Security News

Cybersecurity news aggregator

đź’€
LOW News SecurityWeek

Man Linked to Phobos Ransomware Arrested in Poland

  • What: A man suspected of involvement with the Phobos ransomware operation was arrested in Poland.
  • Impact: Authorities found hacking tools and communications with the Phobos group on the suspect's devices.
Read Full Article →

CYBERCRIME Man Linked to Phobos Ransomware Arrested in Poland Polish police said they found evidence of cybercrime on the 47-year-old suspect’s devices. By Eduard Kovacs | February 17, 2026 (7:54 AM ET) Flipboard Reddit Whatsapp Email A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation. According to Poland’s Central Cybercrime Bureau, officers found hacking tools, credentials, payment card numbers, and server IP addresses on the unnamed suspect’s devices during a search. They also discovered that the suspect had exchanged messages with the Phobos ransomware group. While authorities have not shared details about his potential role in the Phobos operation, the brief description from the Central Cybercrime Bureau suggests he may have been an affiliate rather than an operator. The Phobos ransomware-as-a-service operation emerged in 2019. In early 2024, the US government warned critical infrastructure organizations about attacks. The United States and Europe have since announced taking significant action against the Phobos operation. ADVERTISEMENT. SCROLL TO CONTINUE READING. The international law enforcement operation involved infrastructure takedowns and the arrests of several Russian nationals believed to have been key members and affiliates of the cybercrime gang. One suspect, accused of selling, distributing, and operating the Phobos ransomware, was extradited from South Korea to the US in late 2024. According to authorities, more than 1,000 organizations around the world have been targeted in Phobos ransomware attacks and the cybercriminals are believed to have obtained over $16 million in ransom payments. Related: Ukrainian Nefilim Ransomware Affiliate Extradited to US Related: US Charges 31 More Defendants in Massive ATM Hacking Probe Related: Jordanian Admits in US Court to Selling Access to 50 Enterprise Networks WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs Check Point Announces Trio of Acquisitions Amid Solid 2025 Earnings Beat BeyondTrust Vulnerability Targeted by Hackers Within 24 Hours of PoC Release China Revives Tianfu Cup Hacking Contest Under Increased Secrecy Hacktivists, State Actors, Cybercriminals Target Global Defense Industry, Google Warns Conduent Breach Hits Volvo Group: Nearly 17,000 Employees’ Data Exposed Chipmaker Patch Tuesday: Over 80 Vulnerabilities Addressed by Intel and AMD Google-Intel Security Audit Reveals Severe TDX Vulnerability Allowing Full Compromise ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, Phoenix Contact Latest News 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos Password Managers Vulnerable to Vault Compromise Under Malicious Server Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Android 17 Beta Strengthens Secure-by-Default Design for Privacy and App Security CISA Navigates DHS Shutdown With Reduced Staff Microsoft Warns of ClickFix Attack Abusing DNS Lookups Amazon Scraps Partnership With Surveillance Company After Super Bowl Ad Backlash Google Patches First Actively Exploited Chrome Zero-Day of 2026 TRENDING Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit PEOPLE ON THE MOVE Robert Carvajal has been appointed as CISO of BayCare Health System. KnowBe4 announced the appointment of Kelly Morgan as Chief Customer Officer. CrowdStrike has named Jonathon Dixon as vice president and managing director for the JAPAC region. More People On The Move EXPERT INSIGHTS How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Email

Share this article