Para garantizar la mejor experiencia de navegación, active JavaScript en su navegador web. Sin él, muchas funciones del sitio web no estarán disponibles.


Total de pruebas:
485,773,462
737,046
130,956

Issue #193 | October 2026, Week 2

8 de octubre de 2026

Five cases this week: MonsterCloud LLC owner accused of cooperation with ransomware gangs, KillSec cybercriminal gang dismantled, Qilin member extradited to Germany, Former CIA officer pleads guilty to financial fraud scheme.

Vistas: 1k Tiempo de lectura:5 min.

Issue #193 | October 2026, Week 2

Ransomware recovery company owner charged with fraud for secretly paying cybercriminals

Jurisdicción
Estados Unidos
Actor de amenazas
Individual
Incriminated Activity
Wire fraud
Estimated Damage
$11 million
Enforcement Action
Arresto
Case Status
Investigation pending

El propietario de una empresa de recuperación de ransomware ha sido acusado de supuestamente estafar a las víctimas pagando en secreto a ciberdelincuentes por claves de descifrado, mientras afirmaba que su empresa poseía tecnología propia para recuperar archivos cifrados.

La fiscalía afirma que Zohar Pinhasi, de 50 años, también conocido como «Zack Silver» y «Zack Green», era propietario de MonsterCloud LLC, una empresa con sede en Florida que ayudaba a las empresas a recuperarse de ataques de ransomware. La empresa afirmaba poder restaurar datos cifrados sin pagar a los hackers. Sin embargo, la fiscalía alega que Pinhasi y sus socios contactaban frecuentemente a grupos de ransomware, pagaban por claves de descifrado y utilizaban dichas claves para recuperar los archivos de los clientes.

In one case, Pinhasi allegedly paid a ransomware group about $8,200 but charged the victim around $150,000. In another case, prosecutors say he paid about $236,000 and charged the customer roughly $380,000.

The indictment says MonsterCloud also used recovered sample files to convince customers that it could decrypt their data, even when the files had been decrypted using keys obtained from attackers.

Over the five-year period from June 2018 to June 2023, Pinhasi and his co-conspirators allegedly helped facilitate more than $8 million in ransom payments and charged more than $19 million for recovery services.

Pinhasi faces one count of conspiracy to commit wire fraud and two counts of wire fraud. If convicted, he could face up to 20 years in prison.

Former engineer gets nearly 3 years for a ransomware attack against his employer

Jurisdicción
Estados Unidos
Actor de amenazas
Individual
Incriminated Activity
Ransomware-style attack
Estimated Damage
Thousands of devices disrupted
Enforcement Action
32-month prison sentence
Case Status
Court judgement

A former infrastructure engineer has been sentenced to 32 months in prison for carrying out a ransomware-style attack against his former employer, locking thousands of devices and demanding a $750,000 ransom.

Daniel Rhyne, 57, of Kansas City, Missouri, pleaded guilty to the attack on the New Jersey-based industrial company where he previously worked. He was arrested in August 2024.

According to court documents, Rhyne accessed the company's network using an administrator account. He changed passwords, deleted administrator accounts, and blocked access to hundreds of servers and thousands of workstations.

Rhyne also shut down servers and workstations and sent employees an email claiming the company's backups had been deleted and demanding 20 bitcoin (worth about $750,000 at the time). He threatened to shut down 40 servers each day unless the ransom was paid.

La investigación reveló que Rhyne había buscado en línea cómo cambiar contraseñas de administrador, eliminar cuentas de red, borrar registros de Windows y apagar computadoras de forma remota.

Rhyne didn’t receive any ransom, but the attack caused major disruption to the company's network, leaving employees unable to access many systems.

La policía apunta a la banda de ransomware KillSec y detiene a un presunto líder

Jurisdicción
International (10 countries)
Actor de amenazas
Ransomware group
Incriminated Activity
Ransomware extortion
Estimated Damage
110 TB of stolen data
Enforcement Action
Three arrests, infrastructure seizure
Case Status
Investigation pending

An international law enforcement operation has disrupted the KillSec ransomware group, with authorities seizing its data leak site and servers and arresting three suspects.

The operation, called “Operation KillSwitch,” took place on September 30 and involved authorities from 10 countries, including Germany, the United States, Belgium, Finland, Greece, the Netherlands, Romania, Spain, Switzerland, and the United Kingdom.

