Hacker NewsInternational NewsNewsOther VideosVideos

U.S. Charges Curitiba Hacker Junior Barros De Oliveira With Extorting $3.2 Million in Bitcoin After a 300,000-Record Breach

A Newark grand jury did not need a mugshot to sign an indictment. On December 23, 2024, the U.S. Attorney’s Office for the District of New Jersey unsealed charges against Junior Barros De Oliveira, then 29, of Curitiba, Brazil. Prosecutors say he broke into the Brazilian subsidiary of a New Jersey company in March 2020, pulled confidential records on about 300,000 customers, and spent the next months turning that pile into a bitcoin invoice. The first ask, sent to the company’s chief executive under an alias, was about 300 bitcoin — roughly $3.2 million at then-prices — to keep the data off the market. The follow-up pitch was friendlier on paper: 75 bitcoin, about $800,000, to « help » patch the hole he had used.

The indictment lists four counts of extortionate threats involving information from protected computers, 18 U.S.C. § 1030(a)(7)(B), and four counts of threatening communications, 18 U.S.C. § 875(d). Each 1030 count carries up to five years and a $250,000 fine, or twice the gain or loss. Each 875 count carries up to two years and the same fine math. U.S. Attorney Philip R. Sellinger announced the case. Assistant U.S. Attorney David E. Malagold is on the caption. Through September 2026 the Justice Department has not announced a U.S. arrest, a Brazilian detention memo, a plea, or a trial date. The AEGIS Alliance is keeping the presumption of innocence on this page because a charging sheet is not a conviction, and because an indictment sitting in Newark does not move a defendant sitting in Paraná by itself.

Stylized image used by The AEGIS Alliance to illustrate the Curitiba bitcoin-extortion indictment unsealed in Newark.
The company is unnamed in the public release. The bitcoin amounts are not.

A 2020 intrusion that waited four years for a courtroom

According to the Justice Department, De Oliveira gained unauthorized access, and exceeded authorized access, to the systems of « Victim 1-Brazil » in March 2020. He did it more than once. Prosecutors say the stolen material covered about 300,000 customers and came out across at least three intrusions. In September 2020 he began emailing U.S. representatives of the parent company, including the CEO, with a demand: pay in bitcoin or watch the file go public.

The Hacker News, SC Media, Security Affairs, and Bitdefender all reconstructed the same charging narrative. After the $3.2 million demand, the defendant allegedly offered a consulting-fee version of the same crime — 75 bitcoin to « solve the security flaw, » with wallet instructions attached. That second email is the tell. Extortionists who stay in character as thieves keep asking for silence money. Extortionists who rebrand as vendors ask for a fee to fix the door they kicked. Both asks are still threats under § 1030(a)(7)(B) if the government can prove the data came from a protected computer and the demand was tied to a threat to publish.

The victim company is not named. That is standard when the records are customer files and the parent sits in New Jersey. Naming the firm would republish the leak before a jury exists. Readers should treat every blog that claims to have identified the subsidiary as a guess until the firm puts its own incident letter on a homepage. The AEGIS Alliance will not launder a guess into a caption.

Why an unsealed indictment is not an extradition

Brazil does not ship every national to Newark because a grand jury voted. Extradition is a diplomatic and judicial process with its own defenses, including nationality arguments and dual-criminality fights. An indictment can sit for years while attachés write notes that never become a flight. That is the most likely reason this file has not grown a mugshot. It is also why cybercrime charging announcements often look louder than the docket that follows them.

The timing is the other puzzle. The intrusion is dated March 2020. The first demand is dated September 2020. The unsealing is dated December 23, 2024. Four years is a long stretch for a bitcoin-extortion case unless agents were tracing wallets, waiting on mutual legal assistance, or building a sealed complaint until they thought they could survive a motion to dismiss. The public release does not explain the gap. It does not say whether any bitcoin moved. It does not say whether the 300,000-record file ever landed on a leak site. Absence of those sentences is not proof the data stayed dark. It is proof the government did not want those facts in a press release.

Maximums on the page are stacking math, not a predicted sentence. Eight counts do not automatically become 28 years. Federal judges group overlapping threats. A first-time defendant who eventually appears and pleads often sees a guideline range far under the theoretical ceiling. None of that math matters until there is a body in a courtroom. Right now there is a PDF.

The product called data extortion

This case is not ransomware in the classic sense. The charging language is publish-or-pay, the older cousin of the double-extortion model crews later industrialized. No mention is made of encrypting the victim’s servers. The leverage is the customer file and the CEO’s inbox. That model scaled during the pandemic years because remote access was messy and bitcoin rails were liquid. Curitiba to Newark is a short sentence on a map and a long sentence in a mutual-legal-assistance treaty.

Readers of this desk have watched other cross-border computer cases stall in the same way. A charging headline travels. The defendant does not. The Hacker News file on this site exists for that gap. So does the NGate NFC-relay write-up, which is a different toolset aimed at a similar motive: turn access into money without standing in a bank lobby. The Brazilian indictment is older in method and simpler in plot. Steal the list. Price the list. Offer a discount dressed as consulting.

Bitcoin at 2020 prices is not bitcoin at 2026 prices. Three hundred coins meant about $3.2 million when the first email went out. The same stack is a different headline now. Charging documents freeze the number at the time of the demand because that is the alleged loss theory. Anyone rewriting the ask at current spot prices is doing market commentary, not criminal law.

What the public still does not have

There is no photograph of De Oliveira in the DOJ package. There is no wallet address in the press release. There is no victim-notification letter from a named New Jersey parent company that The AEGIS Alliance can match to the caption. There is no PACER minute entry widely reported as an arraignment. Those missing pieces are the story now. An indictment without a defendant is a bookmark.

That does not make the charges theater. Grand juries hear agents. Agents dump logs. Logs show logins. The March 2020 access window sits inside the first months of a global work-from-home scramble, which is exactly when a lot of subsidiaries learned that « authorized access » had become a slogan. If the government ever walks this case into a Newark courtroom, the exhibits will be emails, wallet instructions, and server records, not a hoodie illustration.

The short clip embedded above is not a documentary about this defendant. It is a public-facing warning about the adjacent scam economy in which strangers demand bitcoin over a threat to publish private material. The charging theory in Newark is a corporate version of the same lever. Different inbox. Same coin. The AEGIS Alliance is using that explainer because a clean news package on this specific Curitiba caption has not been posted by a network that will travel inside a Classic Editor embed.

Related reading on this site sits in International News and the running original URL for this report. Until DOJ or Brazilian federal police announce a body in custody, the accurate last line is the dull one. Junior Barros De Oliveira is a charged man in a New Jersey indictment. He is not, on the public record, a man in a New Jersey cell.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Articles similaires

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *

Bouton retour en haut de la page
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link