Search/airbnb
Vendor

airbnb

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
optica
Connections
8 relationships
How to protect yourself from webcam spying: five simple steps | Kaspersky official blog
These days, it can feel like there’s a camera watching us from every corner: a video doorbell by the front door, a laptop webcam in the home office, an IP baby monitor in the children’s room, a smart TV with a camera and microphone in the bedroom, a robot vacuum with a navigation camera roaming around the house… Even a smart cat feeder could be spying on you! And any one of these cameras can easily become a useful tool for extortionists, blackmailers, or simply curious malicious actors. You don’t have to look far for examples. South Korea, late 2025: not one device, but 120,000 IP cameras were hacked . The criminals sold intimate footage and recordings of people’s everyday lives by subscription in private chats. In this article, we look at exactly where the threat comes from, and outline five rules that can greatly reduce your chances of becoming the star of a voyeur’s show. Real-life cases of surveillance Hotel porn by subscription Unfortunately, reports of miniature cameras being discovered in hotel rooms and rental apartments have become almost routine. Technically, these belong to a separate category of devices — “spy cameras” disguised as power outlets, smoke detectors, or alarm clocks. We’ll explain a little later how to detect them. Criminals don’t just publish footage from spy cameras — they even livestream it. Access to intimate videos, naturally, isn’t free. In some regions, criminals have built an entire infrastructure around spy cameras: some people install the cameras, others process the footage, while still others sell access through the dark web or messaging apps. Victims typically discover that there was a hidden camera in their hotel room purely by accident , after coming across videos of themselves on porn sites. Hunting motorists Another popular attack vector is hacking dashcams that can connect to the internet. These devices are tempting targets for attackers: their security is often weak, while the footage clearly shows license plates, road signs, and addresses on buildings. The recordings also contain detailed metadata, including exact dates, GPS coordinates, and more. This can allow criminals to identify a victim’s regular routes, determine where their car is parked, or even eavesdrop on conversations with passengers. There can be enough information for full-scale surveillance, car theft, or even blackmail if the camera records conversations and video inside the car. Stalking Not all stolen camera footage is the result of attacks by professional cybercriminals looking to profit from it. Sometimes, stalkers hack webcams to spy on specific people — often someone they know. For example, in 2025 a case came to light in which a man had been spying on his colleagues for years through their home IP cameras. All of the victims were women, who had no idea they were being watched. In another case, a man monitored his ex-wife and daughter through an intercom system and IP cameras. He made no attempt to hide the fact that he was spying on his own family, and even sent his daughter screenshots from the webcam. As a result, she eventually had to move away. Why does this happen? Neglecting basic cybersecurity rules This is probably the main reason IP cameras get hacked. Most users never change the factory-default passwords on their routers, smart devices, or the apps connected to them. Such passwords are essentially public knowledge. They often use simple combinations such as “admin/admin” or “root/1234”, which are known worldwide and can be guessed in a matter of seconds — no sophisticated algorithm is required. This is exactly what recently allowed attackers to hack 120,000 cameras in South Korea. Irresponsible camera manufacturers Even when manufacturers give assurances that camera data is stored only locally, in practice this is often far from the truth. For example, in 2022 researchers discovered that one popular range of video cameras sent snapshots to the manufacturer’s server every time a person appeared in the frame . And that wasn’t all: remote access to all cameras’ recordings was available through URLs generated in a predictable way — making them relatively easy to generate or guess. At the same time, the company claimed that its cameras used end-to-end encryption, stored recordings exclusively on the device, and didn’t transmit data to external servers. Incidentally, the supposedly “secure encryption” was implemented using a fixed key that was identical for every user. And the key itself could easily be found in the source code published by the manufacturer. In short, if a device has a lens and Wi-Fi, be prepared for the possibility that sooner or later a serious security flaw will be discovered in it. Search engines for