HomeSecurityUkrainian man jailed for selling thousands of credentials on the dark web

Ukrainian man jailed for selling thousands of credentials on the dark web

Glib Oleksandr Ivanov-Tolpintsev, a 28-year-old Ukrainian, was sentenced to four years in prison for stealing thousands of login credentials and selling them on the dark web. Essentially, the Ukrainian had sold other criminals access to thousands of computers.

dark web credentials

Ivanov-Tolpintsev claimed to some of his associates that he could “crack” credentials for more than 2,000 systems each week with brute-force attacks, using a botnet.

See also: Nerbian RAT: New malware distributed via COVID-19-themed emails

“During the conspiracy, Ivanov-Tolpintsev boasted that his botnet was capable of decrypting the login credentials of at least 2,000 computers each week,” the Justice Department revealed.

According to the indictment, from 2017 to 2019, the Ukrainian had put thousands of credentials up for sale on dark web marketplaces. Cybercriminals turn to these marketplaces to buy stolen data and use it in a wide range of attacks (e.g. ransomware, phishing , etc.). Therefore, the Ukrainian was not only stealing victims' login details but also exposing them to additional risks, since the criminals who bought them could use them for their own malicious activities.

How was the Ukrainian identified by the authorities?

The Ukrainian defendant was active online under several aliases. However, the Justice Department used emails to identify his real identity and a Jabber address he used to communicate with representatives of the dark web market where he sold the stolen credentials.

According to court documents , FBI agents analyzed thousands of Jabber conversations during the investigation and built a timeline of Ivanov-Tolpintsev's activity as a seller of stolen data.

See also: HP patches two high-severity vulnerabilities

Ukrainian imprisonment
Ukrainian man jailed for selling thousands of credentials on the dark web

As researchers discovered, using the alias “Mars,” the Ukrainian cybercriminal allegedly “sold access” (via credentials) to 6,704 computers, earning a total of $82,648.

The young Ukrainian was arrested by Polish authorities in Korczowa, Poland, two years ago, on October 3, 2020, and extradited to the United States under the extradition treaty between the two countries.

See also: Elon Musk: Russia is trying to hack Starlink in Ukraine

Ivanov-Tolpintsev faced charges of conspiracy, unauthorized access to devices, and illegally obtaining and selling passwords that allowed access to thousands of computers.

On February 22, 2022, he pleaded guilty and has now received a 4-year prison sentence, although he faced a maximum sentence of 17 years.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS