Cybercrime

Man Linked to Phobos Ransomware Arrested in Poland

Polish police said they found evidence of cybercrime on the 47-year-old suspect’s devices.

Hacker arrested

A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation.

According to Poland’s Central Cybercrime Bureau, officers found hacking tools, credentials, payment card numbers, and server IP addresses on the unnamed suspect’s devices during a search. 

They also discovered that the suspect had exchanged messages with the Phobos ransomware group.

While authorities have not shared details about his potential role in the Phobos operation, the brief description from the Central Cybercrime Bureau suggests he may have been an affiliate rather than an operator.

The Phobos ransomware-as-a-service operation emerged in 2019. In early 2024, the US government warned critical infrastructure organizations about attacks.

The United States and Europe have since announced taking significant action against the Phobos operation.

Advertisement. Scroll to continue reading.

The international law enforcement operation involved infrastructure takedowns and the arrests of several Russian nationals believed to have been key members and affiliates of the cybercrime gang. 

One suspect, accused of selling, distributing, and operating the Phobos ransomware, was extradited from South Korea to the US in late 2024. 

According to authorities, more than 1,000 organizations around the world have been targeted in Phobos ransomware attacks and the cybercriminals are believed to have obtained over $16 million in ransom payments.

Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US

Related: US Charges 31 More Defendants in Massive ATM Hacking Probe

Related: Jordanian Admits in US Court to Selling Access to 50 Enterprise Networks

Related Content

Cybercrime

Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Data Breaches

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

Data Breaches

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

Ransomware

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

Cybercrime

Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version