vulnerable devices are becoming increasingly popular To access a camera, an attacker often only needs to know its IP address and try a handful of common passwords. There are search engines that index not websites, but devices and their open ports: webcams, routers, industrial controllers, medical equipment — you name it. If an IP camera requires no username and password, or is “protected” by the default “admin/admin” credentials, it may easily be discovered and added to the database of an OSINT service. Journalists and researchers have used such services to find publicly accessible cameras in children’s rooms, offices, hospital operating rooms, banks, and shops. So what can you do? What can you do at home or in a small office without a dedicated security team? These five simple recommendations can help. 1. Research the manufacturer When choosing an IP camera model, make sure you check whether cameras from that manufacturer have been hacked before — for example, by searching for “IP camera hack manufacturer name “. Then visit the Support section of the manufacturer’s website and check the date of the most recent firmware update both for the model you are considering and older models. If you find that firmware has not been updated for more than six months, or that updates are released irregularly, you may want to choose a different model. Most cameras run specialized embedded versions of Linux, and more than 2,300 vulnerabilities were recorded in the Linux kernel in the first six months of 2026 alone. If a manufacturer fails to update its firmware regularly, sooner or later a security hole is almost certain to appear in its cameras. Consider models from major manufacturers if you don’t want to end up with a whole collection of vulnerabilities and virtually no chance of them ever being patched. Cheap cameras from obscure companies with limited functionality and weak protection can ultimately cost you dearly. 2. Disable unnecessary features The fewer third-party cloud storage services involved in your surveillance system, the better. When choosing a camera, look for a microSD card slot, or support for a home network-attached storage device (NAS), so you can store all recordings locally. Ideally, the camera should be able to operate entirely within your local network without transmitting data to the cloud or the manufacturer’s servers — with viewing available over the LAN or through a secure connection  to your home or office. When buying other smart home appliances, consider whether you really need a built-in camera in, say, a smart TV, smart speaker , robot vacuum , or automatic pet feeder . Each and every one of these devices expands the potential attack surface. After buying an IP camera, go through its settings — usually available in the manufacturer’s app or through the camera’s web interface — and disable anything you don’t need. Pay attention to features related to person recognition, artificial intelligence, system permissions, discovery of other devices on the network, and cloud storage. If you don’t use a feature, feel free to disable it. In the network settings, make sure UPnP (Universal Plug and Play) is disabled or even absent as an option. UPnP can allow the camera to make itself accessible to other devices over the internet. Check that P2P access to the webcam is disabled or unavailable, so that the camera does not connect to external servers and cannot be reached from the internet without your direct control. Make a habit of checking who’s logged into your account and who still has access to your recordings. If you gave a friend access to your webcam so they could keep an eye on your dog while you’re away, remember to remove any unnecessary sessions afterwards. And if you’ve recently ended a relationship, pay particularly close attention to whether an ex-partner still has access. For more on this, see Post-breakup digital hygiene: what to check and shut down . 3. Change the default settings Factory-default passwords have been known to attackers for years. If you haven’t changed the username and password for your router or IP camera, an attacker may be able to gain access in a matter of seconds. Replace your router’s factory-default username and password with unique, long credentials. You can do this through the router’s web interface — we explain how to access it below. To generate and store strong, unique passwords, we recommend using Kaspersky Password Manager . If your camera is linked to an account on a website or in an app, make sure you use a strong password there too, and enable two-factor authentication or passkey authentication whenever possible. By the way, both 2FA tokens and passkeys can also be stored in Kaspersky Password Manager  and synchronized across all your devices. Update the firmware on both your router and IP camera to the latest versions, even if you just bought the device, and make regular updates a habit. Large-scale IP camera hacking campaigns often exploit long-known vulnerabilities that can only be fixed by installing updates. 