This last week saw multiple operations to disrupt cybercrime gangs run by Russians. With multiple sites taken down, hardware seized, and arrests made, it will be seen as being successful. It is a significant ramping up by national law enforcement agencies around the world.
However, the end of the week was overshadowed by the news that the US had fired around 5% of the staff at the Cybersecurity and Infrastructure Security Agency. Those staff were fired as part of a cost-cutting exercise at the parent agency, the Department for Homeland Security.
With increased attacks on the USA by cybercriminals and recent actions to disrupt cybercrime gangs, there is concern that this will weaken efforts to protect US organisations.
In other news, JumpCloud has launched its latest SaaS management solution, which it claims will eliminate the threat of shadow IT. The new solution provides visibility, control, and automation tools to allow IT teams to discover and secure SaaS usage across the organisation.
The Amsterdam Police Cybercrime Team have taken down bulletproof hosting (BPH) provider ZServers/XHost (in Dutch). The hosting provider advertised that customers would be anonymous, could use the servers for anything, and that all payments would be in cryptocurrency.
iProov claims that a recent study shows that only 0.1% of people are able to identify AI-generated deepfakes. The study, which the company has chosen to keep private, exposed 2,000 people to content, including images and video. Participants were asked to detect true from false, making that detection rate staggeringly low.
NVISIONx has launched Nx+RexAI to improve Data Security Posture Management (DSPM). It claims the new solution will “tackle the evolving challenges of data governance, regulatory compliance, and data security.” It is free for existing customers until June 2025.
ENCS
The ENCS has posted a list of all the main publications on security requirements, position papers, and best practices that it produced in 2024. It includes policy, architecture and operations programs. Among those of interest are those on tabletop exercises, AI and cybersecurity in power grids, and the security of EV charging grids.
Europol
Law enforcement in multiple countries took action against the 8base and Phobos ransomware groups. It led to the arrest of four individuals, all Russian nationals, who are accused of deploying 8base ransomware. It also resulted in the seizure of 27 servers.
Intelligence gathered through the raid led to 400 companies being warned that they had been compromised or were at risk of an imminent attack.
noyb
noyb has brought a case against the German online weather app WetterOnline. The app has been gathering and selling precise location data of users without telling them. The case came after netzpolitik.org published research into smartphone apps and how they misused data.
As part of that, journalist Ingo Dachwitz submitted an access request to WetterOnline. It was rejected because “extracting and compiling all this data would require considerable technical, personnel and financial resources”. That is not a defence under the GDPR and shows that the company is unwilling to provide users with the data it has gathered on them.
Martin Baumann, data protection lawyer at noyb: “The GDPR makes it clear that data subjects have the right to a copy of their data processed by a company. There is simply no exception for an allegedly ‘disproportionate effort’. WetterOnline must comply with EU law just like all other companies.”
US Department of Justice
The Justice Department today unsealed criminal charges against two Russian nationals, Roman Berezhnoy and Egor Nikolaevich Glebov. They are alleged to have operated the Phobos ransomware, which victimized more than 1,000 organisations and is reported to have made over $16 million in ransom payments. Both were arrested this week as part of an operation to take down 8base, Affiliate 2803, and Phobos.

















