Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Man Linked to Phobos Ransomware Arrested in Poland

Polish police said they found evidence of cybercrime on the 47-year-old suspect’s devices.

Hacker arrested

A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation.

According to Poland’s Central Cybercrime Bureau, officers found hacking tools, credentials, payment card numbers, and server IP addresses on the unnamed suspect’s devices during a search. 

They also discovered that the suspect had exchanged messages with the Phobos ransomware group.

While authorities have not shared details about his potential role in the Phobos operation, the brief description from the Central Cybercrime Bureau suggests he may have been an affiliate rather than an operator.

The Phobos ransomware-as-a-service operation emerged in 2019. In early 2024, the US government warned critical infrastructure organizations about attacks.

The United States and Europe have since announced taking significant action against the Phobos operation.

Advertisement. Scroll to continue reading.

The international law enforcement operation involved infrastructure takedowns and the arrests of several Russian nationals believed to have been key members and affiliates of the cybercrime gang. 

One suspect, accused of selling, distributing, and operating the Phobos ransomware, was extradited from South Korea to the US in late 2024. 

According to authorities, more than 1,000 organizations around the world have been targeted in Phobos ransomware attacks and the cybercriminals are believed to have obtained over $16 million in ransom payments.

Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US

Related: US Charges 31 More Defendants in Massive ATM Hacking Probe

Related: Jordanian Admits in US Court to Selling Access to 50 Enterprise Networks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.