4. Put all cameras and smart devices on a separate Wi-Fi segment We recommend segmenting your home Wi-Fi into separate subnets. You’ve probably encountered this arrangement in cafés, which often have one Wi-Fi network for staff and another for guests. All IP cameras and other smart home gadgets should ideally be moved to a separate Wi-Fi network and completely isolated from laptops, phones, and other work devices. Better still, IP cameras should be isolated from all other devices by creating a dedicated Wi-Fi network specifically for them. Most modern routers allow you to create at least two Wi-Fi networks — a primary network and a guest network — while more advanced models can support more. That way, even if your camera is hacked, the attacker won’t be able to reach your other devices or access sensitive files. How to open your router’s web interface Enter the router’s IP address in your browser’s address bar. It is usually printed on a label on the bottom of the router. Common IP addresses for home routers include 168.0.1 , 192.168.1.1 , and 10.0.0.1. Sign in on the page that opens. Most routers have a default username and password, which are usually also printed on the same label. Some routers may ask you to create your own username and password. We recommend choosing a strong one and storing it in Kaspersky Password Manager . Factory-default passwords have long been known to attackers, and if you don’t change your router password, they may be able to get into your home network with ease. Open the settings and look for sections related to Wi-Fi segmentation or the creation of subnets or guest networks. For detailed setup instructions, consult your router’s manual or the support section of the manufacturer’s website. For more advice on protecting your smart home, see our post How to secure your smart home . 5. Learn how to detect hidden cameras — both at home and while traveling Our final set of recommendations is not about configuring the camera itself, but about good security hygiene. Make a habit of checking the client list on your router. If you see an unknown device with a strange name or MAC address, investigate what it is and why it’s connected to your home network. Our security solution  includes a dedicated Smart Home Monitor component . This feature can alert you when a new device connects to your home wired or wireless network, provide simple recommendations for improving home network security, and identify weak router passwords and insecure encryption. When traveling, we recommend checking hotel rooms and rental properties for hidden recording devices: inspect places that offer a “convenient” view of the room, such as ventilation grilles, smoke detectors, power outlets, and decorative objects; in the dark, use your smartphone as an improvised optical detector: turn on the flashlight and camera, slowly scan the room, and look for distinctive reflections from a camera lens; use the front-facing camera to look for infrared light sources that are invisible to the human eye — this can help you spot the IR illumination used for “night vision”. For more practical methods of finding spy cameras, see our article Four ways to find spy cameras . What else you should know about surveillance and cameras: Korean-style webcam breach: 120 000 IP cameras hacked IP camera security: the bad, the ugly, and the evil Airbnb security: tips for safe travel Lumos: IoT device detection system Finding hidden cameras with your smartphone’s ToF sensor
kaspersky.comAug 19, 2026extracted
Travel scams are everywhere. Here’s how to avoid them
Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms. Combined with frequent travel scams and recurring data breaches in the travel and hospitality sector, it creates plenty of opportunities for criminals. This guide covers the most common risks when making travel reservations and explains how to avoid them. Save the adventure for your destination. Travel bookings combine high-value payments with urgency and emotional decision-making. Attackers love that for several reasons: Large upfront payments make scams profitable. Booking confirmations often contain valuable personal data, such as names, travel dates, contact details, and sometimes passport information. Travelers are more likely to act quickly and overlook red flags. Travel and hospitality companies are frequent breach targets due to complex IT environments and third-party integrations. Recent years have seen repeated breaches involving hotel chains, booking platforms, cruise operators, and airlines, exposing everything from email addresses to passport numbers. Common travel-related scams Fake booking websites Attackers create convincing clones of airline, hotel, and travel booking websites, often promoted through online ads or SEO poisoning (manipulating search engine results). Victims enter payment details, receive fake confirmations, and only discover the fraud later. Last year we uncovered a campaign using fake Booking.com websites that tricked visitors into infecting their own devices with a Remote Access Trojan (RAT). Phishing messages about reservation problems Emails, texts, or messaging app notifications may claim there’s a problem with your booking and urge you to click a link, open an attachment, or call a number. The scammers often impersonate legitimate travel brands and may include real stolen data from previous breaches. Earlier this year, we wrote about a Booking.com breach that provided scammers with a lot of useful information that could make their messages appear more convincing. Vacation rental fraud Scammers post fake listings or hijack legitimate ones on rental platforms. They typically encourage off-platform communication or payments to avoid built-in protections. In 2024, one of our researchers encountered exactly this type of scam. A supposedly legitimate Airbnb listing in Amsterdam turned out to be fake, and the scammer sent an email claiming to be from TripAdvisor in an attempt to collect payment details. “Too good to be true” deals Deep discounts on flights or accommodation are used to lure victims into paying for offers that don’t exist. If a deal seems unusually generous, look for the catch. Be especially cautious when advertisers claim the offer will end very soon. Creating urgency is one of the oldest tricks in the scammer playbook. Scam or legit? Scam Guard knows. Booking.com impersonation scams Booking.com has become an increasingly popular brand for scammers to impersonate. According to our—anonymized—Scam Guard data, we’ve recently seen: Fake cashback emails promising a €435 refund that lead to phishing websites In-app messages requesting an additional reservation fee Emails containing PDF attachments that require a “secure viewer,” which turns out to be malware WhatsApp messages claiming credit card details are missing and directing users to phishing sites Text messages linking to fake Booking.com pages and demanding card verification before a deadline The number of scams impersonating Booking.com has been growing. Since the breach disclosed in April, Scam Guard data shows a 56% increase in Booking.com-related scams compared to the previous period, with weekly volume up consistently across five straight weeks. How to book travel safely There are a few simple things that can dramatically reduce your risk: Use secure payment methods. Credit cards offer better fraud protection than debit cards or bank transfers. Never pay anyone asking for payment in cryptocurrencies or gift cards. Stick to trusted platforms. Even though these are not guaranteed to be safe, using them is better than gambling on an unknown platform. Don’t click on sponsored search results. I cannot say this often enough. Verify the existence of the booked accommodation through other channels. Treat requests to move communication or payment to another platform as suspicious. Consider urgent language, unexpected attachments, and mismatched sender domains as red flags. Downloads needed to open an attachment are not to be trusted. These downloads often turn out to be malware. To block and remove malware, use an up-to-date, real-time anti-malware solution. Pro tip: Malwarebytes Browser Guard will block known phishing websites and can even recognize suspicious websites that are not in our database yet. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comJun 4, 2026extracted
Virtual Summit Today: Supply Chain & Third-Party Risk Summit
SecurityWeek’s Supply Chain & Third-Party Risk Summit is now open and runs today from 11AM – 4PM ET. Modern organizations are navigating an increasingly complex ecosystem of vendors, SaaS platforms, APIs, and AI-enabled tools, each introducing new layers of risk. Login now to the virtual conference center to discover the latest frameworks, tools, and best practices to strengthen your defenses against malware, data exposure, and compromised dependencies. Today’s summit will help you: Understand how software supply chain attacks are evolving Gain visibility into third-party and vendor risk at scale Learn how AI and automation are reshaping risk management Explore real-world attack scenarios and defense strategies Discover tools and frameworks to strengthen your security posture immediately 11:00AM ET – Hyper TPRM: Rethinking Third-Party Risk for Scale, Speed, and Confidence (Ed Thomas, ProcessUnity) 11:30AM – The Power of Orchestration: Navigating Multi-Brand Experiences (Nathan Langton, Ping Identity) 12:00PM – Unmasking the Attacker’s Playbook: Dissecting Software Supply Chain Threats (Ziad Ghalleb, Wiz) 12:30PM – BREAK – Visit Virtual Expo 12:45PM – Software Supply Chain Risk Now Runs Client-Side: What OWASP’s Top 10 Shift Means for CISOs (Gareth Bowker, Jscrambler) 1:15PM – Agent Integration as an Identity problem (Mudita Khurana, Airbnb) 1:45PM – AI-Driven Vendor Risk Orchestration: Autonomous Framework for Third-Party Monitoring (Nirajkumar Radhasharan Barot, JPMorgan Chase) 2:15PM – 4:00PM – Technical Demos, Networking and Virtual Expo
