Polish police detain alleged cybercriminal with Phobos ransomware ties
嗯,用户让我用中文帮他总结一下这篇文章的内容,控制在一百个字以内。首先,我需要通读整篇文章,抓住主要信息。 文章讲的是一个47岁的男子在波兰被逮捕,涉嫌参与Phobos勒索软件活动。波兰的网络犯罪中心协调了这次逮捕行动,涉及多个城市的警察。他们在嫌疑人的电脑里发现了加密的信息,指向Phobos团伙。这个团伙攻击了全球超过1000个组织,包括医院、学校和政府机构。美国检察官提到他们从受害者那里获得了超过1600万美元的赎金。最近的行动包括逮捕Ptitsyn和其他成员,并查封了大量服务器。 现在我要把这些信息浓缩到100字以内。重点包括:波兰逮捕47岁男子,参与Phobos勒索软件;该团伙攻击全球1000多个组织;赎金高达1600万美元;国际执法合作打击该团伙。 确保语言简洁明了,不使用复杂的结构。检查字数是否符合要求。 </think> 一名47岁男子在波兰被捕,涉嫌参与Phobos勒索软件活动。该团伙曾攻击全球超1000个组织,赎金总额达1600万美元。国际执法机构已逮捕多名成员并查封相关服务器。 2026-2-17 19:45:46 Author: therecord.media(查看原文) 阅读量:1 收藏

A 47-year-old man was arrested in Poland for his alleged involvement with the Phobos ransomware operation. 

Poland’s Central Bureau for Combating Cybercrime said the man was detained in the southern Małopolska region of the country in an operation coordinated by police in the cities of Katowice and Kielce. 

The man, who was not named, is now facing a prison sentence of up to five years for his involvement in cybercrime. 

During the raid, officers searched the man’s computer and found encrypted messages with members of the Phobos group — a focus of Europol’s Operation Aether. 

Polish police officials said the regional operation has involved the arrest of both back-end developers of the Phobos ransomware as well as operators and affiliates who conducted the attacks and encrypted victim systems. 

Phobos was a ransomware gang that attacked more than 1,000 organizations worldwide, targeting hospitals, schools, government agencies and more. U.S. prosecutors previously said operators of Phobos and a related strain called 8Base collected upwards of $16 million from victims worldwide dating back to 2019.

U.S. authorities warned in February 2024 that Phobos attacks were impacting state, local, tribal and territorial governments — damaging “municipal and county governments, emergency services, education, public healthcare, and other critical infrastructure entities to successfully ransom several million U.S. dollars.”

The spinoff operation named 8Base ramped up its activity in the summer of 2023 and the group claimed responsibility for high-profile attacks on the United Nations Development Programme and the Atlantic States Marine Fisheries Commission as well as a Canadian agency that administers dental benefit plans for disabled people in Alberta.

Phobos is known for accepting significantly smaller ransoms from attacks than other groups, including several under $100,000.

“Key elements of this pressure included the extradition of the alleged Phobos administrator to the US and coordinated arrests in Europe and beyond, combined with technical measures targeting the cybercriminal infrastructure,” Polish officials said in a statement, referencing arrested Russian national Evgenii Ptitsyn

Ptitsyn was extradited to the U.S. from South Korea in 2024 and multiple other members of Phobos are now facing charges

As part of Operation Aether, two men and two women were arrested after raids in Phuket, Thailand. The FBI, alongside law enforcement agencies in Germany, Japan and more, took down more than 100 servers used as part of the Phobos scheme and warned more than 400 companies worldwide of ongoing or imminent ransomware attacks.

Following the Thai raids, the U.S. Department of Justice unsealed an array of criminal charges against Roman Berezhnoy, 33, and Egor Nikolaevich Glebov, 39, for their alleged roles in Phobos.

Last July, Japanese officials published a free Phobos ransomware decryption tool and a guide in English for organizations impacted by the group’s attacks.

The indictment of Ptitsyn revealed significant information about the group’s inner workings and victims, which include:

  • The California public school system, which paid the $300,000 ransom in the summer of 2023
  • A Maryland-based company that provided accounting and consulting services to federal agencies. It paid a $12,000 ransom in early 2021
  • A Pennsylvania healthcare organization that paid $20,000 in the spring of 2022
  • An Illinois-based contractor for the U.S. departments of Defense and Energy
  • Maryland healthcare organizations that paid ransoms of $25,000 and $37,000 in the summer of 2022
  • A New York-based law enforcement union and a federally recognized tribe in the summer of 2022
  • A Connecticut public school system in the summer of 2023, which did not pay a ransom
  • A North Carolina children’s hospital in the fall of 2023, which paid $100,000

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/poland-phobos-ransomware-arrest
如有侵权请联系:admin#unsafe.sh