Unauthorized news on hackers, data breaches, zero-day exploits, ransomware and AI. Original reporting and analysis for people who actually read the source.

Hackers

A Russian Hacker's Decade Behind Bars: Solitary, a Pigeon Named Baksik, and Extradition in Chains

Vladimir Drinkman, charged in one of the largest credit card data thefts on record, describes his 2012 arrest in the Netherlands and ten years in prison.

A Russian Hacker's Decade Behind Bars: Solitary, a Pigeon Named Baksik, and Extradition in Chains

Vladimir Drinkman spent more than a decade in foreign prisons for his role in what U.S. prosecutors called one of the largest credit card data thefts ever charged. Drinkman described for the first time the day of his arrest, his years in European detention, and his extradition to the United States in chains.

Arrested on the way to the airport

Drinkman was detained on 27 June 2012 in the Netherlands, the same day he had planned to fly home to Moscow. By his account, several cars boxed in his taxi on the road to the airport, and plainclothes officers he immediately clocked as armed identified themselves as Dutch Royal Marechaussee acting on a request from the U.S. Secret Service.

He was arrested alongside Dmitry Smilyanets, a member of the same group. Drinkman says he had always stayed in the shadows and believed nothing tied him to the scheme. Had he traveled only with his wife, as first planned, he says he would have flown home without incident.

The group is accused of breaking into the networks of foreign companies and siphoning off "dumps," the digital copies of payment card data, from their infrastructure.

Two months of solitary, and a pigeon named Baksik

Drinkman says he spent about three years moving through several European facilities before extradition. The harshest, he recalls, was Nortsingel in Rotterdam, a building he says was originally a psychiatric hospital before being turned into a prison after the Second World War, and one that housed some of the most dangerous inmates.

There he spent two months in solitary, permitted to speak only with his lawyer, by phone and under supervision. His only regular company, he says, were the pigeons that landed at his window. He fed them rolled pieces of bread, and one white pigeon became a daily visitor he named Baksik. If Drinkman was late with the 7 a.m. or 7 p.m. feeding, he says, the bird would tap on the glass.

The "four-star hotel"

Conditions changed sharply after he was moved to Alphen aan den Rijn, near Amsterdam, when Nortsingel was closed. Drinkman describes it as a four-star hotel with limited freedom: a real gym three days a week, a choice of good food, a weekly grocery budget, and a shared kitchen where he cooked lamb steaks and, on weekends, pancakes and borscht for other inmates from the former Soviet bloc. It was still a prison, he stresses, with a strict regime, but far more humane than what came next.

Ten years, and a story still being told

In all, Drinkman says he spent roughly three years in Europe and about seven more in American prisons, more than ten years behind bars. In this first part of the interview he recounts being extradited to the United States wrapped in chains.

Share this article
Share

Written by

Martin
Martin
Editor of Russian Hackers. Unauthorized news on hackers, breaches, exploits and AI.

Read next

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack

On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
Comic-poster cover: a cracked security shield shattering under 570 flaws and two zero-days

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
Comic-poster cover: a hacker prying open a Windows registry hive, the LegacyHive zero-day