasi, de 50 años, también conocido como «Zack Silver» y «Zack Green», era propietario de MonsterCloud LLC, una empresa con sede en Florida que ayudaba a las empresas a recuperarse de ataques de ransomware. La empresa afirmaba poder restaurar datos cifrados sin pagar a los hackers. Sin embargo, la fiscalía alega que Pinhasi y sus socios contactaban frecuentemente a grupos de ransomware, pagaban por claves de descifrado y utilizaban dichas claves para recuperar los archivos de los clientes.
In one case, Pinhasi allegedly paid a ransomware group about $8,200 but charged the victim around $150,000. In another case, prosecutors say he paid about $236,000 and charged the customer roughly $380,000.
The indictment says MonsterCloud also used recovered sample files to convince customers that it could decrypt their data, even when the files had been decrypted using keys obtained from attackers.
Over the five-year period from June 2018 to June 2023, Pinhasi and his co-conspirators allegedly helped facilitate more than $8 million in ransom payments and charged more than $19 million for recovery services.
Pinhasi faces one count of conspiracy to commit wire fraud and two counts of wire fraud. If convicted, he could face up to 20 years in prison.
Former engineer gets nearly 3 years for a ransomware attack against his employer
- Jurisdicción
- Estados Unidos
- Actor de amenazas
- Individual
- Incriminated Activity
- Ransomware-style attack
- Estimated Damage
- Thousands of devices disrupted
- Enforcement Action
- 32-month prison sentence
- Case Status
- Court judgement
A former infrastructure engineer has been sentenced to 32 months in prison for carrying out a ransomware-style attack against his former employer, locking thousands of devices and demanding a $750,000 ransom.
Daniel Rhyne, 57, of Kansas City, Missouri, pleaded guilty to the attack on the New Jersey-based industrial company where he previously worked. He was arrested in August 2024.
According to court documents, Rhyne accessed the company's network using an administrator account. He changed passwords, deleted administrator accounts, and blocked access to hundreds of servers and thousands of workstations.
Rhyne also shut down servers and workstations and sent employees an email claiming the company's backups had been deleted and demanding 20 bitcoin (worth about $750,000 at the time). He threatened to shut down 40 servers each day unless the ransom was paid.
La investigación reveló que Rhyne había buscado en línea cómo cambiar contraseñas de administrador, eliminar cuentas de red, borrar registros de Windows y apagar computadoras de forma remota.
Rhyne didn’t receive any ransom, but the attack caused major disruption to the company's network, leaving employees unable to access many systems.
La policía apunta a la banda de ransomware KillSec y detiene a un presunto líder
- Jurisdicción
- International (10 countries)
- Actor de amenazas
- Ransomware group
- Incriminated Activity
- Ransomware extortion
- Estimated Damage
- 110 TB of stolen data
- Enforcement Action
- Three arrests, infrastructure seizure
- Case Status
- Investigation pending
An international law enforcement operation has disrupted the KillSec ransomware group, with authorities seizing its data leak site and servers and arresting three suspects.
The operation, called “Operation KillSwitch,” took place on September 30 and involved authorities from 10 countries, including Germany, the United States, Belgium, Finland, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom.
La policía identificó a un joven de 16 años como el presunto operador principal de KillSec. Otro presunto miembro, descrito como desarrollador, cumplió 18 años en agosto de 2026, pero era menor de edad cuando se cometieron algunos de los presuntos delitos. Las autoridades también han identificado a presuntos miembros implicados en negociaciones y operaciones de afiliados. La policía registró ocho propiedades en Grecia, Rumanía, España y el Reino Unido. Las autoridades también desactivaron cinco servidores vinculados al grupo y se incautaron de al menos 110 terabytes de datos robados.
US authorities have charged a KillSec member, identified as Fouad Eltibrizi (aka Archduke), with unauthorized access to a computer system, causing damage to a computer, and extortion. Eltibrizi, a Dutch national, was arrested on September 30, 2026, in the UK.
Authorities believe KillSec carried out around 1,000 suspected attacks worldwide, with about 500 considered successful so far. At least 70 attacks targeted organizations in Germany.
KillSec lleva en activo desde aproximadamente 2024. Al parecer, el grupo explotaba vulnerabilidades de software y sistemas mal protegidos para infiltrarse en sistemas corporativos y robar información sensible. Los datos robados se utilizaban luego para presionar a las víctimas a pagar rescates, amenazando con publicar la información en línea. La banda también utilizaba inteligencia artificial para ayudar a desarrollar sus sistemas de ransomware e identificar posibles víctimas.
Suspect linked to Qilin ransomware gang reportedly extradited to Germany
- Jurisdicción
- Japan, Germany
- Actor de amenazas
- Ransomware group
- Incriminated Activity
- Ataque de ransomware
- Estimated Damage
- Major system outage of Asahi Group Holdings
- Enforcement Action
- Extradition to Germany
- Case Status
- Investigation pending
Japanese police have arrested a Russian national believed to be a key member of the international ransomware group Qilin and extradited him to Germany, according to local media.
Qilin is suspected of carrying out ransomware attacks on companies around the world, encrypting data and causing major damage. In 2025, the group claimed responsibility for a major system outage at Japanese food and beverage company Asahi Group Holdings.
Las autoridades alemanas venían buscando al hombre ruso por su presunta implicación en un ataque de ransomware contra una empresa alemana. Tras enterarse de que se encontraba en Japón, las autoridades japonesas lo localizaron y lo detuvieron antes de entregarlo a Alemania a petición de las autoridades alemanas.
A former CIA officer pleads guilty to a $193M fraud scheme
- Jurisdicción
- Estados Unidos
- Actor de amenazas
- Individual
- Incriminated Activity
- Financial fraud
- Estimated Damage
- $193.6 million
- Enforcement Action
- Arresto
- Case Status
- Judicial proceedings
El exagente de la CIA David J. Rush se ha declarado culpable de robar casi 194 millones de dólares al Gobierno de EE. UU. a través de un falso programa de inteligencia de alto secreto.
According to media reports, Rush had worked since 2010 in a CIA division responsible for developing hacking tools and techniques used in espionage operations. Court filings say that Rush held significant authority over government intelligence programs and related spending.
Prosecutors said Rush used his position and security clearance to create a fraudulent special access program and direct government money to himself. He had reportedly lied about parts of his education and military background to help secure his position at the CIA.
The FBI searched Rush’s Virginia home in May 2026 and found 298 gold bars worth about $46 million, more than $2.1 million in cash, euros, luxury watches and other valuables. Prosecutors said Rush also used the stolen money to buy luxury properties, cars and watches.
In total, Rush fraudulently obtained about $193.6 million in government funds. Under his plea agreement, he will forfeit the gold, cash, properties, watches and two luxury BMW vehicles.
Rush is scheduled to be sentenced on January 28, 2027. He faces up to 20 years in prison, along with fines, restitution and forfeiture.
Aviso legal: La información de este blog procede de fuentes públicas y gubernamentales. Recordamos respetuosamente a nuestros lectores la presunción de inocencia. La información aquí contenida se proporciona únicamente con fines educativos y no constituye una opinión ni un asesoramiento jurídico.
N.º 192 | Octubre de 2026, semana 1