{"id":81071,"date":"2023-07-01T07:00:00","date_gmt":"2023-07-01T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=81071"},"modified":"2025-09-11T20:45:42","modified_gmt":"2025-09-11T17:45:42","slug":"prison-bitcoin-scheme-arrest-of-an-f-a-c-c-t-executive-and-other-cybersecurity-developments","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/prison-bitcoin-scheme-arrest-of-an-f-a-c-c-t-executive-and-other-cybersecurity-developments\/","title":{"rendered":"Prison Bitcoin scheme, arrest of an F.A.C.C.T. executive, and other cybersecurity developments"},"content":{"rendered":"<p>We have gathered the most important cybersecurity news of the week.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>The head of F.A.C.C.T.&#8217;s department was detained in Kazakhstan at the request of the United States and was arrested in absentia in Russia.<\/li>\n<li>The LockBit ransomware operators demanded $70 million from semiconductor maker TSMC.<\/li>\n<li>In Australia, an inmate ran a Bitcoin scheme worth $2 million.<\/li>\n<li>The FBI seized several BreachForums-linked domains.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>The head of F.A.C.C.T.&#8217;s department detained in Kazakhstan at the request of the United States and arrested in absentia in Russia<\/strong><\/h2>\n<p>On June 22, Kazakh authorities detained F.A.C.C.T.&#8217;s department head Nikita Kislytsin at the request of the United States; his colleagues said. <a href=\"https:\/\/www.facct.ru\/media-center\/press-releases\/zayavlenie-kompanii-otnositelno-zaderzhaniya-nikity-kislitsina\">stated<\/a> by his colleagues.<\/p>\n<p>Kislytsin will be held in custody during the period of examining grounds for extradition to the United States.<\/p>\n<p>The charges against him became known in 2020. At that time the U.S. Department of Justice <a href=\"https:\/\/cyberscoop.com\/group-ib-nikita-kislitsin-indicted-formspring-nikulin\/\">unsealed<\/a> a 2014 indictment outlining the alleged involvement of the Russian national in conspiring to sell login credentials stolen from the Formspring forum in 2012 (before he joined Group-IB).<\/p>\n<p>Separately on June 28, the Tverskoy Court of Moscow <a href=\"https:\/\/mos-gorsud.ru\/rs\/tverskoj\/services\/cases\/criminal-materials\/details\/9af67840-158d-11ee-a790-c31ea37fd320\">authorized<\/a> Kislytsin&#8217;s arrest in absentia in a case of illegal access to protected computer information. He was declared on the federal wanted list and intends to <a href=\"https:\/\/www.vedomosti.ru\/society\/news\/2023\/06\/28\/982749-glavu-departamenta-bivshei-group-ib-zaderzhali-v-kazahstane\">to seek extradition<\/a> to his homeland.<\/p>\n<p>Representatives of F.A.C.C.T. said that the charges against Kislytsin have no relation to the company itself and relate to his period as a journalist and cybersecurity researcher. They are sure there were no lawful grounds for detaining their colleague.<\/p>\n<h2 class=\"wp-block-heading\"><strong>LockBit ransomware operators demanded $70 million from semiconductor maker TSMC<\/strong><\/h2>\n<p>The operators of the LockBit ransomware claimed a successful breach of the world&#8217;s largest semiconductor maker, TSMC, and demanded a $70 million ransom. The company, however, denied the leak, according to <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/tsmc-denies-lockbit-hack-as-ransomware-gang-demands-70-million\/\">Bleeping Computer<\/a>.<\/p>\n<p>According to the initially published screenshots, the attackers gained access to a substantial amount of email addresses and credentials allegedly belonging to TSMC for various internal systems. Later this information was removed, and instead a ransom note appeared.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"977\" height=\"974\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/lockbit2.webp\" alt=\"lockbit2\" class=\"wp-image-210564\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/lockbit2.webp 977w, https:\/\/u1f987.com\/wp-content\/uploads\/lockbit2-300x300.webp 300w, https:\/\/u1f987.com\/wp-content\/uploads\/lockbit2-150x150.webp 150w, https:\/\/u1f987.com\/wp-content\/uploads\/lockbit2-768x766.webp 768w\" sizes=\"auto, (max-width: 977px) 100vw, 977px\" \/><figcaption class=\"wp-element-caption\">Data: LockBit leak site.<\/figcaption><\/figure>\n<p>As explained by a TSMC spokesperson, hackers breached one of their IT equipment suppliers, Kinmax Technology. As a result, information relating to system installation and server configuration was leaked. The company later also confirmed the incident.