Polish authorities arrest alleged Phobos ransomware affiliate
Full article606 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The 47-year-old man, who was not identified, faces up to five years in prison for producing, obtaining and sharing computer programs used to conduct cyberattacks.
Listen to this article
0:00
Learn more.
Polish officials arrested a 47-year-old man accused of participating in ransomware attacks as an affiliate for the Phobos ransomware group, the country’s Central Bureau for Combating Cybercrime said Tuesday.
Authorities did not name the man who was arrested during a raid on his apartment in the Małopolskie province, but said he faces up to five years in prison for his alleged crimes.
The arrest is the latest in a series of coordinated law enforcement actions targeting people involved with Phobos ransomware attacks, which were also carried out by the 8base ransomware group. Polish officials said they identified the suspect through the “Phobos Aetor” operation, a Europol-led effort involving agencies across Europe, Asia and North America that took place in February 2025.
Officials accused the 47-year-old man of possessing credentials, credit card numbers and IP addresses for servers that may have been used to conduct various attacks. He also had tools that could breach servers and used encrypted messaging platforms to communicate with others linked to Phobos, police said.
During the raid, police said they seized a computer and multiple mobile phones that were used to commit cyberattacks. The unnamed suspect was charged with producing, obtaining and sharing computer programs used to illegally obtain information stored on IT systems.
Phobos ransomware had claimed more than 1,000 victims globally and received more than $16 million in extortion payments by February 2025, according to the Justice Department. Victims of Phobos ransomware attacks, which date back to at least November 2020, include hospitals, schools, non-profit organizations, and a company that contracted with the Defense Department, officials said.
Malicious activity linked to Phobos significantly declined when Russian national Evgenii Ptitsyn, the alleged developer and administrator of Phobos ransomware, was extradited from South Korea to the United States in November 2024.
Ptitsyn, also known as “derxan” and “zimmermanx,” was charged with multiple counts of cybercrime, including wire fraud, wire fraud conspiracy, conspiracy to commit computer fraud and abuse, extortion in relation to hacking and causing intentional damage to protected computers.
Pretrial motions for his case are due this week in the U.S. District Court of Maryland.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/phobos-ransomware-affiliate-arrested-poland/