NEWS

Suspect Arrested in $4.5M Cryptojacking Scheme

A 35-year-old suspect has been apprehended in connection with a sophisticated cryptojacking scheme that siphoned $4.5 million from an international hosting company. The operation, which began in 2018, compromised over 5,000 customer accounts by turning their servers into illicit crypto farms.

By
LNGFRM Team
Published June 6, 2025
"Abstract illustration of a blue rectangular device with an antenna, surrounded by a yellow and grey explosion, with zigzag lines extending to four dark grey rings resembling handcuffs, all on a textured yellow background."
Illustration by Addison Smith for LNGFRM

In a stark reminder of the shadowy battles being waged in the digital realm, authorities have apprehended a 35-year-old individual linked to a sophisticated cryptojacking operation that siphoned an estimated $4.5 million from an international hosting company.

The arrest, a culmination of meticulous investigative work across international borders, peels back the curtain on an insidious form of cybercrime that is rapidly displacing more overt threats like ransomware.

This was no smash-and-grab.

The perpetrator, whose identity remains undisclosed, orchestrated a long game.

For years, since at least 2018, he systematically gathered data from public sources, meticulously mapping out the hosting company’s security vulnerabilities.

This intelligence-gathering phase, often overlooked in the drama of a breach, speaks volumes about the patience and strategic foresight of modern cybercriminals.

Once armed with this knowledge, the hacker moved in, compromising over 5,000 customer accounts – a staggering digital footprint that underscores the scale of the infiltration.

The method was equally sophisticated: rather than simply stealing data or holding systems hostage, the attacker deployed virtual machines within the compromised infrastructure.

These digital constructs were then repurposed to mine cryptocurrency, effectively turning the hosting company’s powerful servers into an illicit crypto farm.

The $4.5 million loss isn’t just about stolen digital assets; it represents the colossal computing power diverted, the bandwidth consumed, and the operational strain placed on the unwitting victim.

It is a silent, insidious form of theft, where the victim’s own resources are weaponized against them.

The unraveling of this elaborate scheme was a testament to international collaboration.

Law enforcement agencies, including Ukraine’s Zaporizhia regional cyber police, worked in tandem with international partners like Europol, tracking the digital breadcrumbs left by the elusive suspect.

It was a complex chase, with the hacker reportedly operating primarily from Poltava but frequently moving across various Ukrainian regions in an attempt to evade detection.

Such mobility highlights the fluid nature of cybercrime, where physical borders are often irrelevant to the digital movements of perpetrators.

When the net finally closed, police raids yielded a trove of evidence: computer equipment, mobile devices, bank cards, and perhaps most crucially, digital evidence including login credentials, crypto wallets containing the illicitly mined assets, and specialized software designed to automate and manage the cryptojacking operations.

This cache paints a picture of a professional, dedicated cybercriminal, equipped with the tools and knowledge to exploit the very fabric of the internet for personal gain.

The unnamed suspect now faces charges under Ukrainian law for unauthorized interference with computer systems, a serious offense punishable by up to 15 years in prison.

Yet, as the legal process unfolds, questions linger.

What is the true financial impact on the hosting company’s customers?

Will the stolen cryptocurrency ever be recovered?

And perhaps most importantly, are there accomplices still operating in the shadows?

The ongoing investigation suggests authorities are probing for a wider network, hinting that this individual might be part of a larger, more organized criminal enterprise.

This incident, while significant on its own, is far from isolated.

It serves as a stark illustration of a rapidly escalating global trend.

According to McAfee, undetected cryptojacking attacks surged by a staggering 60 percent in 2024, reflecting an almost 400 percent rise in attempts over the past year.

This isn’t just a corporate problem; critical sectors are bearing the brunt.

Healthcare organizations suffered an almost 700 percent increase in these attacks, while educational institutions faced an even more alarming spike, enduring 320 times more attacks than the previous year.

The shift is palpable: cybercriminals are increasingly pivoting from traditional ransomware, which often brings immediate and noticeable disruption, to the more covert cryptojacking.

The appeal is clear – it’s a stealthier, less detectable way to monetize illicit access.

Instead of demanding a ransom for encrypted files, they quietly hijack processing power, turning victims into unwitting participants in their crypto-mining schemes.

This makes it harder for organizations to detect and respond, allowing the theft to continue for extended periods.

The broader landscape of crypto-related exploits paints an even bleaker picture.

In 2024 alone, hackers pilfered an astonishing $2.2 billion through such exploits, marking a 17 percent increase from 2023.

The sheer number of individual incidents also climbed, from 282 in 2023 to 303 in 2024.

These figures are not mere statistics; they represent a tangible erosion of trust, a direct financial drain, and a constant threat to the digital infrastructure that underpins our modern world.

The arrest of this 35-year-old cryptojacker is a victory for law enforcement, a testament to their growing prowess in tackling the digital underworld.

But it is also a sober warning.

As our lives become ever more intertwined with cloud computing and digital currencies, the vulnerabilities grow, and the incentives for cybercriminals multiply.

This incident is a harsh reminder that the battle for digital security is a continuous, evolving struggle, demanding constant vigilance and ever-more sophisticated defenses from companies and individuals alike.

The silent thief of cryptojacking is no longer lurking in the shadows; it is a clear and present danger.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.