Alleged admin of Russian-speaking cybercrime platform XSS arrested in Ukraine

Alleged admin of Russian-speaking cybercrime platform XSS arrested in Ukraine

Authorities in Kyiv arrested the suspected administrator of xss.is, one of the most notorious Russian-speaking cybercrime forums in the world. The arrest comes after a multi-year investigation led by French law enforcement, in close collaboration with Ukrainian authorities and Europol.

The suspect, whose identity has not yet been publicly disclosed, was apprehended on July 22 as part of a coordinated international operation aimed at dismantling criminal infrastructure and gathering critical evidence. According to investigators, the suspect run xss.is, a forum boasting over 50,000 registered users, where stolen data, hacking tools, and illicit cyber services were traded.

As the forum’s administrator, the suspect reportedly served as an arbitrator in disputes between criminals and ensured secure transactions, effectively functioning as a trusted third party. He is also suspected of running thesecure.biz, a private messaging service designed specifically for cybercriminal communications.

Authorities estimate the suspect earned over EUR 7 million through advertising revenues and facilitation fees. With alleged activity stretching back nearly two decades, the administrator is thought to have maintained longstanding relationships with some of the most prolific and dangerous threat actors online.

The investigation was launched by France in 2021. The arrest in Kyiv is the latest in a series of enforcement actions targeting the forum’s infrastructure and affiliates.

Back to the list

Latest Posts

Cyber Security Week in Review: July 25, 2025

Cyber Security Week in Review: July 25, 2025

In brief: Microsoft SharePoint zero-days exploited in widespread attacks, the Russian aerospace and defense industries targeted in Operation CargoTalon, and more.
25 July 2025
Microsoft warns of Warlock ransomware attacks exploiting SharePoint flaws

Microsoft warns of Warlock ransomware attacks exploiting SharePoint flaws

The attackers are using the flaws to deploy a malicious web shell named spinstall0.aspx.
24 July 2025
Lumma infostealer returns after May police crackdown

Lumma infostealer returns after May police crackdown

Lumma has shifted away from previous use of Cloudflare and is now leveraging alternative cloud services, particularly the Russian provider Selectel.
23 July 2025