An FSB-Linked Hacker Undone by PayPal and One Phone Number. The Void Blizzard Case and Cybersecurity Lessons for Companies
A Russian hacking group left fingerprints across half of Europe. Then, prosecutors say, one of its operators booked a beach holiday.
By Robert Nogacki
Facts and law stated as of July 26, 2026. Sources are linked in the text.
On the evening of November 6, 2025, Thai police officers, working jointly with the F.B.I., entered a hotel room in Phuket and arrested a guest who had flown in a week earlier: a thirty-five-year-old Russian programmer named Denis Obrezko. He left the building in handcuffs; his laptop, his phone, and a cryptocurrency wallet left in an evidence bag. On July 9th of this year, eight months later and half a world away, Obrezko, by then thirty-six, stood in a federal courtroom in Boston and pleaded not guilty to a single, bureaucratically phrased count: conspiracy to obtain unauthorized access to protected computers. The case is being handled by the national-security division of the Justice Department; the defendant is being held without bail; a conviction carries up to ten years in prison.
The distance between the modesty of that charge and the scale of what investigators describe is the most instructive thing about the case. The story assembled from charging documents, Dutch and American government reports, and press investigations (chiefly by Radio Free Europe/Radio Liberty, whose reporters first traced the arc) reads less like a spy novel than like an audit: an operation designed to be invisible, undone by the small conveniences of ordinary online life. It is also, for anyone who runs a company on the eastern edge of NATO, a preview of the questions that follow an incident. How does jurisdiction reach a perpetrator abroad? How is attribution actually built? And what changes, legally, once an attack is recognized as the work of a state?
* * * *
In September, 2024, Dutch analysts discovered that someone had been reading the police’s mail. An intruder had taken over the account of an employee of the national force, and had done so without any of the flourishes that the word “hacking” tends to conjure. There was no zero-day exploit, no breached firewall. There was a stolen cookie: the small session file that a browser saves after a successful login. To the system, a valid session cookie is a hand stamp at a club door; whoever presents it has, by definition, already been checked, and is asked for neither a password nor a second factor. Inside the captured mailbox sat the force’s address book, with contact details for potentially all sixty-four thousand employees of the Dutch national police and, possibly, information about informants. Dutch military intelligence concluded that the country had, for the first time, been the target of deliberate cyber sabotage by a Russian-backed group. When the Dutch services went public, on May 27, 2025, they gave the intruders a code name of homely precision: Laundry Bear. Microsoft, publishing its own report the same day, calls the group Void Blizzard; in the company’s threat taxonomy, the weather is assigned by nationality, and “Blizzard” simply means Russia.
According to Microsoft, the group has been active since at least April, 2024, and hunts across NATO countries and Ukraine: government agencies, defense, transport, media, health care, N.G.O.s. Its specialty is the wholesale theft of e-mail. The pattern had a prologue. Years earlier, more than half a million e-mail addresses leaked from the servers of Alexey Navalny’s organization; some of the people on the list later received threats, and journalistic investigations traced the look-alike domains used in that operation to business circles in Samara, an industrial city on the Volga, and in particular to a businessman named Mikhail Dudin. Remember him; he comes back.
* * * *
Who, then, is Denis Obrezko? According to an F.B.I. agent’s affidavit, declassified during the extradition proceedings, he worked for the F.S.B., Russia’s domestic-security service, from 2012 to 2017; what he did there is not specified. He is a graduate of Bauman Moscow State Technical University, an élite engineering school that investigative journalists have repeatedly described as a feeder for the government’s hacking teams. Reuters established that he worked at Kaspersky Lab, the antivirus company, from 2017 to 2019, and in 2021 he appeared publicly as a deputy director of an information-and-analysis center at Russia’s Ministry of Emergency Situations. Since 2023, according to the indictment, he has been the deputy director of a company called Yutek, which prosecutors say conducted cyber-espionage operations at the direction of the Russian government.
It is at Yutek that the story acquires texture, and its largest asterisk. Journalists at RFE/RL found that Yutek-NN, registered in Nizhny Novgorod, held an F.S.B.-issued license to deal in equipment for the covert acquisition of information. In the charging documents, “Ethan Hunt” is the nickname of an unidentified co-conspirator whom Obrezko allegedly e-mailed; RFE/RL matched the same nickname, in a popular caller-I.D. app, to Dudin, the businessman from the Navalny prologue, who owned Yutek-NN until 2018 and whose reported associate, Pavel Seleznev, is described as a former F.S.B. officer. Neither man could be reached for comment, and independent researchers who have examined the corporate records call these connections circumstantial rather than proven. For the record, then, and not as a formality: Obrezko denies the charges, his lawyer has promised a vigorous defense on the facts and on the law, and everything recounted here comes from court filings, government reports, and press accounts, not from a verdict.
