Briefing

Ukraine identifies infostealer operator tied to 28,000 stolen accounts

security
by Bill Toulas ·

Audit for stolen session tokens and enforce MFA to mitigate infostealer activity.

What to do now

Implement session token monitoring, enforce MFA, review account activity logs, and conduct a security audit.

Summary

The Ukrainian cyberpolice, in cooperation with U.S. law enforcement, identified an 18‑year‑old suspect from Odesa who ran an infostealer malware operation between 2024 and 2025, targeting users of a California online store. The malware stole browser sessions and account credentials, enabling the attacker to bypass MFA checks and conduct unauthorized purchases. The operation impacted 28,000 customer accounts, with 5,800 used for unauthorized purchases totaling $721,000, and caused $250,000 in direct losses including chargebacks. The suspect operated infrastructure to sell stolen data via Telegram bots, and police seized devices and evidence but have not yet announced an arrest. The stolen session data allowed attackers to log in without credentials and bypass MFA, highlighting the need for stronger session management.

Security teams should audit for stolen session tokens, enforce MFA, review account activity logs, and conduct a comprehensive security audit to mitigate infostealer threats.

Key changes

  • 28,000 customer accounts impacted; 5,800 used for unauthorized purchases totaling $721,000.
  • Direct losses of $250,000, including chargebacks.
  • 18‑year‑old suspect used infostealer malware between 2024‑2025 to steal browser sessions and credentials.
  • Session data could bypass MFA checks.
  • Suspect operated infrastructure to sell stolen data via Telegram bots.
  • Police seized devices and evidence, but no arrest announced yet.
  • 5,800 unauthorized purchases were made.
  • 28,000 accounts had session tokens stolen.

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting