{"id":95446,"date":"2026-03-21T07:00:00","date_gmt":"2026-03-21T04:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=95446"},"modified":"2026-03-21T07:02:11","modified_gmt":"2026-03-21T04:02:11","slug":"thai-crypto-billionaire-on-the-run-fbi-tokens-and-other-cybersecurity-highlights","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/thai-crypto-billionaire-on-the-run-fbi-tokens-and-other-cybersecurity-highlights\/","title":{"rendered":"Thai crypto billionaire on the run, \u2018FBI\u2019 tokens and other cybersecurity highlights"},"content":{"rendered":"<p>We have gathered the week\u2019s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>Thai investors accused the head of 1000X of a $42m fraud.<\/li>\n<li>Co-founder of a $1m crypto pyramid scheme detained in Kyiv.<\/li>\n<li>The FBI seized Iranian hackers\u2019 websites after a large-scale attack on the healthcare sector.<\/li>\n<li>Nordstrom customers targeted by a crypto scam.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\">Thai investors accuse 1000X boss of $42m fraud<\/h2>\n<p>Thai law enforcers are searching for billionaire and crypto-industry pioneer Worawat Narknawdee, <a href=\"https:\/\/world.thaipbs.or.th\/detail\/thai-bitcoin-tycoon-accused-in-bt13bn-investment-complaints\/60669\">Thai PBS<\/a> reports.<\/p>\n<p>A case was opened after users of the crypto platform <a href=\"https:\/\/forklog.com\/en\/news\/thailand-to-restrict-access-to-five-cryptocurrency-exchanges\">1000X<\/a> went to the police. The damage is estimated at roughly 1.39bn baht (~$42m at the time of writing). <\/p>\n<p>In March 2023, <span data-descr=\"Thailand\u2019s Securities and Exchange Commission\" class=\"old_tooltip\">SEC<\/span> <a href=\"https:\/\/www.sec.or.th\/EN\/Documents\/SEC-12-03-2026-2.pdf\">filed<\/a> a complaint with the Cyber Crime Investigation Bureau, accusing Narknawdee of running 1000X without a licence. According to media reports, before launching his crypto venture he was the lead singer of the rock band DoubleDeep, whose members were active investors. He later founded the Traderist community, where he offered free public education on handling cryptocurrencies.<\/p>\n<p>Through investments since 2012, the trader amassed about 11,000 BTC. His company ACET became one of the industry\u2019s fastest-growing.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"658\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-6aa2f1c231df6479-9255249652340579-1024x658.png\" alt=\"image\" class=\"wp-image-277167\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/img-6aa2f1c231df6479-9255249652340579-1024x658.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/img-6aa2f1c231df6479-9255249652340579-300x193.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/img-6aa2f1c231df6479-9255249652340579-768x494.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/img-6aa2f1c231df6479-9255249652340579.png 1282w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Worawat Narknawdee listed among Thailand\u2019s top five forex traders. Source: <a href=\"https:\/\/tradersunion.com\/interesting-articles\/richest-forex-traders-trading-secrets-life-stories\/in-thailand\/\">Traders Union<\/a>.<\/figcaption><\/figure>\n<p>However, data from the Department of Business Development revealed another side of his activities. According to <a href=\"https:\/\/creden.co\/\">Creden Data<\/a>, Narknawdee owns two companies: Bitnance Company (a loss of <span data-descr=\"~$920,000 at the time of writing\" class=\"old_tooltip\">~30m baht<\/span>) and Great Begins Company (a debt of <span data-descr=\"~$180,000 at the time of writing\" class=\"old_tooltip\">~5.8m baht<\/span>).<\/p>\n<p>Police say the billionaire fled to the UAE, where he owns property, a hotel business and other assets.<\/p>\n<h2 class=\"wp-block-heading\">Co-founder of $1m crypto pyramid detained in Kyiv<\/h2>\n<p>Ukrainian law enforcement uncovered a ring that appropriated funds under the guise of crypto investments. One of the scheme\u2019s co-founders was detained in Kyiv, <a href=\"https:\/\/cyberpolice.gov.ua\/news\/obiczyaly-prybutky-vid-kryptoinvestyczij-u-kyyevi-vykryly-odnogo-z-zasnovnykiv-finansovoyi-piramidy-2948\/\">reported<\/a> the Cyber Police.