Two men accused of administering WWH Club, a Russian-language cybercrime marketplace and training forum, were arrested in 2024 after investigators connected online aliases, cloud-hosting records, cryptocurrency transactions and conspicuous spending to them. The defendants were later indicted, but the allegations had not been proven in court. The case also did not immediately eliminate WWH Club: contemporaneous reporting said the platform remained online after the arrests.
Who was arrested?
The defendants were Pavel Kublitskii, described by the U.S. Department of Justice as a 37-year-old Russian national, and Alex Khodyrev, a 35-year-old Kazakhstan national. Some early reports rendered Khodyrev’s name as “Alexandr Khodyrev”; these references concern the same defendant.
According to the Justice Department and the FBI affidavit, the men had arrived in the United States in 2022, sought asylum and listed the same Hollywood, Florida address. Authorities alleged that they held significant administrative roles in WWH Club and related sites.
The early August 2024 coverage was uncertain about Khodyrev’s arrest. The later Justice Department announcement said that both men had been arrested and indicted. That later official account is the appropriate basis for describing both as defendants in the case.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- The PBN-TEC Digital Investigation Kit is a comprehensive eight-tool investigation system trusted by law enforcement agencies, private investigators, IT security professionals, legal teams, and even concerned parents. One kit covers mobile device extraction, computer investigations, evidence collection, illicit content detection, audio monitoring, and secure file deletion — no additional software purchases required.
- The iRecovery Stick extracts and investigates data from iPhone and iPad devices, the Phone Recovery Stick handles Android phones and tablets, and the SIM Card Seizure analyzes data from virtually any GSM SIM card. Together these three tools provide complete mobile device investigation coverage from a single kit, including contacts, messages, call logs, and photos.
- The Data Recovery Stick recovers deleted files from any Windows OS, the Voice Logger installs an audio monitoring application onto any Windows computer, and the Data Shredder Stick securely deletes files and wipes storage when the investigation is complete. All three tools work on Windows XP or newer with no additional software required.
- The Capturra Action Drive 1TB automatically collects targeted file types from virtually any device, serving as both an evidence storage drive and a targeted file collection tool for focused investigations. The XXX Detection Stick then scans the collected evidence for illicit content, categorizing results into Low Suspect, Suspect, and Highly Suspect for review.
- The Digital Investigation Kit includes everything needed to begin an investigation immediately — a Data Cable Kit with iPhone, USB-C, and Micro USB cables, a universal SIM Card Adapter compatible with all SIM card sizes, and a Softshell Compartmentalized Protection Case to organize and transport all eight tools securely.
What was WWH Club?
WWH Club was described by prosecutors as part of a broader Russian-language cybercrime ecosystem, rather than simply a message board. The associated sites named in the case were:
- WWH Club
- Skynetzone
- Opencard
- Center-Club
Authorities alleged that the sites operated as marketplaces, discussion forums and training centers. Their alleged offerings included stolen personal information, payment-card and bank-account data, passwords, malware, fraudulent documents and instruction for carrying out online fraud.
The alleged business model also included membership fees, paid courses and advertising. The Justice Department said WWH Club had approximately 353,000 users worldwide in 2023. That figure should not be interpreted to mean that every registered user was an administrator or confirmed criminal participant.
The FBI affidavit linked the username “Makein” to the alleged administrators and described that account as the owner and primary administrator of Skynetzone. That identity link was investigative evidence, not a fact established by a conviction.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhy did investigators focus on their spending?
The case attracted attention because the men appeared to have substantial resources without an obvious legitimate source of income. Reporting based on the affidavit described:
- An approximately $50,000 cash deposit by Kublitskii into a Bank of America account.
- Luxury housing in South Florida.
- Khodyrev’s purchase of a 2023 Chevrolet Corvette for about $110,000 in cash.
The later indictment also sought forfeiture of Khodyrev’s 2023 Mercedes-Benz G63 AMG and Kublitskii’s 2020 Cadillac CT5 Sport sedan, alleging that the vehicles were traceable to criminal proceeds.
That spending was a financial lead and part of the probable-cause picture, not necessarily the sole reason for the arrests. The broader case involved undercover activity, infrastructure records, account data, emails, domain registrations and cryptocurrency analysis.
What did the undercover investigation find?
As described in the FBI criminal complaint and affidavit, an undercover FBI employee registered for WWH training and paid approximately $1,000 in Bitcoin for a course.
Rank #3
The undercover investigation also encountered listings for stolen U.S. personal information. The agent purchased a data package containing sensitive identity and financial fields. The affidavit said investigators believed some account information was connected to a February 2022 LendingTree breach that affected more than 200,000 customers.
