Skip to main content
Security

Ukrainian police arrest three for hijacking 610,000 Roblox accounts

Ukrainian police arrest three for hijacking 610,000 Roblox accounts Image: Primary
Ukrainian police have arrested three individuals who hacked more than 610,000 Roblox gaming accounts and sold them for a profit of $225,000. The arrests were made in Lviv after conducting ten searches on targeted locations. Authorities seized $35,000 in cash, 37 mobile phones, 11 desktop computers, seven laptops, five tablets, and four USB drives. The hackers, aged 19, 21, and 22, were identified by the Prosecutor General's Office as targeting Roblox accounts. The 19-year-old leader recruited the other two on gaming forums and set up the account-hacking scheme. The group promoted info-stealing malware disguised as a game-enhancer tool, infecting victim devices and collecting login credentials. At least 357 of the compromised accounts were classified as high-value elite accounts. The stolen accounts were categorized by value, inventory rarity, and remaining Robux balances, then sold via a Russian website and closed online communities. The hackers were charged under articles 185 (theft) and 361 (unauthorized interference with IT systems) and face up to 15 years of imprisonment. Authorities continue investigating to identify other possible accomplices and victims.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...

Products Security
Products Security

Figma launches Japan data residency for enterprise file hosting

Figma introduced data residency in Japan, letting enterprise customers store Figma Design, FigJam, Figma Slides, and Figma Make file data in the country. The company said the option responds to customer demand for domestic storag...