Ukrainian cyberpolice, working with U.S. law enforcement, identified an 18-year-old suspect from Odesa as a key operator in an international cybercrime scheme that targeted customers of a California-based online retailer. Investigators said the operation used info-stealing malware to harvest browser session data and account credentials, leading to the compromise of roughly 28,000 to 30,000 customer accounts during 2024 and 2025.
Authorities said at least 5,800 of the stolen accounts were used to place unauthorized orders worth about $721,000, causing more than $250,000 in losses including chargebacks. The stolen data was allegedly processed and sold through online platforms, specialized resources, and Telegram channels or bots, while the suspect is believed to have managed infrastructure used to process and monetize the data. Ukrainian investigators searched two residences linked to the suspect and seized phones, computers, bank cards, storage media, server logs, account credentials, and cryptocurrency exchange information; officials have not named the retailer, the malware family, or any hacker group, and no arrest was announced.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Ukrainian cyberpolice identified an 18-year-old from Odesa as a central operator in the infostealer campaign and searched two residences linked to him. Investigators seized devices, bank cards, storage media, server logs, credentials, and cryptocurrency exchange information.
U.S. authorities notified Ukrainian investigators that hackers operating from Ukraine might be involved in attacks against American e-commerce platforms. This alert prompted the Ukrainian investigation into the scheme.
Using at least 5,800 compromised customer accounts, the operators made unauthorized purchases worth about $721,000. Authorities said the scheme caused more than $250,000 in losses, including chargebacks.
Between 2024 and 2025, an infostealer-based operation targeted customers of a California online retailer, stealing browser sessions and account credentials. Investigators said nearly 28,000 to 30,000 customer accounts were compromised during the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcecyberpolice.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.