securityweek.comMar 18, 2026extracted
“I Paid Twice” Phishing Campaign Targets Booking.com
A large-scale phishing operation exploiting Booking.com partner accounts has been uncovered by cybersecurity experts The latest Sekoia.io report, published today, detailed how cybercriminals compromised hotel systems and customer data through a sophisticated malware campaign active since at least April 2025. The intrusion began when attackers sent malicious emails from legitimate hotel accounts or impersonated Booking.com. Each message contained a link leading victims through a redirection chain before launching the so-called ClickFix social engineering tactic. Victims were prompted to execute a PowerShell command that downloaded malware, ultimately infecting systems with the PureRAT remote access Trojan. PureRAT allows attackers to remotely control infected machines, steal credentials, capture screenshots and exfiltrate sensitive data. Its modular design enables the addition of plugins for expanded capabilities. Analysts believe the malware initially targeted hotel staff to steal login credentials for booking platforms such as Booking.com, Airbnb and Expedia. These credentials were then either sold on cybercrime forums or used directly in fraudulent schemes. Once in possession of partner credentials, threat actors contacted hotel guests via email or WhatsApp, claiming issues with banking verification. Messages included authentic booking details, increasing their credibility. Victims were directed to fake Booking.com pages designed to harvest payment information. These sites, hosted behind Cloudflare protection and linked to Russian infrastructure, mimicked legitimate layouts to avoid detection. Sekoia.io analysts also observed an active trade in Booking.com credentials on Russian-language forums. Access details for these accounts (sold as authentication cookies or login pairs) ranged from $5 to $5,000, depending on value. One user, “moderator_booking,” allegedly claimed over $20m in profits. Attackers have since expanded operations to include Agoda accounts. The campaign demonstrates the growing professionalization of cybercrime targeting hospitality businesses. “We assess with high confidence that the client who fell victim to this fraudulent scheme paid twice for his reservation: once at the hotel and once to the cybercriminal,” Sekoia.io wrote. “Unveiling the adversary infrastructure revealed hundreds of malicious domains active for several months as of October 2025, demonstrating a resilient and likely profitable campaign.” The firm added it continues to monitor adversary infrastructure and improve detection methods to help protect booking platforms and their customers.
infosecurity-magazine.comNov 6, 2025extracted
Who Got Arrested in the Raid on the XSS Crime Forum?
On July 22, 2025, the European police agency Europol said a long-running investigation led by the French Police resulted in the arrest of a 38-year-old administrator of XSS, a Russian-language cybercrime forum with more than 50,000 members. The action has triggered an ongoing frenzy of speculation and panic among XSS denizens about the identity of the unnamed suspect, but the consensus is that he is a pivotal figure in the crime forum scene who goes by the hacker handle “Toha.” Here’s a deep dive on what’s knowable about Toha, and a short stab at who got nabbed. Europol did not name the accused, but published partially obscured photos of him from the raid on his residence in Kiev. The police agency said the suspect acted as a trusted third party — arbitrating disputes between criminals — and guaranteeing the security of transactions on XSS. A statement from Ukraine’s SBU security service said XSS counted among its members many cybercriminals from various ransomware groups, including REvil, LockBit, Conti, and Qiliin. Since the Europol announcement, the XSS forum resurfaced at a new address on the deep web (reachable only via the anonymity network Tor). But from reviewing the recent posts, there appears to be little consensus among longtime members about the identity of the now-detained XSS administrator. The most frequent comment regarding the arrest was a message of solidarity and support for Toha, the handle chosen by the longtime administrator of XSS and several other major Russian forums. Toha’s accounts on other forums have been silent since the raid. Europol said the suspect has enjoyed a nearly 20-year career in cybercrime, which roughly lines up with Toha’s history. In 2005, Toha was a founding member of the Russian-speaking forum Hack-All. That is, until it got massively hacked a few months