Ukraine Uncovers $721K Cybercrime Scheme Targeting California Retailer

Ukraine Uncovers $721K Cybercrime Scheme Targeting California Retailer

First seen 21 May 2026, 06:41 UTC Gp.UaTherecord.MediaThecyberexpressCybernewsBitdefender+3 83% similarity 66.5

Article Content

Browse articles
ThreatCluster

Ukrainian authorities have identified an 18-year-old suspect linked to a cybercrime operation that compromised nearly 30,000 customer accounts of a California-based online retailer. The operation, which ran from 2024 to 2025, involved the use of infostealer malware to harvest sensitive data, including login credentials and session tokens. Approximately 5,800 of the compromised accounts were exploited for unauthorized purchases totaling around $721,000, leading to direct losses exceeding $250,000. The investigation was initiated after U.S. law enforcement alerted Ukrainian officials about potential cyberattacks from Ukraine targeting American e-commerce platforms. Evidence collected during searches included mobile phones, computers, and cryptocurrency accounts, but no arrests have been reported yet. The suspect is believed to have managed the infrastructure for processing and selling stolen data through underground platforms.

Key Points: • An 18-year-old from Odesa is suspected of managing a cybercrime operation targeting a California retailer. • The scheme compromised nearly 30,000 accounts, leading to unauthorized purchases worth $721,000. • Infostealer malware was used to harvest sensitive data, highlighting the growing threat of credential theft.

ThreatCluster AI

Timeline

2024-01-01
Cybercrime operation begins
The operation targeting California online store customers commenced, utilizing infostealer malware.
Thecyberexpress
2025-12-31
Operation concludes
The cybercriminal group exploited over 28,000 accounts before being identified by authorities.
Thecyberexpress
2026-05-12
Searches conducted
Ukrainian police executed searches at the suspect's residences, seizing digital evidence.
Gp.Ua
2026-05-21
Public announcement made
Ukrainian authorities publicly identified the suspect and detailed the operation's impact.
Bitdefender

Community

Browse all →