* * * *
In the summer of 2024, the F.B.I. received a tip from a private-sector partner, widely reported to be Microsoft, about a campaign aimed at American and European companies and institutions. The indictment describes a conspiracy running since at least 2023: spoofed domains, V.P.N.s, proxy servers, and a victim list that includes a social-media service, a real-estate developer, a cloud-software vendor, and an American university. The Bureau has identified at least eleven targeted companies in the United States, and notes, with the weariness of experience, that this is probably a fraction of the true number.
The path from campaign to name reads like a training manual. Cryptocurrency transactions from 2024 and 2025, used to pay for a virtual server and a domain deployed in the attacks, led to an Internet provider in Samara. The e-mail address attached to those transactions was linked to a Google account registered under a real name; the same account had registered social-media profiles and a PayPal account bearing the same phone number and the same date of birth. The same nickname and the same photograph recurred from platform to platform, like a monogram. A few hours after Microsoft published its Void Blizzard report, Obrezko allegedly wrote to “Ethan Hunt,” proposing a meeting that same day. And on the phone seized in Phuket, investigators say, there was a file of A.I.-generated summaries of more than thirteen thousand stolen e-mails belonging to parliamentarians of an Eastern European country. Espionage, too, is undergoing digital transformation; it now has productivity tools.
An analyst at Recorded Future, a threat-intelligence firm, has observed that what undid the operation was not one catastrophic mistake but a chain of small ones, each corroborating the next. It is entirely possible to be excellent at breaking into other people’s systems and mediocre at protecting your own identity. I know this methodology from the other side of the mirror. In my firm’s practice in Warsaw, representing victims of investment fraud, the work of recovery looks exactly like this: blockchain analysis joined to open-source intelligence, pursued patiently until an anonymous wallet touches the physical world at an exchange, a payment gateway, a phone number. Online anonymity rarely shatters. It leaks, through convenience.
* * * *
Why Phuket, and not Moscow? Because Russia does not extradite its own citizens; Article 61 of its constitution forbids it outright. American warrants have therefore learned to wait, sometimes for years, until a suspect buys a plane ticket. Yevgeniy Nikulin was arrested in the Czech Republic in 2016, in connection with the LinkedIn breach, and sentenced in the United States to seven years. Vladislav Klyushin was picked up in Switzerland in 2021 and sentenced to nine; he went home in the great prisoner exchange of August, 2024. That Moscow trades such convicts like assets says more about their status than any intelligence report could. Thailand, for its part, coöperated with Washington under a bilateral extradition treaty, and stressed that the transfer was carried out under domestic law and treaty obligations, with the usual procedural guarantees: precisely the machinery the Russian constitution is designed to keep its citizens away from.
The line between prosecution and protection, meanwhile, can be purely political. In 2021, when ransomware attacks by the REvil group hit American hospitals and businesses and President Biden raised the matter personally with Vladimir Putin, the F.S.B. staged demonstrative arrests of REvil members, taking care to note that it was acting at Washington’s request. A former analyst at the Dutch national cybersecurity center has asked what failed in Obrezko’s calculation: an underestimate of Western services, or an overestimate of his own protective umbrella? The psychology of risk suggests a third answer. Years of impunity recalibrate a person’s sense of danger more efficiently than any training course.
* * * *
In classic cybercrime, intrusion is followed by monetization: ransom, blackmail, the sale of data. Here that step never came, which raises the question the Dutch analyst posed: if there is no visible business model, who is paying? Is the intruder selling data to the state, or simply employed by it? The answer matters far beyond geopolitics, because it decides which body of law an incident falls into, and who ends up bearing the loss.
The prosecutors’ choice of statute is the first tell. The charge is computer crime, not espionage, and that is no accident: logs, transactions, and account records can be shown to a jury without exposing intelligence sources. (For companies operating in Poland, the domestic analogues sit in Articles 267 through 269b of the Criminal Code, and acting for a foreign intelligence service can additionally engage the espionage provisions that were tightened in 2023.) Public attribution to a state also opens the way to the European Union’s cyber-sanctions regime: listings, asset freezes, travel bans. Then there is insurance, where geopolitics quietly becomes a line item. After the NotPetya attack, the pharmaceutical giant Merck spent years litigating with its insurers over a war-exclusion clause; the courts leaned the insured’s way, and, in January, 2024, the parties settled a dispute over roughly $1.4 billion in claims. The market replied in its own dialect: since March 31, 2023, standalone cyber policies written at Lloyd’s have been required to exclude losses from state-backed cyberattacks. It is worth reading your own policy before a claims adjuster does. And civil recovery from a perpetrator operating under a state umbrella is, for practical purposes, an illusion; liability migrates to where it can actually be enforced, which is to say the quality of your procedures, your vendor contracts, and the text of your policy. Those are the documents that will be judged after an incident, because the person who caused it will be out of reach, or at the beach.
