Security News

Three Ukrainians Charged Over Mass Theft of 610,000 Roblox Accounts

The Record · 17 Sept 2026
Key Takeaway Be cautious of any third party tools promising game bonuses or advantages, as these are a common way attackers deliver malware that steals login credentials and session data.

Ukrainian law enforcement in the Lviv region has announced that three men will stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia. Prosecutors say a 19 year old organiser recruited two 22 year old associates, dividing tasks such as running servers, managing sales channels and handling payments.

The group is accused of distributing information stealing malware disguised as tools offering gaming advantages or free in game bonuses. Rather than stealing passwords, the malware captured session tokens (also known as cookies), which let attackers take over active accounts without needing to log in normally. Software was then used to check which tokens still worked and to assess the value of each account, including virtual currency and rare items.

According to investigators, the most valuable accounts were sold individually while less valuable ones were bundled and sold at a discount, advertised through Russian online platforms with payments made in cryptocurrency. The case began with an announcement in April, and Tuesday's update outlines further detail on how the operation was allegedly structured and run.

Roblox account takeover malware credential theft cybercrime

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.