<\/p>\n<p>According to investigators, since 2022 the group built a network of financial pyramids across Ukraine. They urged citizens to invest in their own token, promising steady returns. In practice, payouts came from new investors and were distributed via pyramid or binary commission schemes.<\/p>\n<p>The founder and his spouse promoted the project on Instagram, with other bloggers amplifying the ads. Losses totalled about $1m.<\/p>\n<p>Police searched suspects\u2019 residences in Khmelnytskyi, Odesa, Chernihiv and Poltava regions, seizing computer equipment, notes and a car.<\/p>\n<p>One participant was notified of suspicion of fraud, an offence punishable by up to eight years in prison.<\/p>\n<h2 class=\"wp-block-heading\">FBI seizes Iranian hackers\u2019 websites after major attack on the healthcare sector<\/h2>\n<p>The FBI seized two websites used by the hacktivist group Handala after a destructive cyberattack on medtech giant Stryker, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fbi-seizes-handala-data-leak-site-after-stryker-cyberattack\/\">reports<\/a> BleepingComputer.<\/p>\n<p>There has been no official statement from law enforcement about the seizures. However, the domains\u2019 DNS servers were switched to those the FBI typically uses when taking sites offline.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/forklog.com\/wp-content\/uploads\/img-e57f5cb275dc43f6-9255249146061169-1024x576.png\" alt=\"image\" class=\"wp-image-277166\" srcset=\"https:\/\/forklog.com\/wp-content\/uploads\/img-e57f5cb275dc43f6-9255249146061169-1024x576.png 1024w, https:\/\/forklog.com\/wp-content\/uploads\/img-e57f5cb275dc43f6-9255249146061169-300x169.png 300w, https:\/\/forklog.com\/wp-content\/uploads\/img-e57f5cb275dc43f6-9255249146061169-768x432.png 768w, https:\/\/forklog.com\/wp-content\/uploads\/img-e57f5cb275dc43f6-9255249146061169.png 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">FBI \u2018splash page\u2019 on one of Handala\u2019s sites. Source: BleepingComputer.<\/figcaption><\/figure>\n<p>Media say Handala (also known as Handala Hack Team, Hatef, Hamsa) is an Iran-linked hacktivist group that emerged in December 2023. Its operations are associated with the country\u2019s Ministry of Intelligence and Security. It has targeted Israeli organisations using wiper malware for Windows and Linux.<\/p>\n<p>The takedowns followed a mass attack by Handala on March 11th 2026. The hackers compromised a Windows domain administrator account and factory-reset about 80,000 devices, including employees\u2019 PCs and mobile phones. The attackers claimed to have stolen 50 terabytes of data before wiping.<\/p>\n<p>After the incident, <span data-descr=\"US Cybersecurity and Infrastructure Security Agency\" class=\"old_tooltip\">CISA<\/span> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-warns-businesses-to-secure-microsoft-intune-systems-after-stryker-breach\/\">urged<\/a> US organisations to follow Microsoft\u2019s updated <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/intunecustomersuccess\/best-practices-for-securing-microsoft-intune\/4502117\">guidance<\/a> to harden defences.<\/p>\n<h2 class=\"wp-block-heading\">Nordstrom customers hit by crypto scam<\/h2>\n<p>In the US, customers of high-end fashion department store chain Nordstrom received scam emails offering to double their crypto-wallet balances, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/nordstroms-email-system-abused-to-send-crypto-scams-to-customers\/\">reports<\/a> BleepingComputer.