Romanian national Catalin Dragomir, who used the alias inthematrixl, was sentenced to 56 months in prison after pleading guilty to hacking Oregon’s Office of Emergency Management and selling administrative access to the state government network on a cybercriminal forum. U.S. prosecutors said Dragomir repeatedly breached the Oregon network, stole an employee’s personal data — including name, email address, date of birth, and Social Security number — and used that access for criminal resale.
The case followed Dragomir’s arrest in Romania in November 2024, extradition to the United States, and guilty plea to aggravated identity theft and obtaining information from a protected computer. Authorities said he was also tied to intrusions affecting 10 other U.S. organizations, with combined losses of at least $250,000, underscoring how stolen government and enterprise credentials continue to be monetized through underground access markets.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
After his November 2024 arrest in Romania, Catalin Dragomir was extradited to the United States in January 2025 to face charges tied to intrusions affecting an Oregon state government office and other U.S. victims.
Dragomir was sentenced to 56 months in prison for hacking Oregon government systems and additional U.S. organizations, with authorities linking him to 10 other American company intrusions and at least $250,000 in losses. The Record reported the sentencing on May 27, 2026 as a new development.
Catalin Dragomir was arrested in Romania in connection with hacking Oregon government systems and other U.S. organizations. The later sentencing report states this arrest occurred in November 2024 before his extradition to the United States.
Catalin Dragomir pleaded guilty to aggravated identity theft and obtaining information from a protected computer for intrusions involving Oregon’s Office of Emergency Management and other U.S. victims. DOJ announced the plea on February 20, 2026.
A Ukrainian national pleaded guilty to conspiracy related to using Nefilim ransomware to attack companies in the United States and other countries. The plea was announced by DOJ on December 19, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcestatescoop.com
Open sourcejustice.gov
Open sourcetherecord.media
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.