Polish law enforcement arrested a 47-year-old man in the Małopolska/Lesser Poland region on suspicion of involvement with the Phobos ransomware operation as part of Europol-coordinated Operation Aether targeting Phobos-linked infrastructure and affiliates. During a search of the suspect’s residence, Poland’s Central Bureau/Central Office for Combating Cybercrime (CBZC) seized devices and data investigators said could enable unauthorized access and ransomware activity, including stolen credentials, passwords, credit card numbers, and server IP/access data.
Authorities said technical analysis indicated the seized materials could be used to breach electronic security and support “various attacks, including ransomware,” and alleged the suspect used encrypted messaging to communicate with the Phobos criminal group. Reporting also noted the seizure of a laptop and multiple smartphones, and that the suspect was charged with offenses related to creating/acquiring/sharing tools or data used to unlawfully obtain information and facilitate unauthorized system access; if convicted, he faces up to five years in prison. Operation Aether reporting additionally linked the enforcement activity to efforts against 8Base, described as a ransomware group believed to be connected to Phobos.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
During the raid, police seized a laptop or computer, multiple smartphones, payment cards, and other items, and reported finding stolen credentials, passwords, credit card numbers, server IP addresses, and related access data. Investigators said the materials could facilitate unauthorized access and ransomware attacks.
Poland's Central Bureau of Cybercrime Control arrested a 47-year-old man in the Małopolska region on suspicion of involvement with the Phobos ransomware operation. Authorities said he used encrypted messaging to communicate with the group and charged him with creating, obtaining, and sharing tools used for illegal access to IT systems.
A Europol-led multinational operation conducted in February 2025, referred to in reporting as Operation Aether, identified a suspect in Poland allegedly tied to the Phobos ransomware ecosystem. The operation targeted Phobos operators, affiliates, and infrastructure internationally.
In November 2024, alleged Phobos developer and administrator Evgenii Ptitsyn was extradited from South Korea to the United States to face cybercrime charges tied to Phobos development and operations. Reporting says Phobos-linked activity declined after his extradition.
In February 2024, U.S. authorities warned that Phobos ransomware was affecting U.S. state, local, tribal, and territorial governments and other critical infrastructure organizations. The warning highlighted the growing operational impact of the ransomware-as-a-service group.
The 8Base ransomware group, described as linked to the Phobos ecosystem, increased its activity in summer 2023 and claimed several high-profile victims. Later reporting connected 8Base to broader law-enforcement actions targeting Phobos infrastructure and affiliates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcetheregister.com
Open sourcecbzc.policja.gov.pl
Open sourcetherecord.media
Open sourcego.theregister.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.