after its debut. In 2006, Toha rebranded the forum to exploit[.]in, which would go on to draw tens of thousands of members, including an eventual Who’s-Who of wanted cybercriminals. Toha announced in 2018 that he was selling the Exploit forum, prompting rampant speculation on the forums that the buyer was secretly a Russian or Ukrainian government entity or front person. However, those suspicions were unsupported by evidence, and Toha vehemently denied the forum had been given over to authorities. One of the oldest Russian-language cybercrime forums was DaMaGeLaB, which operated from 2004 to 2017, when its administrator “Ar3s” was arrested. In 2018, a partial backup of the DaMaGeLaB forum was reincarnated as xss[.]is, with Toha as its stated administrator. CROSS-SITE GRIFTING Clues about Toha’s early presence on the Internet — from ~2004 to 2010 — are available in the archives of Intel 471, a cyber intelligence firm that tracks forum activity. Intel 471 shows Toha used the same email address across multiple forum accounts, including at Exploit, Antichat, Carder[.]su and inattack[.]ru. DomainTools.com finds Toha’s email address — [email protected] — was used to register at least a dozen domain names — most of them from the mid- to late 2000s. Apart from exploit[.]in and a domain called ixyq[.]com, the other domains registered to that email address end in .ua, the top-level domain for Ukraine (e.g. deleted.org[.]ua, lj.com[.]ua, and blogspot.org[.]ua). Nearly all of the domains registered to [email protected] contain the name Anton Medvedovskiy in the registration records, except for the aforementioned ixyq[.]com, which is registered to the name Yuriy Avdeev in Moscow. This Avdeev surname came up in a lengthy conversation with Lockbitsupp, the leader of the rapacious and destructive ransomware affiliate group Lockbit. The conversation took place in February 2024, when Lockbitsupp asked for help identifying Toha’s real-life identity. Lockbitsupp didn’t share why he wanted Toha’s details, but he maintained that Toha’s real name was Anton Avdeev. I declined to help Lockbitsupp in whatever revenge he was planning on Toha, but his question made me curious to look deeper. It appears Lockbitsupp’s query was based on a now-deleted Twitter post from 2022, when a user by the name “3xp0rt” asserted that Toha was a Russian man named Anton Viktorovich Avdeev, born October 27, 1983. Searching the web for Toha’s email address [email protected] reveals a 2010 sales thread on the forum bmwclub.ru where a user named Honeypo was selling a 2007 BMW X5. The ad listed the contact person as Anton Avdeev and gave the contact phone number 9588693. A search on the phone number 9588693 in the breach tracking service Constella Intelligence finds plenty of official Russian government records with this number, date of birth and the name Anton Viktorovich Avdeev. For example, hacked Russian government records show this person has a Russian tax ID and SIN (Social Security number), and that they were flagged for traffic violations on several occasions by Moscow police; in 2004, 2006, 2009, and 2014. Astute readers may have noticed by now that the ages of Mr. Avdeev (41) and the XSS admin arrested this month (38) are a bit off. This would seem to suggest that the person arrested is someone other than Mr. Avdeev, who did not respond to requests for comment. A FLY ON THE WALL For further insight on this question, KrebsOnSecurity sought comments from Sergeii Vovnenko, a former cybercriminal from Ukraine who now works at the security startup paranoidlab.com. I reached out to Vovnenko because for several years beginning around 2010 he was the owner and operator of thesecure[.]biz, an encrypted “Jabber” instant messaging server that Europol said was operated by the suspect arrested in Kiev. Thesecure[.]biz grew quite popular among many of the top Russian-speaking cybercriminals because it scrupulously kept few records of its users’ activity, and its administrator was always a trusted member of the community. The reason I know this historic tidbit is that in 2013, Vovnenko — using the hacker nicknames “Fly,” and “Flycracker” — hatched a plan to have a gram of heroin purchased off of the Silk Road darknet market and shipped to our home in Northern Virginia. The scheme was to spoof a call from one of our neighbors to the local police, saying this guy Krebs down the street was a druggie who was having narcotics delivered to his home. I happened to be lurking on Flycracker’s private cybercrime forum when his heroin-framing plan was carried out, and called the police myself before the smack eventually arrived in the U.S. Mail. Vovnenko was later arrested for unrelated cybercrime activities, extradited to the United States, convicted, and deported after a 16-month stay in the U.S. prison system [on several occasions, he has expressed heartfelt apologies for the incident, and we have since