Cybercrime

US Charges Genesis Market User

A Michigan man has been charged for buying compromised credentials on Genesis Market and using and selling them.

A Michigan man has been charged for buying compromised credentials on Genesis Market and using and selling them.

The US Justice Department last week announced charges against a man accused of buying credentials from the Genesis Market cybercrime marketplace, as well as using and selling those credentials.

The suspect is 29-year-old Andrew Shenkosky from Michigan. According to authorities, the man, who had resided in Minnesota when he conducted the scheme back in 2020, purchased roughly 2,500 stolen login credentials from Genesis Market.

In at least one case Shenkosky allegedly used the credentials to steal money from a bank account, transferring the funds to a PayPal account he controlled. He also attempted to sell some of the stolen account data on RaidForums, a cybercrime marketplace dismantled in an international law enforcement operation in 2022. 

The man has been charged with wire fraud, aggravated identity theft, possession of unauthorized access devices, and trafficking computer access information. 

Shenkosky appeared before a judge earlier this month and his arraignment hearing is scheduled for this week. 

The Genesis Market website was targeted by law enforcement in April 2023, when the FBI announced seizing the surface web domain used by the site and the arrest of 120 individuals. 

Advertisement. Scroll to continue reading.

The marketplace had been around since 2018, offering cybercriminals access to bots that could be used to carry out malicious activities and bypass anti-fraud systems.

Administrators were apparently not arrested in the 2023 operation and they had attempted to keep the website online on the dark web after the takedown effort. There hasn’t been any news on Genesis Market since, which indicates that it was completely shut down at some point. 

Last year, the Justice Department announced charges against a Buffalo police detective who had allegedly bought stolen credentials from Genesis Market.

Related: Alabama Man Pleads Guilty to Hacking SEC’s X Account

Related: Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines

Related: Mining Company NioCorp Loses $500,000 in BEC Hack

Related: 127 Servers of Bulletproof Hosting Service Zservers Seized by Dutch Police

Related Content

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Cyberwarfare

The 17 members of the Mabna Institute targeted hundreds of universities and organizations in the US and abroad.

Malware & Threats

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.

Cybercrime

The suspects and their companies were previously sanctioned by the United States and its allies.

Cybercrime

Hundreds of C&C servers were disrupted in an operation involving law enforcement and several cybersecurity companies.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Malware & Threats

Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version