That LendingTree connection was an investigative conclusion reported in the affidavit, not necessarily a final judicial finding. The sensitive data is not reproduced here because doing so could facilitate identity theft or account fraud.
How were the alleged administrators identified?
The FBI’s account describes a cumulative digital investigation. It did not depend on a single IP address or one isolated clue. Investigators allegedly combined:
- Server and IP information obtained through a search warrant served on hosting provider DigitalOcean.
- Domain-registration records.
- Email and Google records that allegedly contained stolen personal and payment-card information.
- Bitcoin and BitPay transaction records.
- Blockchain analysis connecting financial activity.
- Online aliases, photographs, identity records and related account information.
- Evidence linking the “Makein” administrator account to both defendants.
This combination illustrates how investigators can connect pseudonymous online activity to real-world identities by following infrastructure, money and account-reuse patterns together.
Rank #4
- The Cellphone Investigation Kit is a complete solution for accessing and preserving data from virtually any mobile device. One kit covers iPhones, Android phones, GSM SIM cards, and photo backup — giving investigators, IT professionals, and parents everything they need in a single package.
- The included iRecovery Stick accesses data directly from iPhones and iPads running up to iOS 26.x, pulling contacts, text messages, call logs, saved passwords, WiFi networks, photos, the Deleted Photos folder, and more. Runs entirely on your Windows PC — no software is installed on the target device and no trace is left behind.
- The Phone Recovery Stick analyzes Android devices, recovering contacts, messages, photos, call logs, and more from a wide range of Android smartphones and tablets. Connect the target Android device to your Windows PC alongside the stick to begin extraction and data analysis.
- The SIM Card Seizure reader pulls data stored directly on GSM SIM cards, including contacts, SMS messages, call history, carrier information, and SIM serial numbers. Compatible with SIM cards from any carrier — including older flip phones and prepaid devices — making it essential for cases involving old phones that store data on SIM cards.
- The Photo Backup Stick completes the kit with fast photo and video backup from phones, tablets, and even computers, preserving visual evidence without requiring a PC or special software. All four tools work together to give you comprehensive mobile device coverage from a single professional investigation kit.
What charges did they face?
August 2024 criminal complaint
The initial complaint alleged:
- Conspiracy to traffic in unauthorized access devices under 18 U.S.C. §§ 371 and 1029(a)(2).
- Conspiracy to possess 15 or more unauthorized access devices under 18 U.S.C. §§ 371 and 1029(a)(3).
A criminal complaint starts a prosecution based on probable cause. It is not a finding of guilt.
September 6, 2024 indictment
The Justice Department later announced an indictment charging both men with:
- Conspiracy to commit access-device fraud.
- Conspiracy to commit wire fraud.
The department said each defendant faced a maximum possible sentence of up to 20 years in federal prison if convicted. That is a statutory maximum, not a prediction of the sentence either person would receive. Both defendants were presumed innocent unless and until proven guilty.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Was WWH Club taken offline?
Not completely, based on contemporaneous 2024 reporting. Malwarebytes and Recorded Future News reported that the forum remained operational after the arrests. Other administrators reportedly acknowledged the defendants’ involvement while attempting to characterize them as moderators or distance the wider operation from them.
Best Value
This does not establish the platform’s status in 2026. It does show that arresting alleged administrators did not immediately amount to a full shutdown. The researched sources do not establish a final disposition of the criminal case or prove that the entire network was dismantled.
Why the case matters for consumers and businesses
The allegations show how cybercrime forums can function like diversified businesses. They may combine data sales with training, advertising and membership revenue, creating several income streams rather than relying on one marketplace.
The case also demonstrates why identity data remains valuable after a breach. Stolen information can support identity theft, account takeover, synthetic identities and targeted phishing. Consumers who believe their information may have been exposed should consider placing a credit freeze with the three major credit bureaus, monitoring financial accounts, changing reused passwords, enabling multifactor authentication and reporting suspected identity theft through official government channels.
Finally, the investigation highlights the value of financial tracing. Visible cash purchases and luxury assets may attract attention, but the alleged case against Kublitskii and Khodyrev rested on a much wider body of digital and financial evidence. The continued operation reported after the arrests also suggests—by inference—that removing prominent administrators does not necessarily remove the underlying user base, infrastructure or criminal market.
What remains unknown
The cited sources do not establish whether either defendant was ultimately convicted, sentenced or acquitted. They establish an August 2024 complaint, a September 6, 2024 indictment and allegations about the defendants’ roles and assets. Those procedural facts should not be confused with proof that the allegations were true.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