buried the hatchet]. Vovnenko said he purchased a device for cloning credit cards from Toha in 2009, and that Toha shipped the item from Russia. Vovnenko explained that he (Flycracker) was the owner and operator of thesecure[.]biz from 2010 until his arrest in 2014. Vovnenko believes thesecure[.]biz was stolen while he was in jail, either by Toha and/or an XSS administrator who went by the nicknames N0klos and Sonic. “When I was in jail, [the] admin of xss.is stole that domain, or probably N0klos bought XSS from Toha or vice versa,” Vovnenko said of the Jabber domain. “Nobody from [the forums] spoke with me after my jailtime, so I can only guess what really happened.” N0klos was the owner and administrator of an early Russian-language cybercrime forum known as Darklife[.]ws. However, N0kl0s also appears to be a lifelong Russian resident, and in any case seems to have vanished from Russian cybercrime forums several years ago. Asked whether he believes Toha was the XSS administrator who was arrested this month in Ukraine, Vovnenko maintained that Toha is Russian, and that “the French cops took the wrong guy.” WHO IS TOHA? So who did the Ukrainian police arrest in response to the investigation by the French authorities? It seems plausible that the BMW ad invoking Toha’s email address and the name and phone number of a Russian citizen was simply misdirection on Toha’s part — intended to confuse and throw off investigators. Perhaps this even explains the Avdeev surname surfacing in the registration records from one of Toha’s domains. But sometimes the simplest answer is the correct one. “Toha” is a common Slavic nickname for someone with the first name “Anton,” and that matches the name in the registration records for more than a dozen domains tied to Toha’s [email protected] email address: Anton Medvedovskiy. Constella Intelligence finds there is an Anton Gannadievich Medvedovskiy living in Kiev who will be 38 years old in December. This individual owns the email address [email protected], as well an an Airbnb account featuring a profile photo of a man with roughly the same hairline as the suspect in the blurred photos released by the Ukrainian police. Mr. Medvedovskiy did not respond to a request for comment. My take on the takedown is that the Ukrainian authorities likely arrested Medvedovskiy. Toha shared on DaMaGeLab in 2005 that he had recently finished the 11th grade and was studying at a university — a time when Mevedovskiy would have been around 18 years old. On Dec. 11, 2006, fellow Exploit members wished Toha a happy birthday. Records exposed in a 2022 hack at the Ukrainian public services portal diia.gov.ua show that Mr. Medvedovskiy’s birthday is Dec. 11, 1987. The law enforcement action and resulting confusion about the identity of the detained has thrown the Russian cybercrime forum scene into disarray in recent weeks, with lengthy and heated arguments about XSS’s future spooling out across the forums. XSS relaunched on a new Tor address shortly after the authorities plastered their seizure notice on the forum’s homepage, but all of the trusted moderators from the old forum were dismissed without explanation. Existing members saw their forum account balances drop to zero, and were asked to plunk down a deposit to register at the new forum. The new XSS “admin” said they were in contact with the previous owners and that the changes were to help rebuild security and trust within the community. However, the new admin’s assurances appear to have done little to assuage the worst fears of the forum’s erstwhile members, most of whom seem to be keeping their distance from the relaunched site for now. Indeed, if there is one common understanding amid all of these discussions about the seizure of XSS, it is that Ukrainian and French authorities now have several years worth of private messages between XSS forum users, as well as contact rosters and other user data linked to the seized Jabber server. “The myth of the ‘trusted person’ is shattered,” the user “GordonBellford” cautioned on Aug. 3 in an Exploit forum thread about the XSS admin arrest. “The forum is run by strangers. They got everything. Two years of Jabber server logs. Full backup and forum database.” GordonBellford continued: And the scariest thing is: this data array is not just an archive. It is material for analysis that has ALREADY BEEN DONE . With the help of modern tools, they see everything: Graphs of your contacts and activity. Relationships between nicknames, emails, password hashes and Jabber ID. Timestamps, IP addresses and digital fingerprints. Your unique writing style, phraseology, punctuation, consistency of grammatical errors, and even typical typos that will link your accounts on different platforms. They are not looking for a needle in a haystack. They simply sifted the haystack through the AI sieve and got ready-made dossiers.
krebsonsecurity.comAug 6, 2025extracted