Cybercrime

Algerian Man Extradited to US for Running Cybercrime Marketplaces

26-year-old Abdellah Belmili faces up to 30 years in prison for allegedly operating the marketplaces Market0Day and Spoxy.

Hacker arrested

Abdellah Belmili, a 26-year-old Algerian national, was recently arrested in Spain and extradited to the United States, where he faces up to 30 years in prison for allegedly running two cybercrime marketplaces.

According to the US Justice Department, Belmili, also known as Dila Belmili and Spox, was the administrator of a cybercrime marketplace called Market0Day between September and December 2020. 

Authorities said Spox was known for developing phishing kits targeting major American financial institutions.

The US investigators who targeted the Market0Day website successfully purchased a JPMorgan Chase phishing kit and access to a compromised email server in December 2020. 

Shortly after, Spox announced that he was no longer the administrator of Market0Day and instead had created a new marketplace named Spoxy, where cybercriminals could acquire ‘bulk SMS’ services, which enabled them to conduct mass phishing and other campaigns through text messages. 

“During the course of the conspiracy, Belmili is accused of defrauding multiple institutions, including American Express, Bank of America, JPMorgan Chase, and Wells Fargo, as well as financial institutions in the United Kingdom,” the Justice Department said. 

Advertisement. Scroll to continue reading.

It added, “Between January 2020 and January 2023, approximately $900,000 was deposited into an account controlled by Belmili. The investigation has also identified approximately 5,600 U.S. and international victims.”

Belmili is in custody after being charged with conspiracy to commit bank fraud.

While the crimes allegedly committed by the Algerian national took place several years ago, the US has recently shown that it will prosecute cybercriminals long after their crimes. A Romanian man was recently extradited to the United States for his alleged role in a hacking scheme dating back 17 years.

Related: Russian Initial Access Broker Behind FortiBleed Campaign

Related: Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

Related: Dutch Police Dismantle Massive 17-Million-Device Botnet

Related Content

Cybercrime

Using a custom sniffer, the threat actor has captured over 110 million credentials since at least February 2026.

Hacker Conversations

From building LED bulbs to graduating college and buying a house with money earned from bug bounties.

Cybercrime

Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang.

Cybercrime

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques.

Cybercrime

Relying on social engineering, the hacking group engages in credential phishing, malware distribution, and fraud activities.

Cybercrime

Law enforcement and tech companies disrupted infrastructure linked to scammers operating across Southeast Asia.

Cybercrime

Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.

Cybercrime

The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version