<\/p>\n<p>The attack did not affect TSMC&#8217;s business operations or the security of customer data.<\/p>\n<p>The investigation is ongoing with law enforcement involvement. During the proceedings, the semiconductor maker halted operations with the affected supplier.<\/p>\n<h2 class=\"wp-block-heading\"><strong>In Australia, an inmate carried out a Bitcoin scheme worth $2 million<\/strong><\/h2>\n<p>Ishan Sinar Sappidin, an inmate in Australia serving a 12-year sentence for organizing a financial pyramid scheme, persuaded at least six inmates to transfer over $2 million to accounts under his control, under the pretext of investments in Bitcoin, according to the Daily Mail.<\/p>\n<p>The events occurred between 2020 and 2022. Sappidin claimed to have extensive experience in the cryptocurrency market, allegedly working with Australian billionaire Mike Cannon-Brookes.<\/p>\n<p>Among the scammer&#8217;s victims was the well-known Australian rugby player Jarryd Hayne.<\/p>\n<p>Because inmates lacked internet access, they turned to third parties outside the prison to transfer funds to the scammer. Despite assurances of substantial profits, the victims never received any payouts.<\/p>\n<p>Authorities began an investigation into the case, and Sappidin was moved to a higher-security prison.<\/p>\n<h2 class=\"wp-block-heading\"><strong>The FBI seized several BreachForums-linked domains<\/strong><\/h2>\n<p>U.S. law enforcement gained control of BreachForums&#8217; backup domain on the clearnet three months after the arrest of its founder and administrator Conor Brian Fitzpatrick, known as Pompompurin. This is reported by <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-seizes-breachforums-after-arresting-its-owner-pompompurin-in-march\/\">Bleeping Computer<\/a>.<\/p>\n<p>Now the Breached.vc address displays a banner listing the agencies involved in the operation, along with a clenched-arms avatar of Pompompurin.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" loading=\"lazy\" decoding=\"\" width=\"1024\" height=\"574\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/2023-06-30-19.13.20-1024x574.jpg\" alt=\"2023-06-30-19.13.20\" class=\"wp-image-210563\" srcset=\"https:\/\/u1f987.com\/wp-content\/uploads\/2023-06-30-19.13.20-1024x574.jpg 1024w, https:\/\/u1f987.com\/wp-content\/uploads\/2023-06-30-19.13.20-300x168.jpg 300w, https:\/\/u1f987.com\/wp-content\/uploads\/2023-06-30-19.13.20-768x430.jpg 768w, https:\/\/u1f987.com\/wp-content\/uploads\/2023-06-30-19.13.20.jpg 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Data: Bleeping Computer.<\/figcaption><\/figure>\n<p>Additionally, the pompur[.]in domain, which belonged to Fitzpatrick personally, was confiscated, and the BreachForums site on the dark web now shows a 404 Not Found error.<\/p>\n<p>DNS servers of all seized domains have been changed to ns1.seizedservers.com and ns2.seizedservers.com, commonly used by authorities in such cases.<\/p>\n<p>The operation also affected one of the DataBreaches.net news site, which was used to post data leaks \u2014 Breaches.net. Media representatives have already contacted the FBI to challenge the domain seizure.<\/p>\n<h2 class=\"wp-block-heading\"><strong>\u201cTinkoff\u201d fined 70,000 rubles for data leak<\/strong><\/h2>\n<p>The Savyolovsky District Court of Moscow fined Tinkoff Bank 70,000 rubles for a data leak. <a href=\"https:\/\/ria.ru\/20230628\/tinkoff-1880916773.html\">RIA News<\/a> reports.<\/p>\n<p>The bank itself rejected claims of violations. Representatives said the court decision is connected to a technical error in servicing one of the bank&#8217;s clients.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Experts uncover a new Trojan from the Andariel hackers<\/strong><\/h2>\n<p>The Andariel subgroup of the Lazarus cybercrime group has begun using a new remote access Trojan, EarlyRat. This was reported by <span class=\"old_tooltip\" data-descr=\"\u0418\u0441\u0442\u043e\u0447\u043d\u0438\u043a: \u041b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u0438\u044f \u041a\u0430\u0441\u043f\u0435\u0440\u0441\u043a\u043e\u0433\u043e\">Kaspersky Lab<\/span>.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Beyond DTrack #malware &#038; Maui #ransomware: #Andariel expands its TTPs?<br \/>Log4j appeared to be the source of EarlyRat based on our initial investigations. However, while hunting for more samples, we found <a href=\"https:\/\/twitter.com\/hashtag\/phishing?src=hash&#038;ref_src=twsrc%5Etfw\">#phishing<\/a> docs that dropped <a href=\"https:\/\/twitter.com\/hashtag\/EarlyRat?src=hash&#038;ref_src=twsrc%5Etfw\">#EarlyRat<\/a>.