Cybercrime

Algerian Man Extradited to US for Running Cybercrime Marketplaces

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Hacker arrested

Abdellah Belmili, a 26-year-old Algerian national, was recently arrested in Spain and extradited to the United States, where he faces up to 30 years in prison for allegedly running two cybercrime marketplaces.

According to the US Justice Department, Belmili, also known as Dila Belmili and Spox, was the administrator of a cybercrime marketplace called Market0Day between September and December 2020. 

Authorities said Spox was known for developing phishing kits targeting major American financial institutions.

The US investigators who targeted the Market0Day website successfully purchased a JPMorgan Chase phishing kit and access to a compromised email server in December 2020. 

Shortly after, Spox announced that he was no longer the administrator of Market0Day and instead had created a new marketplace named Spoxy, where cybercriminals could acquire ‘bulk SMS’ services, which enabled them to conduct mass phishing and other campaigns through text messages. 

“During the course of the conspiracy, Belmili is accused of defrauding multiple institutions, including American Express, Bank of America, JPMorgan Chase, and Wells Fargo, as well as financial institutions in the United Kingdom,” the Justice Department said. 

Advertisement. Scroll to continue reading.

It added, “Between January 2020 and January 2023, approximately $900,000 was deposited into an account controlled by Belmili. The investigation has also identified approximately 5,600 U.S. and international victims.”

Belmili is in custody after being charged with conspiracy to commit bank fraud.

While the crimes allegedly committed by the Algerian national took place several years ago, the US has recently shown that it will prosecute cybercriminals long after their crimes. A Romanian man was recently extradited to the United States for his alleged role in a hacking scheme dating back 17 years.

Related: Russian Initial Access Broker Behind FortiBleed Campaign

Related: Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

Related: Dutch Police Dismantle Massive 17-Million-Device Botnet

Related Content

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. 

Hacker Conversations

Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks.

Cybercrime

Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).

Cybercrime

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version