Saturday, March 15, 2025
HomeCyber Security NewsUkraine Authorities Arrested Cybercriminal Gang That Has Stolen Over 100 Million

Ukraine Authorities Arrested Cybercriminal Gang That Has Stolen Over 100 Million

Published on

SIEM as a Service

Follow Us on Google News

The Cyber ​​police exposed a criminal group stealing 100 million hryvnias from Ukrainians under the guise of social security payments from the European Union.

According to the cyber police of Ukraine, the criminals created more than 400 phishing links to acquire the bank card data of citizens and appropriate money from their accounts. As a consequence, the criminal may face up to 15 years behind bars for what they have committed.

A dedicated cybercrime unit within the Ministry of Internal Affairs operating with police based in central Kyiv and specialists from the National Bank of Ukraine (NBU) worked to arrest nine individuals.

Phishing Links Used to Obtain Bank Data

For obtaining the banking data of citizens, the nine individuals created and administered more than 400 fake web resources. Through the websites, Ukrainians were offered to form an application for the payment of financial assistance from the countries of the European Union.

Unknowingly, by using phishing links victims took surveys and entered their bank card details. Having received bank data, the attackers carried out unauthorized intervention in online banking and withdrew money from citizens’ accounts.

According to the NBU, “Criminals defrauded more than 5,000 citizens. The total amount of damages reaches more than 100 million hryvnias”.

Phishing web source used by the gang

The police searched the home of the suspects and seized computer equipment, mobile phones, bank cards, and money obtained through the illicit activities. The police also released a video during their raid on a suspect’s home.

Authorities Arrested the Cybercriminal Gang

The reports state that the perpetrators may face up to fifteen years in prison for multiple violations of Ukraine’s Criminal Code.

“Criminal proceedings have been opened under Part 3 of Art. 190 (Fraud), Part 5 of Art. 361 (Unauthorized interference in the work of information (automated), electronic communication, information and communication systems, electronic communication networks) of the Criminal Code of Ukraine”. “The issue of declaring suspicion and choosing precautionary measures for the persons involved are being resolved”, reads the advisory.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hackers Exploiting Exposed Jupyter Notebooks to Deploy Cryptominers

Cado Security Labs has identified a sophisticated cryptomining campaign exploiting misconfigured Jupyter Notebooks, targeting...

AWS SNS Exploited for Data Exfiltration and Phishing Attacks

Amazon Web Services' Simple Notification Service (AWS SNS) is a versatile cloud-based pub/sub service...

Edimax Camera RCE Vulnerability Exploited to Spread Mirai Malware

A recent alert from the Akamai Security Intelligence and Response Team (SIRT) has highlighted...

Cisco Warns of Critical IOS XR Vulnerability Enabling DoS Attacks

Cisco has issued a security advisory warning of a vulnerability in its IOS XR...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Hackers Exploiting Exposed Jupyter Notebooks to Deploy Cryptominers

Cado Security Labs has identified a sophisticated cryptomining campaign exploiting misconfigured Jupyter Notebooks, targeting...

AWS SNS Exploited for Data Exfiltration and Phishing Attacks

Amazon Web Services' Simple Notification Service (AWS SNS) is a versatile cloud-based pub/sub service...

Edimax Camera RCE Vulnerability Exploited to Spread Mirai Malware

A recent alert from the Akamai Security Intelligence and Response Team (SIRT) has highlighted...