A suspected hacker believed to be extorting companies using the name “DESORDEN Group” (or ALTDOS, GHOSTR and 0mid16B) has been arrested in Thailand, for leaking stolen data from more than 90 organizations around the world.

The suspect was arrested in Bangkok as part of an operation by law enforcement authorities (Royal Thai Police and Singapore Police Force), in collaboration with experts from Group-IB.
The hacker, who had been operating since 2020, stole and leaked/sold over 13 TB of data belonging to the compromised organizations.
See also: Hackers leaked Genea patient data
According to Group-IB , the arrested individual was “ one of the most active cybercriminals in the Asia-Pacific region since 2021 ,” targeting entities primarily in Thailand, Singapore, Malaysia, Indonesia, and India . Some companies in Europe and North America were also targeted . Twenty of the data breaches involved organizations in these regions.
The hacker managed to evade authorities by constantly using new aliases and online personas.
How did the hacker act?
Group-IB says the hacker focused largely on extorting companies, often contacting the press to put more pressure on victims.
See also: Hackers can gain access to buildings – How is it done?
The hacker would attempt to infiltrate compromised databases containing personal data and demand payment for not disclosing it to the public. If the victim refused to pay, the hacker would not publish the data on the dark web, as most would do. Instead, he would alert the media or privacy regulators, in order to damage the victims’ reputations and cause them even greater financial damage.
He also often sent emails to his victims' customers to inform them of the breaches and, in rare cases, even encrypted the compromised company's databases.
A notable attack since the hacker operated under the alias "Desorden" is the breach and theft of data from Taiwanese computer giant Acer.
Despite the large number of breaches, Group-IB says the hacker did not perform significant lateral movement within networks, but focused on quickly stealing data and blackmailing victims.
In addition to arresting the hacker, Thai authorities also seized several items, including laptops and luxury goods believed to have been purchased with proceeds from cybercrime.
See also: DeceptiveDevelopment: North Korean hackers target freelance developers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Nation news agency reports that the suspect is a 39-year-old man named Chia, who was arrested in Bangkok. According to the same agency, Chia has already admitted his guilt, claiming that he worked alone.
While the hacker's arrest may bring some relief to victims, it serves as a stark reminder that cybersecurity is an ongoing battle that requires vigilance. As technology continues to advance, so must our defenses against cybercrime.
Protection from attacks
- Stay up to date on the latest trends and attack tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
Source: www.bleepingcomputer.com
