Ukrainian cyberpolice, in cooperation with U.S. law enforcement, has identified an 18-year-old from Odesa suspected of operating an infostealer malware campaign that compromised 28,000 accounts belonging to customers of a California online store. The attacker harvested browser session tokens and credentials between 2024 and 2025, using 5,800 of the stolen accounts to make unauthorized purchases totaling $721,000 and causing $250,000 in direct losses. Stolen data was processed and sold via Telegram bots and specialized online resources. Authorities conducted searches, seized devices and digital evidence, but no arrest has been announced yet.
Table of contents
Related Articles:128 Impressions