READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Accused Russian Hacker in Boston Case Previously Worked at Kaspersky Lab

Accused Russian Hacker in Boston Case Previously Worked at Kaspersky Lab
Denis Obrezko, extradited from Thailand and now facing federal hacking charges in Boston, worked as a senior specialist at Kaspersky Lab from 2017 to 2019, according to Reuters. Kaspersky says the charges have nothing to do with his time there. Fair enough, but the resume adds one more data point on why the US banned the company's software from federal systems.

A Kaspersky Alum Now Sits in a Boston Jail

Denis Obrezko pleaded not guilty last week to computer crimes in federal court in Boston. He's 36, Russian, and until recently unknown outside a narrow slice of cybersecurity circles. Now Reuters reports he spent two years, 2017 to 2019, as a senior specialist at Kaspersky Lab, the Moscow antivirus giant that the US government banned from federal computers and later banned from sale in America entirely over ties to the Kremlin.

The timeline matters. US prosecutors say Obrezko spent the five years before Kaspersky working for Russia's FSB, its domestic intelligence service. He left Kaspersky in 2019. The hacking he's charged with allegedly started in 2023 or 2024, after he'd moved on to a different firm. Kaspersky isn't accused of anything.

What He's Actually Charged With

Obrezko was arrested in Thailand in November and extradited to the US, making his initial court appearance in Boston, according to Global Banking & Finance Review, which credited Reuters reporter Nate Raymond. He's charged with conspiring to commit unauthorized access to a protected computer and is being held without bond. The case is being prosecuted by the Justice Department's National Security Division.

Thailand's Ministry of Foreign Affairs said the extradition followed Thai domestic law and treaty obligations, "while fully respecting the due process of law of the defendant." The Justice Department had no comment when asked about the case, and a court-appointed lawyer for Obrezko did not respond to requests for comment at the time.

Prosecutors tie Obrezko to a group called Void Blizzard, also known as Laundry Bear. Microsoft flagged the group in a May 2025 report as a newly identified operation conducting cyber espionage on behalf of Russian government objectives. Active since at least April 2024, Void Blizzard has targeted government agencies, defense contractors, transportation, media, healthcare providers and NGOs across NATO member states and Ukraine, according to Microsoft's findings as cited by Reuters.

An FBI agent's affidavit says the group's main method was mass email harvesting across a wide swath of US business sectors. The FBI has identified at least 11 US companies hit so far, which the court filing describes as likely just a fraction of the total victim list. Investigators say they linked Obrezko to the operation through cryptocurrency transactions used to buy a virtual private server and a domain name that were then used to carry out the attacks.

The Kaspersky Connection

An indictment filed last week ties Void Blizzard to Yutek-NN, a Russian cybersecurity firm where Obrezko worked as deputy director starting in 2024. That indictment does not mention his earlier stint at Kaspersky. Reuters says it's reporting that connection for the first time, based on leaked salary documents and a former colleague.

Kaspersky confirmed the employment in a statement: "An employee with the name specified worked at the company between 2017-2019, and we have no information on the individual's current status. The offenses charged cannot be related to the individual's role or responsibilities during the employment at Kaspersky."

There's nothing in the charging documents contradicting this. Nobody has alleged Kaspersky directed, knew about, or benefited from whatever Obrezko did after he left. Attributing an employee's post-employment conduct to a former employer without evidence would be its own kind of misinformation, and the record here doesn't support it.

Still, the resume is relevant context, not guilt by association. A VKontakte account tied to one of Obrezko's email addresses lists him as a graduate of Moscow's Bauman University, a technical school that a European journalism consortium identified last year as a key training ground for Russian government hackers, according to Reuters. His listed specialization: information security. Bauman University did not respond to a request for comment.

Why Kaspersky's US Ban Is Back in the Conversation

Kaspersky was one of the most widely used antivirus products in America before Washington moved against it. The Commerce Department barred the company from selling software in the US, citing national security risk tied to its Russian ownership and the legal obligations Russian firms have to cooperate with FSB requests under Russian law. Kaspersky has always denied doing Moscow's bidding and says it operates independently.

This case doesn't prove that dispute one way or the other. It does show that at least one person who later got accused of running Kremlin-directed hacking operations passed through Kaspersky's payroll. Correlation, not evidence of company wrongdoing. Critics of the US ban have long argued it was based on suspicion rather than a proven smoking gun tying Kaspersky software itself to espionage. This case doesn't hand them that gun either. But it doesn't help Kaspersky's PR position, and it's the kind of detail that will get cited in the next congressional hearing on foreign software risk regardless of whether it's fair to the company.

What's Unresolved

Obrezko's not-guilty plea means this goes to trial or a plea deal, neither of which has happened yet. The Russian Embassy in Washington has not responded to repeated questions about the case, according to Reuters. The FSB could not be reached for comment. Russia, as a rule, denies responsibility for hacking campaigns attributed to it by Western governments.

The open question for US companies: which of them are among the victims beyond the 11 already identified, and how much of their data is now sitting on servers tied to a group the FBI says was still active as recently as 2024.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ReutersAlleged Russian cyber spy in Boston case previously worked for Kaspersky, source says and documents show - Reuters
unknown
jpostAlleged Russian cyber spy in Boston worked for Kaspersky, source, documents show
unknown
globalbankingandfinanceUS charges suspected Russian hacker with facilitating cyber campaign
unknown
devdiscourseFrom Moscow to Massachusetts: The Hacking Trail of Denis Obrezko