U.S. Treasury sanctions Russian network for crypto-funded cyber tool theft

The U.S. Department of the Treasury has sanctioned a Russian exploit brokerage network accused of buying stolen U.S. government cyber tools with cryptocurrency and reselling them. This marks the first use of authorities under the Protecting American Intellectual Property Act. The network, led by Sergey Sergeyevich Zelenyuk, obtained at least eight proprietary tools from a U.S. defense contractor.

On February 24, 2026, the U.S. Treasury's Office of Foreign Assets Control announced sanctions against Sergey Sergeyevich Zelenyuk, his company Operation Zero, and several associates. Zelenyuk, based in St. Petersburg, Russia, is accused of building a business that acquires and sells exploits—tools exploiting software vulnerabilities for unauthorized access or data extraction.

The sanctioned tools include at least eight proprietary cyber tools developed by a U.S. defense contractor for exclusive use by the U.S. government and select allies. These were stolen by Peter Williams, an Australian national and former employee of the contractor. According to the Department of Justice, Williams stole the trade secrets between 2022 and 2025 and sold them to Operation Zero for millions of dollars in cryptocurrency. Williams pleaded guilty in October 2025 to two counts of theft of trade secrets following an investigation by the Justice Department and the Federal Bureau of Investigation.

The sanctions block any property or interests in property of the designated parties under U.S. jurisdiction and prohibit U.S. persons from transacting with them. They were issued under Executive Order 13694, targeting malicious cyber-enabled activities, and the Protecting American Intellectual Property Act, which addresses significant theft of U.S. trade secrets posing national security or economic threats. Zelenyuk and Operation Zero are the first sanctioned under this act.

Associates designated include Marina Evgenyevna Vasanovich, Zelenyuk's assistant; Special Technology Services LLC FZ, a United Arab Emirates-based firm controlled by Zelenyuk; Azizjon Makhmudovich Mamashoyev; and Oleg Vyacheslavovich Kucherov, suspected member of the Trickbot cybercrime group linked to ransomware attacks on U.S. agencies and healthcare providers.

Operation Zero advertised bounties worth millions in cryptocurrency for exploits targeting U.S.-built operating systems and encrypted messaging platforms. The firm did not disclose vulnerabilities to software companies and instead sold them to customers in non-NATO countries, including foreign intelligence services. It also sought to recruit hackers and develop ties with foreign intelligence via social media.

Treasury Secretary Scott Bessent stated, “If you steal U.S. trade secrets, we will hold you accountable.” He added that the designations reflect efforts to protect American intellectual property and national security, working alongside the Trump Administration.

Awọn iroyin ti o ni ibatan

President Trump announces Cyber Strategy for America at White House podium, with blockchain, AI, and quantum visuals on screen.
Àwòrán tí AI ṣe

Trump administration's cyber strategy backs security of cryptocurrencies and blockchain

Ti AI ṣe iroyin Àwòrán tí AI ṣe

The Trump administration released its 'Cyber Strategy for America' on March 7, 2026, explicitly supporting the security of cryptocurrencies and blockchain technologies for the first time. It positions blockchain alongside AI and quantum computing as critical to U.S. technological leadership, aligning with President Trump's pro-crypto policies.

The Office of Foreign Assets Control (OFAC) of the U.S. Treasury Department sanctioned six people on April 14 linked to a money laundering and cash smuggling network operated by the Northeast Cartel. Among those sanctioned is lawyer Juan Pablo Penilla Rodríguez, connected to Miguel Ángel “Z-40” Treviño Morales. Two casinos used for illicit activities in Tamaulipas were also targeted.

Ti AI ṣe iroyin

Treasury Secretary Scott Bessent has launched Operation Economic Fury, a campaign targeting Iran's illicit oil networks and terror financiers with new sanctions. The US Office of Foreign Assets Control sanctioned more than two dozen individuals, companies, and vessels, including the network of Mohammad Hossein Shamkhani. The measures include warnings of secondary sanctions and the non-renewal of oil purchase licenses expiring April 19.

Experts from blockchain intelligence firm NOMINIS.io have revealed how Iran's regime employs cryptocurrencies to evade Western sanctions, funding proxy groups in the region. By selling oil to Russia and China for digital payments, Iran maintains economic flows despite restrictions. This network also facilitates activities like espionage, as seen in a recent Israeli indictment.

Ti AI ṣe iroyin

A group of seven Russians is accused of robbing a crypto blogger of $42,000 in cryptocurrency, along with cash and luxury watches, in a violent home invasion. Prosecutors say the suspects could face up to 15 years in prison for the organized crime. The incident highlights a rising trend of attacks on cryptocurrency holders in Russia.

Treasury Secretary Scott Bessent appeared on CNBC on Monday to address rising oil prices amid tensions with Iran. He outlined the administration's strategy to neutralize Iran's military capabilities and manage global oil supply disruptions. Bessent also defended a temporary waiver on Russian oil sanctions.

Ti AI ṣe iroyin

New York prosecutors have warned that the GENIUS Act, a new law regulating stablecoins, fails to protect fraud victims and allows issuers to profit from stolen funds. In a letter to key senators, Attorney General Letitia James and District Attorney Alvin Bragg argue the legislation provides legal cover to companies like Tether and Circle. They claim these firms resist returning seized assets, prioritizing their own financial gains.

 

 

 

Ojú-ìwé yìí nlo kuki

A nlo kuki fun itupalẹ lati mu ilọsiwaju wa. Ka ìlànà àṣírí wa fun alaye siwaju sii.
Kọ