<\/p>\n<p>Emails promised a 200% return on any cryptocurrency sent to a listed bitcoin address. Victims were given two hours to decide \u2014 a ploy to create urgency. <\/p>\n<p>The messages appeared to originate from an official sender the company uses for marketing, indicating a security breach. Some customers said the email reached an address that had never been disclosed or leaked online. <\/p>\n<p>As of March 18th, more than $5,600 had been sent to the scammers in cryptocurrency. According to a <a href=\"https:\/\/www.blockexplorer.com\/bitcoin\/address\/bc1qzgr05099cay453cetdd9jd3z5u5g2pp0e5qtdh\">blockchain explorer<\/a>, on March 20th the wallet held just 0.00001386 BTC.<\/p>\n<h2 class=\"wp-block-heading\">Scammers airdropped TRC-20 tokens posing as the FBI<\/h2>\n<p>On March 19th the FBI warned crypto investors about a new phishing scheme in which scammers, posing as the agency, distributed fake tokens.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">FBI New York encourages users of the Tron blockchain network to exercise caution if they encounter a token purported to be from the FBI. If you receive a token from an account with the details below, do not provide any identifying information to any website associated with such\u2026 <a href=\"https:\/\/t.co\/VF03sjM4VW\">pic.twitter.com\/VF03sjM4VW<\/a><\/p>\n<p>\u2014 FBI New York (@NewYorkFBI) <a href=\"https:\/\/twitter.com\/NewYorkFBI\/status\/2034676756469154236?ref_src=twsrc%5Etfw\">March 19, 2026<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Unknown <a href=\"https:\/\/forklog.com\/en\/news\/what-is-tron-trx\">TRC-20<\/a> tokens labelled \u201cFBI tokens\u201d landed in users\u2019 wallets, followed by ultimatum messages. The scammers alleged the owner was suspected of money laundering and threatened to freeze assets. To \u201cavoid a block,\u201d victims were told to visit a third-party site for an <span data-descr=\"anti-money-laundering\" class=\"old_tooltip\">AML<\/span> check and to disclose personal data.<\/p>\n<p>The number of victims is being determined.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Average losses from hacks in the crypto industry <a href=\"https:\/\/forklog.com\/en\/news\/average-loss-from-crypto-hacks-reaches-25-million\">hit<\/a> $25m.<\/li>\n<li>Hype around OpenClaw <a href=\"https:\/\/forklog.com\/en\/news\/openclaw-hype-triggers-phishing-attacks-on-crypto-wallets\">sparked<\/a> a wave of phishing attacks on crypto wallets.<\/li>\n<li>The Lazarus group <a href=\"https:\/\/forklog.com\/en\/news\/lazarus-group-suspected-in-bitrefill-cyberattack\">is suspected<\/a> of attacking the Bitrefill service.<\/li>\n<li>Venus Protocol <a href=\"https:\/\/forklog.com\/en\/news\/venus-protocol-loses-2-million-due-to-token-the-manipulation\">lost<\/a> $2m due to manipulation of the THE token.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">What to read this weekend?<\/h2>\n<p>In a new feature, ForkLog explains why it is perfectly fine to stay away from gadgets and the internet.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have gathered the week\u2019s most important cybersecurity news.<\/p>\n","protected":false},"author":1,"featured_media":95447,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"This week\u2019s top cybersecurity: 1000X scandal, FBI seizures, Nordstrom scam, fake \u2018FBI\u2019 tokens.","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-95446","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"140","promo_type":"1","layout_type":"1","short_excerpt":"This week\u2019s top cybersecurity: 1000X scandal, FBI seizures, Nordstrom scam, fake \u2018FBI\u2019 tokens.","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/95446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=95446"}],"version-history":[{"count":1,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/95446\/revisions"}],"predecessor-version":[{"id":95448,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/95446\/revisions\/95448"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/95447"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=95446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=95446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=95446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}