ransom – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 05 Jul 2025 08:42:13 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 ransom – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Crypto Investor’s Wife Kidnapped for Ransom: Court Hands Down 12-Year Sentences https://earlybirdsinvest.com/crypto-investors-wife-kidnapped-for-ransom-court-hands-down-12-year-sentences/ https://earlybirdsinvest.com/crypto-investors-wife-kidnapped-for-ransom-court-hands-down-12-year-sentences/#respond Sat, 05 Jul 2025 08:42:13 +0000 https://earlybirdsinvest.com/crypto-investors-wife-kidnapped-for-ransom-court-hands-down-12-year-sentences/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

A court in Belgium has issued 12-year prison sentences to three individuals involved in the December 2024 kidnapping of the wife of a local cryptocurrency entrepreneur.

The case, which has drawn attention within both legal and crypto communities, centers on a ransom demand made in digital assets, highlighting the growing concerns about the intersection of financial technology and physical security.

Court Ruling and Ongoing Investigations

The Brussels Criminal Court found the trio guilty of hostage-taking after abducting the victim outside her residence and forcing her into a van. The kidnappers reportedly demanded a crypto ransom in exchange for her release.

Authorities acted swiftly after the woman’s husband, Stéphane Winkel, a known figure in the local crypto education scene, alerted law enforcement. Police intercepted the vehicle and executed a high-risk maneuver to halt it, freeing the victim and apprehending the suspects.

In addition to the prison terms, the court ordered the convicted individuals to pay a civil compensation of at least €1 million (approximately $1.2 million) to the victim. While the sentences mark the legal conclusion for the three kidnappers, the case remains open in some respects.

The court acknowledged that the principal figures behind the orchestration of the crime are still unknown. The defendants’ claims that they were acting under duress, allegedly threatened with death if they did not carry out the kidnapping, were dismissed by the court.

The case also involves a minor, whose role is being addressed separately through Belgium’s juvenile justice system. According to reports from La Dernière Heure, the court emphasized the seriousness of the offense and the need to maintain deterrence, particularly in criminal activities intersecting with emerging financial sectors like crypto.

The victim and her family have not been named in detail in court documents to protect their privacy, but the psychological toll has reportedly been substantial.

The Effect on Winkel Family and Crypto Community

Stéphane Winkel is known for his educational efforts within the cryptocurrency space. He runs platforms such as Crypto Académie and Crypto Sun, which aim to make digital asset investing more accessible to the public.

His YouTube channel, which has roughly over 39,000 subscribers, typically featured tutorials, giveaways, and wallet walkthroughs. However, the traumatic incident has prompted a shift in both his personal and public life.

In a post on X  published shortly after the incident, Winkel stated, “I consider myself a defender of freedom, but I now realize that safety must become an absolute priority for me and those around me.”

He also pledged to avoid public wallet demonstrations or promotional giveaways going forward, instead focusing his content on market analysis and education.

After several months of silence, Winkel returned to YouTube in June 2025, opting for voice-only narration in his videos rather than appearing on camera, a move that aligns with his new emphasis on privacy and security.

The global crypto market cap valuation on TradingView
The global digital currency market cap valuation. | Source: TradingView.com

Featured image created with DALL-E, Chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/crypto-investors-wife-kidnapped-for-ransom-court-hands-down-12-year-sentences/feed/ 0 45875
Coinbase resists $20 million Bitcoin ransom demand after insider-led data breach https://earlybirdsinvest.com/coinbase-resists-20-million-bitcoin-ransom-demand-after-insider-led-data-breach/ https://earlybirdsinvest.com/coinbase-resists-20-million-bitcoin-ransom-demand-after-insider-led-data-breach/#respond Thu, 15 May 2025 14:26:35 +0000 https://earlybirdsinvest.com/coinbase-resists-20-million-bitcoin-ransom-demand-after-insider-led-data-breach/

Coinbase revealed that it suffered a data breach that affected less than 1% of its active monthly users, according to the May 15 statement.

Following the hack, the exchange CEO Brian Armstrong said the perpetrators tried to extort it of $20 million in Bitcoin.

