Ukrainian authorities arrested a person suspected of administering the Russian-language cybercrime forum XSS.is in Kyiv on July 22, 2025, during an investigation led by French police and the Paris Prosecutor’s Office. French investigators were present and Europol supported the operation; the Paris Prosecutor’s Office announced it on July 23.
The arrest is an allegation, not a conviction. Public announcements do not identify the suspect by legal name, state final charges, or establish whether the wider XSS community has been permanently dismantled.
What authorities announced
Ukraine’s Cyber Department carried out the detention in Kyiv while working with French investigators. The participating bodies identified by Europol include the Paris Prosecutor’s Office and its cybercrime section, the Paris Police Prefecture’s cybercrime brigade, Ukraine’s Cyber Department, the Security Service of Ukraine, Ukraine’s General Prosecutor’s Office, and Europol’s European Cybercrime Centre and operational-support teams.
Europol’s role was coordination, analysis and operational support—not an independent arrest by a European police force. Because the detention occurred in Ukraine, questions about arrest procedure, searches, evidence handling and any later transfer or prosecution can involve Ukrainian as well as French processes.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Europol’s account says the suspect was the forum’s suspected administrator. The Paris Prosecutor’s Office statement, reproduced on its official LinkedIn account, refers to suspected offenses including complicity in attacks on automated data-processing systems, organized extortion and criminal conspiracy or association with criminal groups. Those descriptions concern an investigation; they are not findings of guilt.
What XSS was
Authorities described XSS.is as a major Russian-language cybercrime forum that had operated since 2013. Europol said it had more than 50,000 registered users. Registration is a measure of platform reach, not proof that every account holder committed a crime.
According to Europol, the forum provided an online marketplace and community for:
- malware sales;
- trading in stolen data;
- sales of access to compromised computer systems;
- ransomware-related services;
- recruitment, promotion and coordination; and
- dispute resolution and transaction facilitation.
That combination matters. A forum administrator can provide the trust and commercial infrastructure that lets many independent actors find one another, advertise services and settle disputes, even without personally carrying out every intrusion.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →The alleged administrator’s role and money
Investigators allege that the administrator moderated disputes, helped guarantee transactions, connected major threat actors and operated a related private communications service. Europol also said the suspect may have earned more than €7 million through advertising and facilitation fees.
The Paris prosecutor’s account, as reproduced in reporting, separately described at least $7 million in profits revealed by intercepted communications. The currencies and wording are different, so the figures should not be combined or treated as a single audited total.
Investigators also examined thesecure.biz, described as a private or encrypted messaging service used by cybercriminals. French investigators reportedly obtained judicial interceptions involving the service, and authorities said messages showed activity connected with cybercrime and ransomware. Public statements do not provide a legitimate reason to publish access instructions, credentials or technical details for that service.
How the investigation reached the arrest
- July 2, 2021: The Paris Prosecutor’s Office account says an initial investigation was opened.
- November 9, 2021: A formal judicial investigation began, according to that same account.
- September 2024: Europol says the case entered an operational phase in Ukraine. French and Ukrainian investigators worked together, while Europol established a virtual command post for information exchange and coordination.
- July 22, 2025: Ukrainian authorities arrested the suspected administrator in Kyiv with French investigators present.
- July 23, 2025: The Paris Prosecutor’s Office publicly announced the operation.
Europol said data seized during the operation would be analyzed for further investigations in Europe and beyond. That makes the evidence potentially more significant than the detention itself: messages, account records and financial information could help identify affiliates, brokers or victims in separate cases.
Rank #3
What is known about the suspect
The official announcements publicly identify only a suspected administrator or key figure. They do not provide a confirmed legal name, indictment, detention term, extradition decision, court ruling, defense response or conviction.
Le Monde reported that investigators associated the administrator with the pseudonym “Toha.” That nickname should remain attributed to the report; it was not included as a confirmed identity in Europol’s public summary.
Why targeting an administrator matters
Cybercrime forums operate as service economies. Their administrators can supply several layers that make illegal activity easier to organize:
Marketplace
Vendors can list malware, stolen information and access to compromised systems for prospective buyers.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteRank #4
Trust and enforcement
Moderation, reputation systems and dispute arbitration reduce the risk that participants will simply take payment and disappear.
Communications
Private messaging gives participants a channel to negotiate, recruit and coordinate outside public listings.
Revenue
Advertising, listing and facilitation fees turn the platform itself into a source of income for its operators.
Intelligence
Seized communications can expose relationships and transactions that are not visible from a single ransomware incident or malware sample.
Best Value
For those reasons, arresting an alleged infrastructure operator may disrupt trust and communications across a network. It does not automatically remove the people, malware or access that users already possess.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What happened to the website
SecurityWeek reported on July 25, 2025 that the XSS website displayed a seizure notice. A notice on a domain is not, by itself, proof that every server, account, backup or affiliated service has been seized.
The possible outcomes are broader than a website going offline:
- administrators and users may lose access or confidence;
- private messages and transaction records may become evidence;
- vendors and affiliates may move to other platforms;
- the community may fragment into smaller groups; and
- law-enforcement agencies may use recovered data in unrelated investigations.
Whether XSS disappeared permanently, whether users migrated, and how much infrastructure investigators controlled were not established by the initial public announcements.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat remains unresolved
- The suspect’s publicly confirmed legal identity.
- The precise charges filed in any jurisdiction.
- Any Ukrainian judicial ruling, detention order or French court action.
- Whether prosecutors will seek a transfer, extradition or prosecution in another country.
- The suspect’s legal representation or response.
- How much seized data can be authenticated and used in court.
- The long-term effect on XSS users and related cybercrime services.
The central distinction is important: this was a cross-border operation against a person authorities say helped run the infrastructure behind a large criminal marketplace. It may produce valuable intelligence and disrupt the forum’s trust mechanisms, but the public record from July 2025 does not establish a final conviction or the permanent disappearance of the wider cybercrime ecosystem.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




