A global law enforcement operation has led to the arrest of four suspected hackers, believed to be linked to the Phobos ransomware , and the seizure of dark web sites belonging to the 8Base gang. The suspects are accused of cyberattacks on more than 1,000 victims worldwide.

The hackers were arrested in Thailand. They are two men and two women, of European origin, who allegedly stole $16,000,000 worth of Bitcoin through their Phobos ransomware attacks.
The police operation, codenamed "Phobos Aetor," led to coordinated raids at four locations. Authorities seized laptops, smartphones and cryptocurrency wallets, which will be examined by experts.
See also: Data of 120,000 Bainbridge Hospital patients exposed in ransomware attack
The arrests were made at the request of Swiss authorities, who asked the Thai government to extradite the suspects.
The four hackers are said to have carried out ransomware attacks against at least 17 Swiss companies between April 2023 and October 2024. During the attacks, they breached corporate networks to steal data and encrypt files. They then demanded payments in cryptocurrency to provide the decryption keys and prevent the data from being made public.
To launder the illicit proceeds from the ransom, the Phobos ransomware hackers used cryptocurrency mixing, making it more difficult for law enforcement to track their final wallet.
8Base ransomware: Dark web sites seized
As part of the same police operation, dark web sites related to the 8Base ransomware were also reportedly seized . The ransomware gang's trading and data leak sites now display a seizure message stating: " THIS DARK SITE HAS BEEN SEIZED. This dark web site and the criminal content were seized by the Bavarian Criminal Police Office on behalf of the Public Prosecutor's Office in Bamberg ."
See also: Ransomware 2024: Ransom payments down 35%
The seizure message also indicates that “Operation Phobos Aetor” involved Thailand, Romania, Bavaria, Germany, Switzerland, Japan, the US, Europol, the Czech Republic, Spain, France, Belgium and the UK.
When asked about the legality of the seizure message, Europol told BleepingComputer, "Europol is supporting an international operation against a ransomware group."
The UK (NCA) also confirmed to BleepingComputer that they played a supporting role in the operation.

Like other ransomware operations, 8Base compromises corporate networks and spreads stealthily while stealing corporate data. It then encrypts devices using the Phobos ransomware encryptor.
When encrypting files, ransomware appends either the .8base or .eight extension to encrypted files. Hackers demand ransoms ranging from hundreds of thousands of dollars to millions in exchange for a decryption key and the promise to delete and not publish stolen data.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New York Blood Center Enterprises hit by ransomware
Ransomware protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source: www.bleepingcomputer.com
