Ukraine charges three over 610,000 stolen Roblox accounts sold to Russia at 80 cents each: the malware took session cookies, so passwords and 2FA never mattered
Prosecutors in Ukraine's Lviv region have sent three young men from the town of Drohobych to trial for stealing access to more than 610,000 Roblox accounts and selling them through Russian websites and Telegram channels, the Prosecutor General's Office said on 14 September. The organiser is 19; his two associates are 22. Between May 2025 and April 2026, according to the indictment, they infected players' computers with an information stealer disguised as cheats and free in-game bonuses, but what they took was not passwords. They took session cookies, the small files that keep a player logged in, and those opened the accounts without a password and without tripping two-factor authentication. Accounts went for about 70 roubles, roughly 80 US cents, each; investigators put the potential proceeds at more than 20 million hryvnias, about 480,000 dollars, and traced 2.4 million hryvnias laundered through crypto exchanges into the suspects' bank accounts. The maximum sentence is 12 years.
In brief
- The group never needed a victim's password. Their malware copied the browser's session token for Roblox; a checker program then tried each token, and where it still worked, tallied the account's Robux balance, rare items and collectibles to price it.
- The best accounts were sold one by one, the rest in bundles or at a discount, through a site on a Russian domain and Telegram channels, with payment to cryptocurrency wallets. Investigators found 357 files listing the "elite" accounts.
- Police arrested the three in April after ten searches in the Lviv region, seizing 37 phones, 11 desktops, 7 laptops, 5 tablets, about 32,000 dollars and 2,000 euros in cash; a 44-year-old acquaintance was charged separately over cannabis found during the raids.
- The lesson is the same one behind the fake GTA 6 download sites that empty saved passwords: a stolen session beats a strong password and a one-time code, and the only cure is to kill the session.
How the scheme worked
The organiser met his two accomplices on gaming forums in 2025, according to the National Police, and designed a multi-stage pipeline. Stage one was infection: software advertised as giving an edge in the game or free bonuses, which in reality was a stealer that harvested logins and, more importantly, cookies from the victim's browser. Stage two was verification: prosecutors describe a purpose-built program into which the stolen "keys" were loaded; it checked whether each still opened a Roblox profile and, if so, immediately calculated the account's worth, looking for game items, rare gear and virtual currency on the balance. Stage three was sorting and sale. Profiles with collectible items, limited inventory or a Robux balance bought with real money were kept in separate files, 357 of which investigators recovered, and sold individually; the rest went in bulk. Sales ran through a website with a Russian-registered domain and Telegram channels, payments arrived in crypto, and the crypto was converted to hryvnias and moved to the suspects' own bank accounts, which is the basis of the money-laundering charge. Roles were divided: the organiser assigned tasks, paid for servers, oversaw sales and split the proceeds; the two others ran the site and channels, talked to buyers and handled the money. The police said in April that "over several months" the malware reached more than 610,000 profiles; the indictment frames the operation as running from May 2025 to April 2026, when the arrests ended it.
Why a cookie beats a password and a code
When you log in to Roblox, or to almost any website, the server hands your browser a token and stores a copy; from then on the browser presents the token with every request and the server treats you as logged in. The password was checked once, at login. A two-factor code, if you have one, was also checked once, at login. The token is what proves you afterwards, and whoever holds the token is you, from any computer, in any country, until the token expires or is revoked. That is why the Drohobych group's checker did not need a single password: it loaded cookies and asked Roblox whether they still worked. It is also why the platform's own security advice, a long password and 2FA, did not protect the 610,000. Those measures guard the front door; a stealer walks in through a window that the victim opened by running a "free Robux" tool. The same mechanics drove the fake GTA 6 sites in August and the Vidar stealer they carried, and they are the reason our plain-language guide to two-factor codes puts session hygiene alongside the codes themselves. Roblox does offer the one control that matters here: in account settings, under Security, "Sign out of all other sessions" invalidates every token issued so far, including any that a stealer copied.
What a Roblox household should do
The victims of this scheme are mostly children and teenagers, because that is who plays Roblox and who is most likely to run a program promising free Robux. The practical steps are short. Anything that promises currency, items or an advantage in the game and asks to be downloaded and run is a stealer until proven otherwise; Roblox does not distribute cheats, and no legitimate bonus arrives as an executable. If such a program has ever been run on a computer, assume every session cookie in that browser is gone: change the Roblox password from a clean device, then use Sign out of all other sessions, then do the same for the email account tied to Roblox, since the stealer took its cookies too. Turn on two-factor authentication anyway, because it stops the password-only attackers who buy leaked credential lists. Check the account's trade history and inventory for items that left without a trade you recognise. And on shared family computers, give the child their own browser profile with no saved parent logins, so that a game cheat downloaded on a Saturday does not also carry off the household's banking session. The Drohobych operation sold accounts for 80 cents each; the reason it was worth doing at that price is that the malware did all the work, and the victims did the installing.
What are the three accused of?
How did they get into accounts without passwords?
How much did they make?
How do I know if my child's account was affected?
Does two-factor authentication help here?
• Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts - The Record
• На Львівщині судитимуть хакерів за крадіжку 610 тисяч акаунтів Roblox та продаж у РФ - RegioNews
• Продали викрадені ігрові акаунти на 10 млн грн: поліцейські Львівщини затримали хакерське угруповання - Національна поліція України
• Хакери з Дрогобича продали в Росію викрадені 600 тис. акаунтів популярної ігрової платформи - ZAXID.NET