
A hacker, a Cypriot national, has been extradited to the US to face charges related to the hacking attack on review portal Ripoff Report, committing extortion and 's backend site.
The man, named Joshua Polloso Epifaniou, 21 years old, and a resident of Nicosia, arrived in the US on Friday and will appear before the judge today.
The hacking attack on Ripoff Report
According to court documents, US authorities believe the Cypriot hacker carried out a brute-force attack to obtain the credentials of a Ripoff Report employee in October 2016.
The Cypriot hacker then worked with an company to remove bad reviews from the Ripoff Report site for the SEO company's clients.
“Epifaniou and his associate removed at least 100 complaints from the ROR database , charging the SEO firm’s clients approximately $3,000 to $5,000 for the removal of each complaint,” the U.S. Department of Justice said.

Investigators said that when a local bank in Cyprus blocked the partner's payments to the hacker, the two arranged for the SEO company to justify the bank transfers to Epifaniou.
Court documents did not name Epifaniou's partner, but an investigation alleges that the Cypriot hacker worked with Pierre Zarokian, the founder of the company Submit Express.
Epifaniou emailed Ripoff Report's CEO in November 2016 and attempted to blackmail the company while simultaneously removing bad reviews from its database.
According to investigators, the Cypriot hacker demanded $90,000 within 48 hours from the CEO, threatening to leak the database onlineif it was not paid.
When he did not receive a response from the CEO, the hacker sent another email with a video showing him accessing his (the CEO's) account.
The FBI launched an investigation into the breaches in 2017, and Submit Express' CEO was arrested in 2018 and pleaded guilty earlier this year.

Other hacking attacks
In addition to the breach and extortion of Ripoff Report, the Cypriot hacker is also accused of breaching other sites (October 2014-November 2016).
To blackmail the victims, Epifaniou used two techniques:
- He used security flaws to hack sites and steal user data.
- He purchased data of the targeted sites from other hackers and then used it to blackmail victims into paying ransom.