How Coinbase was breached

According to the exchange, the threat actors recruited and bribed a group of overseas support agents with access to its internal systems.

These insiders leaked sensitive data, which allowed the threat actors to impersonate Coinbase staff and carry out social engineering scams.

According to the firm, the compromised data included names, contact details, identity documents, and masked bank and social security information.

However, Coinbase stressed that its users’ login credentials, private keys, and core infrastructure, including Prime wallets, remained secure.

Meanwhile, the company has terminated the compromised insiders and vowed to pursue legal action against them. It is also working with law enforcement agencies to investigate the breach.

Coinbase further announced that it will compensate affected users.

The attackers attempted to extort $20 million from the firm following the breach. However, Coinbase rejected the demand, stating:

“We will not pay the $20 million ransom demand we received. Instead we are establishing a $20 million reward fund for information leading to the arrest and conviction of the criminals responsible for this attack.”

ZachXBT’s connection

While Coinbase has not confirmed any direct links, blockchain investigator ZachXBT noted that the breach aligns with previous social engineering attacks he has reported.

In a response to the Coinbase announcement, ZachXBT said:

“Indeed there’s a lot of Coinbase user thefts I posted tied to the group.”

Over recent months, ZachXBT has detailed how Coinbase users have collectively lost hundreds of millions of dollars to elaborate phishing and impersonation tactics. He estimated that such scams cost the exchange users more than $300 million yearly.

However, Wintermute CEO Evgeny Gaevoy believed the current rigid regulatory frameworks allowed these attacks to flourish.

According to him:

“This is the dark side of the idiotic and nonsensical kyc/aml regime we live in. Making life marginally convenient for law enforcement and geopolitical games, while sacrificing our privacy, imposing a massive tax on pretty much all businesses, and making it easier for criminals to rob, kidnap and do crime.”

Mentioned in this article
]]>
https://earlybirdsinvest.com/coinbase-resists-20-million-bitcoin-ransom-demand-after-insider-led-data-breach/feed/ 0 36372
LockBit Hacked: 60,000 Bitcoin Addresses and 4,400 Ransom Chats Go Public https://earlybirdsinvest.com/lockbit-hacked-60000-bitcoin-addresses-and-4400-ransom-chats-go-public/ https://earlybirdsinvest.com/lockbit-hacked-60000-bitcoin-addresses-and-4400-ransom-chats-go-public/#respond Fri, 09 May 2025 01:10:28 +0000 https://earlybirdsinvest.com/lockbit-hacked-60000-bitcoin-addresses-and-4400-ransom-chats-go-public/

Hackers managed to break into the LockBit ransomware group’s dark web affiliate site and publicly release a copy of its internal MySQL database, according to Bleeping Computer.

The files contained nearly 60,000 Bitcoin
BTC


$102,673.26

addresses, which experts believe are linked to the group’s ransom payments.

While no private keys were part of the leak, the exposed information could help blockchain investigators follow the trail of LockBit’s past transactions.

DEX vs CEX: Which is Best for YOU? (Explained with Animation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The leaked database contained twenty different tables. One, named “builds”, listed ransomware files created by LockBit’s partners, along with possible intended targets. Another, labeled “chats”, included more than 4,400 negotiation messages between the group and its victims.

These records showed conversations about ransom amounts, payment terms, and proof that stolen data would be deleted after a deal.

After the leak, an X user shared a conversation with an individual claiming to represent LockBit. The person confirmed that the group’s affiliate panel had been hacked but said that no private keys or critical data had been taken.

Analysts from BleepingComputer also pointed out that the message shown on LockBit’s hacked site was almost identical to one seen during a previous attack on the Everest ransomware group. This raised the idea that the same hacker, or a connected group, could be behind both incidents.