<br \/>More details\u2b07\ufe0f<a href=\"https:\/\/t.co\/qVLbLway8f\">https:\/\/t.co\/qVLbLway8f<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/1674239907487727616?ref_src=twsrc%5Etfw\">June 29, 2023<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"\"UTF-8\"><\/script><\/p>\n<p>Initial infection occurs via the Log4j exploit, or through links in phishing documents.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/u1f987.com\/wp-content\/uploads\/image002-2.webp\" alt=\"image002-2\" class=\"wp-image-210562\"\/><figcaption class=\"wp-element-caption\">Example of a phishing document. Data: \u201cKaspersky Lab\u201d.<\/figcaption><\/figure>\n<p>After activation, EarlyRat collects system information and transmits it to its command-and-control server. The data include unique identifiers of infected machines and requests encrypted using them.<\/p>\n<p>The Trojan is simple and largely limited to executing commands.<\/p>\n<h2 class=\"wp-block-heading\"><strong>YouTube, as part of an experiment, began blocking playback for AdBlock users<\/strong><\/h2>\n<p>Reddit users reported a pop-up on YouTube alerting about restrictions in viewing videos when AdBlock is enabled.<\/p>\n<p>Platform representatives said to the press that these warnings are part of a &#8220;small experiment&#8221; to persuade viewers to allow ads or try a paid subscription.<\/p>\n<p>They added that in extreme cases, when users keep the blocker active, playback may be temporarily disabled.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>In Russia, <a href=\"https:\/\/u1f987.com\/en\/news\/in-russia-15000-asic-miners-were-hijacked-under-the-guise-of-an-offer-from-rushydro\">stole 15,000 ASIC miners<\/a> under the guise of an offer from \u201cRusHydro\u201d.<\/li>\n<li>A U.S. court <a href=\"https:\/\/u1f987.com\/en\/news\/u-s-court-orders-crypto-scammer-to-pay-more-than-50-million\">fined<\/a> a crypto scammer $50 million.<\/li>\n<li>Report: In 2022 Bitcoin&#8217;s share in illicit crypto operations was only <a href=\"https:\/\/u1f987.com\/en\/news\/report-bitcoin-accounted-for-just-19-of-illegal-crypto-activity-in-2022\">19%<\/a>.<\/li>\n<li>Israel confiscated <a href=\"https:\/\/u1f987.com\/en\/news\/israel-confiscates-millions-of-dollars-in-cryptocurrency-linked-to-terrorist-groups\">millions of dollars<\/a> in cryptocurrency linked to terrorists.<\/li>\n<li>The Supreme Court ruled Bitcoin-to-ruble conversions as <a href=\"https:\/\/u1f987.com\/en\/news\/supreme-court-rules-bitcoin-to-ruble-conversions-amount-to-money-laundering\">money laundering<\/a>.<\/li>\n<li>The Chibi Finance team on the Arbitrum network carried out <a href=\"https:\/\/u1f987.com\/en\/news\/chibi-finance-team-on-arbitrum-conducts-a-1-million-rug-pull\">a $1 million rug pull<\/a>.<\/li>\n<li>Sam Bankman-Fried <a href=\"https:\/\/u1f987.com\/en\/news\/sam-bankman-fried-spent-243-million-on-bahamian-villas\">spent $243 million<\/a> on Bahamas villas; the court <a href=\"https:\/\/u1f987.com\/en\/news\/judge-denies-motion-to-dismiss-most-charges-against-sbf\">denied the motion to dismiss most charges against the head of FTX<\/a>.<\/li>\n<li>Media: Swiss authorities froze Do Kwon&#8217;s <a href=\"https:\/\/u1f987.com\/en\/news\/media-swiss-authorities-freeze-do-kwons-crypto-assets-worth-26-million\">crypto assets for $26 million<\/a>.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>What to read this weekend?<\/strong><\/h2>\n<p>In a special feature we examine the thesis that some technologies are more conducive to tyranny than others.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have gathered the most important cybersecurity news of the week.<\/p>\n","protected":false},"author":1,"featured_media":81072,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-81071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"13","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/81071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=81071"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/81071\/revisions"}],"predecessor-version":[{"id":81073,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/81071\/revisions\/81073"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/81072"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=81071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=81071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=81071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}