La policía identificó a un joven de 16 años como el presunto operador principal de KillSec. Otro presunto miembro, descrito como desarrollador, cumplió 18 años en agosto de 2026, pero era menor de edad cuando se cometieron algunos de los presuntos delitos. Las autoridades también han identificado a presuntos miembros implicados en negociaciones y operaciones de afiliados. La policía registró ocho propiedades en Grecia, Rumanía, España y el Reino Unido. Las autoridades también desactivaron cinco servidores vinculados al grupo y se incautaron de al menos 110 terabytes de datos robados.

US authorities have charged a KillSec member, identified as Fouad Eltibrizi (aka Archduke), with unauthorized access to a computer system, causing damage to a computer, and extortion. Eltibrizi, a Dutch national, was arrested on September 30, 2026, in the UK.

Authorities believe KillSec carried out around 1,000 suspected attacks worldwide, with about 500 considered successful so far. At least 70 attacks targeted organizations in Germany.

KillSec lleva en activo desde aproximadamente 2024. Al parecer, el grupo explotaba vulnerabilidades de software y sistemas mal protegidos para infiltrarse en sistemas corporativos y robar información sensible. Los datos robados se utilizaban luego para presionar a las víctimas a pagar rescates, amenazando con publicar la información en línea. La banda también utilizaba inteligencia artificial para ayudar a desarrollar sus sistemas de ransomware e identificar posibles víctimas.

Boletín informativo de ImmuniWeb
Sé el primero en recibir el último número de Cybercrime Weekly en tu bandeja de entrada
Únete a más de 50.000 profesionales de ciberseguridad, informática forense, fuerzas del orden y derecho

Privado y confidencialSus datos permanecerán privados y confidenciales.

Suspect linked to Qilin ransomware gang reportedly extradited to Germany

Jurisdicción
Japan, Germany
Actor de amenazas
Ransomware group
Incriminated Activity
Ataque de ransomware
Estimated Damage
Major system outage of Asahi Group Holdings
Enforcement Action
Extradition to Germany
Case Status
Investigation pending

Japanese police have arrested a Russian national believed to be a key member of the international ransomware group Qilin and extradited him to Germany, according to local media.

Qilin is suspected of carrying out ransomware attacks on companies around the world, encrypting data and causing major damage. In 2025, the group claimed responsibility for a major system outage at Japanese food and beverage company Asahi Group Holdings.

Las autoridades alemanas venían buscando al hombre ruso por su presunta implicación en un ataque de ransomware contra una empresa alemana. Tras enterarse de que se encontraba en Japón, las autoridades japonesas lo localizaron y lo detuvieron antes de entregarlo a Alemania a petición de las autoridades alemanas.

A former CIA officer pleads guilty to a $193M fraud scheme

Jurisdicción
Estados Unidos
Actor de amenazas
Individual
Incriminated Activity
Financial fraud
Estimated Damage
$193.6 million
Enforcement Action
Arresto
Case Status
Judicial proceedings

El exagente de la CIA David J. Rush se ha declarado culpable de robar casi 194 millones de dólares al Gobierno de EE. UU. a través de un falso programa de inteligencia de alto secreto.

According to media reports, Rush had worked since 2010 in a CIA division responsible for developing hacking tools and techniques used in espionage operations. Court filings say that Rush held significant authority over government intelligence programs and related spending.

Prosecutors said Rush used his position and security clearance to create a fraudulent special access program and direct government money to himself. He had reportedly lied about parts of his education and military background to help secure his position at the CIA.

The FBI searched Rush’s Virginia home in May 2026 and found 298 gold bars worth about $46 million, more than $2.1 million in cash, euros, luxury watches and other valuables. Prosecutors said Rush also used the stolen money to buy luxury properties, cars and watches.

In total, Rush fraudulently obtained about $193.6 million in government funds. Under his plea agreement, he will forfeit the gold, cash, properties, watches and two luxury BMW vehicles.

Rush is scheduled to be sentenced on January 28, 2027. He faces up to 20 years in prison, along with fines, restitution and forfeiture.


Aviso legal: La información de este blog procede de fuentes públicas y gubernamentales. Recordamos respetuosamente a nuestros lectores la presunción de inocencia. La información aquí contenida se proporciona únicamente con fines educativos y no constituye una opinión ni un asesoramiento jurídico.

Etiquetas:Aplicación de la ley Cybercrime Hacking Ransomware Fraude Fraude en línea Fuga de datos Arresto Incautación de activos Convicción penal Cargos penales Investigation Operación conjunta
Hable con un experto