* * * *
The attack vector in this case is painfully universal: an infostealer on an employee’s laptop, a stolen session token, a captured mailbox. Multi-factor authentication remains necessary, and it is not an amulet; a grown-up security policy adds short session lifetimes, tokens bound to devices, conditional access, and monitoring for leaked credentials. Under Article 32 of the E.U.’s General Data Protection Regulation, safeguards must be appropriate to the risk in light of the state of the art, and since session-token theft by infostealer malware is by now a known, mass-scale technique, the adequacy of a company’s defenses will be judged with that vector in mind. No regulator, after an incident, will be satisfied to hear that multi-factor authentication was, technically, switched on.
In Poland, where my practice sits and where operations of exactly this kind land with particular frequency, the regulatory ground has just changed state. On April 3, 2026, an amendment to the Act on the National Cybersecurity System (ustawa o krajowym systemie cyberbezpieczeństwa) came into force, implementing the E.U.’s NIS2 directive. Covered entities must identify themselves and register by October 3, 2026; essential and important entities have until April 3, 2027, to bring systems and procedures into line; the first audits of essential entities fall due by April 3, 2028; and administrative fines, reaching ten million euros or two per cent of worldwide turnover for essential entities (seven million euros, or 1.4 per cent, for important ones), become available two years after entry into force. The law also introduces personal liability for the managers of covered entities, with fines pegged to their own remuneration and a mandatory cybersecurity training, which converts the transition period from a grace period into the only window in which compliance can be built without the pressure of proceedings. Financial institutions have applied the E.U.’s Digital Operational Resilience Act, DORA, directly since January 17, 2025, with its own regime for reporting serious incidents; and the G.D.P.R., indifferent to all of the above, still requires notifying the data-protection authority of a breach, as a rule, within seventy-two hours.
The new reporting rhythm is counted in hours: an early warning within twenty-four, an incident notification within seventy-two, a final report within a month. Deadlines of that length mean the decisions must be made in advance: who classifies an incident, who reports it, who speaks to the authorities, how evidence is preserved. The Obrezko case shows that attribution can work. It also shows that attribution is built from data collected in the first hours, not from testimony given months later.
* * * *
Great cyber operations rarely lose to firewalls anymore. They lose to the convenience of their own authors, to one phone number typed into too many forms. The Ethan Hunt of the “Mission: Impossible” movies pulled masks off other people; here, if prosecutors are right, the mask slid off by itself, at the registration page of a payment account. For companies, the moral is less cinematic and more actuarial: resilience is decided before the incident, in access architecture, in reporting procedures, in the fine print of an insurance policy. The sea off Phuket in early November is as warm as bathwater, and the presumption of innocence, unlike a session cookie, does not expire; Obrezko will have his trial. But one finding is already in. What stopped Laundry Bear was not a firewall. It was the laundry: the ordinary, traceable residue of a life lived online, hung out where anyone could see it.

Robert Nogacki – licensed legal counsel (radca prawny, WA-9026), Founder of Kancelaria Prawna Skarbiec.
There are lawyers who practice law. And there are those who deal with problems for which the law has no ready answer. For over twenty years, Kancelaria Skarbiec has worked at the intersection of tax law, corporate structures, and the deeply human reluctance to give the state more than the state is owed. We advise entrepreneurs from over a dozen countries – from those on the Forbes list to those whose bank account was just seized by the tax authority and who do not know what to do tomorrow morning.
One of the most frequently cited experts on tax law in Polish media – he writes for Rzeczpospolita, Dziennik Gazeta Prawna, and Parkiet not because it looks good on a résumé, but because certain things cannot be explained in a court filing and someone needs to say them out loud. Author of AI Decoding Satoshi Nakamoto: Artificial Intelligence on the Trail of Bitcoin’s Creator. Co-author of the award-winning book Bezpieczeństwo współczesnej firmy (Security of a Modern Company).
Kancelaria Skarbiec holds top positions in the tax law firm rankings of Dziennik Gazeta Prawna. Four-time winner of the European Medal, recipient of the title International Tax Planning Law Firm of the Year in Poland.
He specializes in tax disputes with fiscal authorities, international tax planning, crypto-asset regulation, and asset protection. Since 2006, he has led the WGI case – one of the longest-running criminal proceedings in the history of the Polish financial market – because there are things you do not leave half-done, even if they take two decades. He believes the law is too serious to be treated only seriously – and that the best legal advice is the kind that ensures the client never has to stand before a court.