Skip to main content
GBU_week40_2026.jpg
The Good, the Bad and the Ugly

The Good, the Bad and the Ugly in Cybersecurity - Week 40 (2026)

By SentinelOne

The Good | Authorities Sentence Ex-Military Cybercriminals & Dismantle KillSec Gang

A federal court has sentenced former U.S. Army soldier Cameron John Wagenius to 70 months in prison and ordered him to pay $294,978 in restitution for launching cyberattacks on technology and telecommunications firms. While on active duty, Wagenius helped develop the SSH Brute hacking tool to steal network login credentials and customer records. 

He and his co-conspirators then attempted to extort at least $1 million from victims by threatening to publish the stolen data. The stolen records themselves were also used to carry out SIM-swapping fraud, showing how a single database intrusion feeds broader cybercrime ecosystems. 

Also this week, former U.S. Air Force members Chijioke Timothy Odimegwu and Harafat Mogaji were sentenced to a combined 189 months in jail for their roles in widespread business email compromise (BEC) campaigns—a crime that caused over $3 billion in losses last year. The pair stole employee credentials and spoofed business partner emails to hijack corporate wire transfers across multiple states and abroad. 

As part of their scheme, Odimegwu and Mogaji diverted a $1.68 million wire from an Iowa victim and a $720,000 wire from an Ohio victim, among other attempted transfers. Both individuals will also serve three years of supervised release and pay a combined total of $1.3 million in restitution.

Finally, a coordinated law enforcement action “Operation KillSwitch” has dismantled the KillSec ransomware gang, seizing its dark web leak site, five core servers, and 110 terabytes of stolen data. Authorities across four countries executed eight searches, while three suspects were provisionally arrested, one of them being the group's alleged primary administrator and only 16-years-old. 

operation_killswitch_banner.jpg

Active since 2024, KillSec launched approximately 500 successful data theft attacks by exploiting software flaws and abusing AI to build ransomware infrastructure. The coordinated takedown disrupted the syndicate's extortion operations and enabled international investigators to trace illicit cryptocurrency proceeds across global jurisdictions.

The Bad | DPRK-Based Crypto Hackers Exploit Third-Party Zero-Day in $387M Bitget Heist

Cryptocurrency exchange Bitget suffered a cyberattack after threat actors breached its wallet infrastructure and exfiltrated an initial amount of $351.6 million in digital assets across multiple blockchains, including Ethereum, XRP Ledger, TRON, and Avalanche. Security systems flagged unauthorized transfers from the wallets, prompting the exchange to temporarily suspend all withdrawals while maintaining normal trading operations. 

Citing IP behavior patterns and on-chain transaction analysis, Bitget leadership attributed the intrusion to North Korean state-sponsored hackers, who compromised a critical backend wallet-service system to spoof transaction data and bypass authorization controls.

Following further on-chain tracing across eleven affected blockchains, Bitget revised the total stolen assets upward to $387.5 million and launched a five percent recovery bounty program to mobilize the global security community and help freeze affected funds. The exchange reassured users that customer account balances remained unaffected and that all financial losses were fully covered by its $464 million protection fund. After addressing the initial breach vector and confirming system integrity, Bitget has since initiated a phased resumption of cryptocurrency withdrawals.

Subsequent forensic investigations revealed that the attackers gained initial entry by exploiting a zero-day vulnerability in two third-party security appliances. The threat actors leveraged the flaw to harvest database passwords and drop web shells before obtaining high-level internal credentials. Using persistent access on the security appliances, the operators moved laterally to Bitget's production wallet job server and deployed custom malware to issue fraudulent withdrawal commands. 

This intrusion is the latest cryptocurrency heist potentially linked to North Korean state-sponsored actors, with laundering infrastructure from the Bitget breach linked to other operations, including the $1.5 billion Bybit cold-wallet exploit from early last year.

The Ugly | Pentagon Breach Exposes Data of Three Million People

The Pentagon's Defense Manpower Data Center (DMDC) is notifying more than three million people that their personal data was exposed in a data breach involving its human resources management systems. According to official breach notification letters distributed to affected personnel, the DMDC discovered a security vulnerability in the system on July 16, 2026 and determined that a small number of unauthorized users had accessed files containing unencrypted PII since October 2025.

DMDC_3_million_breach.jpg
Source: Reddit (r/AirForce)

Pentagon officials confirmed that the compromised records impact 2.8 million living individuals and 294,000 deceased service members. The exposed data includes sensitive personally identifiable information (PII), such as social security numbers, full names, dates of birth, contact details, race, gender, and detailed military assignment records. 

As the primary repository for military human resources data, the DMDC supports vital operations across national defense, healthcare, finance, labor, and veterans affairs, making the exposure an operational concern for federal defense leadership.

Upon discovering the vulnerability, system administrators initiated incident response protocols in accordance with federal guidelines and began implementing enhancements to strengthen the agency's security posture. The incident coincides with a broader pattern of high-profile government cyber intrusions, including the ShinyHunters extortion group breaching the FBI’s recruitment platform, FBIjobs.gov, by exploiting an Oracle PeopleSoft zero-day flaw. In that intrusion, the threat group claimed to exfiltrate several terabytes of sensitive administrative records, including personal data belonging to active special agents and personnel.

Although ShinyHunters claimed that their actions were not financially motivated, both compromises highlight federal human resources platforms as high-risk targets. 

Defense officials have, so far, not found any evidence of the exposed information being sold or misused and have offered both credit and identity protection resources to those affected.

Related Articles

Decorative background gradient

Subscribe

Get the Latest From the SentinelOne Blog