Meanwhile, Google Threat Intelligence reported a new malware called LOSTKEYS used by the hacking group COLDRIVER. How does the malware do? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/lockbit-hacked-60000-bitcoin-addresses-and-4400-ransom-chats-go-public/feed/ 0 35176
Fake BianLian ransom notes mailed to US CEOs in postal mail scam https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/ https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/#respond Wed, 05 Mar 2025 09:39:56 +0000 https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/

Hacker sending postal mail

Scammers are impersonating the BianLian ransomware gang in fake ransom notes sent to US companies via snail mail through the United States Postal Service.

The fake ransom notes were first reported by Guidepoint Security today, with BleepingComputer later being sent a scan of the note from a CEO who received the same letter.

The envelopes for these ransom notes claim to be from the “BIANLIAN Group” and have a return address located in an office building in Boston, Massachusets:

BIANLIAN GROUP
24 FEDERAL ST, SUITE 100
BOSTON, MA 02110

In the letter shared with BleepingComputer, the envelope shows it was mailed on February 25th, 2025. This mailing date is the same as the one seen by Arctic Wolf, who also reported on the scam today.

The letters are being mailed to the CEO of the companies at their corporate mailing address and show that they were processed through a postal facility in Boston, with the envelope marked, “Time Sensitive Read Immediately.”

Envelope for fake BianLian ransom  note
Envelope for fake BianLian ransom  note
Source: BleepingComputer

The envelopes contain a ransom note addressed to the company’s CEO or another executive, claiming to be from the BianLian ransomware operation. According to notes reviewed by BleepingComputer, they are tailored to the company’s industry, with different types of allegedly stolen data corresponding to the company’s activities.

For example, fake BianLian ransom notes sent to healthcare companies claim that patient and employee information was stolen, while those targeting product-based businesses allege the exposure of customer orders and employee data.

“I regret to inform you that we have gained access to [REDACTED] systems and over the past several weeks have exported thousands of data files, including customer order and contact information, employee information with IDs, SSNs, payroll reports, and other sensitive HR documents, company financial documents, legal documents, investor and shareholder information, invoices, and tax documents,” reads a fake BianLian ransom note.

Fake BianLian ransom note sent via snail mail
Fake BianLian ransom note sent via snail mail
Source: GuidePoint Security

The mailed ransom notes are very different from BianLian’s, but the scammers attempt to make them look convincing by including the real Tor data leak sites for the ransomware operation in the notes.

However, unlike typical ransomware demands, these fake notes state that BianLian is no longer negotiating with victims. Instead, the victim has 10 days to make a Bitcoin payment to prevent data from being leaked.

Each ransom note includes a ransom demand ranging between $250,000 and $500,000, a freshly generated Bitcoin address to send payment, and a QR code for the Bitcoin address.

Arctic Wolf said that all healthcare organizations had their ransom demand set to $350,000, which is the same as the one shared by a healthcare company with BleepingComputer, as shown below.

Payment information in fake BianLian ransom note
Payment information in fake BianLian ransom note
Source: BleepingComputer

Furthermore, Arctic Wolf states that two ransom notes the researchers saw included legitimate compromised passwords to add legitimacy to the demand.

“In at least two letters, the threat actor included a compromised password within the How did this happen? section, almost certainly in an attempt to add legitimacy to their claim.” explained Arctic Wolf.

The consensus in the reports is that these ransom notes are fake and are only designed to scare executives into paying a ransom, as there are no signs of an actual breach.

“While GRIT cannot confirm the identity of the letter’s authors at this time, we assess with a high level of confidence that the extortion demands contained within are illegitimate and do not originate from the BianLian ransomware group,” explains GuidePoint Security researcher Grayson North.

However, this does not mean the emails should be ignored. Due to the widespread mailing of these notes, all IT and security admins should notify executives about the scam so that they are aware and do not waste time and resources worrying about them.

These fake ransom notes are an evolution of the email extortion scams that have become so popular since 2018. However, instead of targeting personal emails, they are now targeting the CEOs of corporations.

BleepingComputer contacted the BianLian ransomware operation to see if they were involved with these mailings, but a reply was not immediately available.

]]>
https://earlybirdsinvest.com/fake-bianlian-ransom-notes-mailed-to-us-ceos-in-postal-mail-scam/feed/ 0 23363