Tuesday, March 4, 2025
Homecyber securityBuffalo Man Pleads Guilty To Buying Stolen Data From Genesis Market

Buffalo Man Pleads Guilty To Buying Stolen Data From Genesis Market

Published on

SIEM as a Service

Follow Us on Google News

Buffalo, N.Y. — U.S. Attorney Trini E. Ross announced today that Wul Isaac Chol, 27, of Buffalo, NY, pleaded guilty before the U.S.

District Judge John L. Sinatra, Jr. to possessing 15 or more unauthorized access devices intending to defraud.

The charge carries a maximum penalty of 10 years in prison and a fine of $250,000.

Details of the Case

Assistant U.S. Attorney Charles M. Kruly, who is handling the case, provided detailed insights into Genesis Market’s operations.

This online marketplace is notorious for compiling stolen data from malware-infected computers worldwide.

With ANYRUN You can Analyze any URL, Files & Email for Malicious Activity : Start your Analysis

The stolen data includes computer and mobile device identifiers, email addresses, usernames, and passwords, which are packaged and sold on the market.

Transactions on Genesis Market are conducted using virtual currencies, such as Bitcoin.

Chol’s Involvement

Between June 2019 and January 2021, Chol deposited approximately $105.08 worth of Bitcoin into a Genesis account he had created.

Using these funds, he purchased 21 packages of unauthorized access devices containing approximately 778 unauthorized access devices.

Furthermore, Chol admitted to obtaining $25,164.00 from the New York State Department of Labor without authorization.

Investigation and Sentencing

The plea results from an extensive investigation by the Federal Bureau of Investigation (FBI), under the direction of Special Agent-in-Charge Matthew Miraglia.

Sentencing for Chol is scheduled for September 13, 2024, before Judge Sinatra.

This case highlights the ongoing efforts of law enforcement agencies to combat cybercrime and the illegal trade of stolen data.

The guilty plea serves as a reminder of the severe consequences of such activities.

As the sentencing date approaches, the community will be watching closely to see what the outcome will be and what message it will send to potential cybercriminals.

Looking for Full Data Breach Protection? Try Cynet's All-in-One Cybersecurity Platform for MSPs: Try Free Demo 

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...