Ukraine charges three over 610,000 stolen Roblox accounts sold to Russia at 80 cents each: the malware took session cookies, so passwords and 2FA never mattered

16.09.2026 8 min 25

Prosecutors in Ukraine's Lviv region have sent three young men from the town of Drohobych to trial for stealing access to more than 610,000 Roblox accounts and selling them through Russian websites and Telegram channels, the Prosecutor General's Office said on 14 September. The organiser is 19; his two associates are 22. Between May 2025 and April 2026, according to the indictment, they infected players' computers with an information stealer disguised as cheats and free in-game bonuses, but what they took was not passwords. They took session cookies, the small files that keep a player logged in, and those opened the accounts without a password and without tripping two-factor authentication. Accounts went for about 70 roubles, roughly 80 US cents, each; investigators put the potential proceeds at more than 20 million hryvnias, about 480,000 dollars, and traced 2.4 million hryvnias laundered through crypto exchanges into the suspects' bank accounts. The maximum sentence is 12 years.

In brief

  • The group never needed a victim's password. Their malware copied the browser's session token for Roblox; a checker program then tried each token, and where it still worked, tallied the account's Robux balance, rare items and collectibles to price it.
  • The best accounts were sold one by one, the rest in bundles or at a discount, through a site on a Russian domain and Telegram channels, with payment to cryptocurrency wallets. Investigators found 357 files listing the "elite" accounts.
  • Police arrested the three in April after ten searches in the Lviv region, seizing 37 phones, 11 desktops, 7 laptops, 5 tablets, about 32,000 dollars and 2,000 euros in cash; a 44-year-old acquaintance was charged separately over cannabis found during the raids.
  • The lesson is the same one behind the fake GTA 6 download sites that empty saved passwords: a stolen session beats a strong password and a one-time code, and the only cure is to kill the session.

How the scheme worked

The organiser met his two accomplices on gaming forums in 2025, according to the National Police, and designed a multi-stage pipeline. Stage one was infection: software advertised as giving an edge in the game or free bonuses, which in reality was a stealer that harvested logins and, more importantly, cookies from the victim's browser. Stage two was verification: prosecutors describe a purpose-built program into which the stolen "keys" were loaded; it checked whether each still opened a Roblox profile and, if so, immediately calculated the account's worth, looking for game items, rare gear and virtual currency on the balance. Stage three was sorting and sale. Profiles with collectible items, limited inventory or a Robux balance bought with real money were kept in separate files, 357 of which investigators recovered, and sold individually; the rest went in bulk. Sales ran through a website with a Russian-registered domain and Telegram channels, payments arrived in crypto, and the crypto was converted to hryvnias and moved to the suspects' own bank accounts, which is the basis of the money-laundering charge. Roles were divided: the organiser assigned tasks, paid for servers, oversaw sales and split the proceeds; the two others ran the site and channels, talked to buyers and handled the money. The police said in April that "over several months" the malware reached more than 610,000 profiles; the indictment frames the operation as running from May 2025 to April 2026, when the arrests ended it.

610,000+Roblox accounts whose session data the group obtained, according to the indictment
70 ₽price of a single account on the Russian resale sites, about 80 US cents
$480,000estimated potential proceeds (over 20 million hryvnias); 2.4 million hryvnias traced as laundered
12 yearsmaximum sentence on the charges of theft, money laundering, unauthorised interference and sale of restricted information

Why a cookie beats a password and a code

When you log in to Roblox, or to almost any website, the server hands your browser a token and stores a copy; from then on the browser presents the token with every request and the server treats you as logged in. The password was checked once, at login. A two-factor code, if you have one, was also checked once, at login. The token is what proves you afterwards, and whoever holds the token is you, from any computer, in any country, until the token expires or is revoked. That is why the Drohobych group's checker did not need a single password: it loaded cookies and asked Roblox whether they still worked. It is also why the platform's own security advice, a long password and 2FA, did not protect the 610,000. Those measures guard the front door; a stealer walks in through a window that the victim opened by running a "free Robux" tool. The same mechanics drove the fake GTA 6 sites in August and the Vidar stealer they carried, and they are the reason our plain-language guide to two-factor codes puts session hygiene alongside the codes themselves. Roblox does offer the one control that matters here: in account settings, under Security, "Sign out of all other sessions" invalidates every token issued so far, including any that a stealer copied.

What is not confirmed: the number of victims by country is not given; police said in April that both Ukrainian and foreign players were affected. The April statements described the scanning window as October 2025 to January 2026 and the potential proceeds as almost 10 million hryvnias; the indictment widens the period to May 2025 to April 2026 and doubles the estimate to over 20 million, without explaining the revision. Roblox has not commented. The 610,000 figure counts accounts whose data the group obtained, not accounts confirmed sold.

What a Roblox household should do

The victims of this scheme are mostly children and teenagers, because that is who plays Roblox and who is most likely to run a program promising free Robux. The practical steps are short. Anything that promises currency, items or an advantage in the game and asks to be downloaded and run is a stealer until proven otherwise; Roblox does not distribute cheats, and no legitimate bonus arrives as an executable. If such a program has ever been run on a computer, assume every session cookie in that browser is gone: change the Roblox password from a clean device, then use Sign out of all other sessions, then do the same for the email account tied to Roblox, since the stealer took its cookies too. Turn on two-factor authentication anyway, because it stops the password-only attackers who buy leaked credential lists. Check the account's trade history and inventory for items that left without a trade you recognise. And on shared family computers, give the child their own browser profile with no saved parent logins, so that a game cheat downloaded on a Saturday does not also carry off the household's banking session. The Drohobych operation sold accounts for 80 cents each; the reason it was worth doing at that price is that the malware did all the work, and the victims did the installing.

What are the three accused of?
Stealing session data for more than 610,000 Roblox accounts between May 2025 and April 2026 with an information stealer, checking and pricing the accounts with custom software, selling them through Russian sites and Telegram for cryptocurrency, and laundering the proceeds. Charges include theft, money laundering, unauthorised interference with computer systems and sale of restricted information; the maximum sentence is 12 years.
How did they get into accounts without passwords?
The stealer copied session cookies from victims' browsers. A cookie proves to Roblox that the user already logged in, so it opens the account without the password and without a two-factor prompt, until the session is revoked or expires.
How much did they make?
Accounts sold for about 70 roubles each. Investigators estimate potential proceeds above 20 million hryvnias, roughly 480,000 dollars, and traced 2.4 million hryvnias converted from crypto into the suspects' bank accounts. Police seized about 32,000 dollars and 2,000 euros in cash during the April searches.
How do I know if my child's account was affected?
There is no public victim list. Warning signs are missing Robux or items, trades you do not recognise, login alerts from unfamiliar locations, and any "free Robux" or cheat program having been run on the computer. If in doubt, change the password from a clean device and sign out all other sessions.
Does two-factor authentication help here?
Not against a stolen session, which is checked after the code has already been entered. It still blocks attackers who only have a password from a leak, so keep it on, but pair it with never running unknown executables and with signing out of all sessions after any suspected infection.

ukrainerobloxaccount theftinfostealersession cookiesrussiacybercrimegamingchildrenmalwaretwo-factor authenticationcryptocurrencymoney launderingcybersecurity

Read also