Two cybersecurity incidents show how small digital footprints—from a fast food order to a compromised developer account—can lead to major breaches.

By Central
A Russian hacker's arrest over a Chicken McNuggets order and the Suno breach reveal how small mistakes cause security failures.
Highlights
  • Denis Obrezhko was arrested in Thailand after ordering Chicken McNuggets, leading to his extradition to the US.
  • The Suno data breach exposed customer names, emails, and payment details through a compromised npm package.
  • Both incidents demonstrate that operational security failures often stem from mundane digital footprints.

The intersection of fast food and state-sponsored cybercrime might seem improbable, but the case of Denis Obrezhko proves that operational security failures often begin with the most mundane habits. Meanwhile, the breach of AI music startup Suno reveals that the same carelessness that fells hackers can also expose companies that built their business on ethically questionable data practices. Together, these two stories from the cybersecurity frontline offer a masterclass in how digital footprints—whether from a McDonald’s delivery or a compromised developer workstation—can unravel even the most carefully constructed operations.

How a Russian Hacker’s Chicken McNuggets Habit Led to His Arrest

In September 2024, Dutch cybersecurity experts discovered that an attacker had burrowed into the computer systems of the Netherlands National Police Force, accessing the email account of a staff member and exfiltrating the data of more than 64,000 officers, including names, addresses, and informant details. Dutch intelligence described it as the first time the country had fallen victim to deliberate sabotage by a Russian-backed hacking group. The intrusion was not about ransomware or extortion—it was intelligence gathering, pure and simple.

Microsoft, working with Dutch intelligence, publicly named the group responsible as Void Blizzard in May 2025. (Other researchers refer to the group as Laundry Bear, a designation that suggests a certain pecking order among Russian state-linked threat actors.) The group’s targets extended beyond the Netherlands to include defence, healthcare, and government sectors across NATO and Ukraine. Their typical attack vector involved phishing emails with fake invitations to events like a European Defence Summit, complete with QR codes or links leading to credential-harvesting login pages.

At the heart of the investigation, according to US prosecutors, is Denis Obrezhko, a 36-year-old Russian IT professional. In late October 2025, Obrezhko made a critical error—he travelled to Phuket, Thailand, for a holiday. Less than a week later, Thai police were knocking on his door, seizing his laptop, mobile phone, and digital wallet. He was arrested at the request of US authorities and has since been extradited to Boston, where he has pleaded not guilty to hacking charges. If convicted, he could face up to 10 years in prison.

Obrezhko’s career history reads like a tour of Russian state-aligned institutions. According to the FBI, he worked for the FSB (the successor to the KGB) from 2012 to 2017. He later spent two years as a senior staff member at Kaspersky, the well-known Russian cybersecurity firm. In 2021, he gave a guest lecture at the Moscow Technical University of Communications and Informatics, where he was introduced as the Deputy Director of the Information and Analytical Center of Russia’s Ministry of Emergency Situations. Prosecutors allege he later became a deputy director at a Russian tech firm called UTECH.NN, which is described as a cover organisation for Void Blizzard’s hacking campaign. Public records show that UTECH.NN holds an FSB-issued licence for what is described as “the covert acquisition of information.”

The McDonald’s Link That Tied It All Together

Investigators pieced together Obrezhko’s identity through a series of operational security failures. He reused the same username and real Russian phone number across multiple email accounts, social media platforms, and financial apps. He used the same Google account for cryptocurrency transactions as he did for Twitter, Instagram, and PayPal—same username, same avatar, same phone number, same date of birth. This repetition allowed investigators to triangulate his identity.

Independent threat intelligence firm Control Alt Intel cross-referenced the email addresses and phone numbers from the FBI affidavit with Russian leak databases. There, they found a trail of personal data from banks, social networks, courier companies, and food delivery apps. Among the most damning evidence: on March 1, 2021, at 3:30 PM, Obrezhko ordered a Lipton iced tea, nine Chicken McNuggets, and a McChicken burger, delivered to the Russian Ministry of Emergency Situations. They found 13 other separate orders, all delivered to that same ministry address, all on weekdays, early in the afternoon. The McDonald’s receipts placed him inside a Russian government institution during working hours, directly contradicting any claims that he was not connected to state-sponsored activities.

This is a textbook example of how operational security unravels under the weight of everyday life. As James Ball, a journalist who worked on the Edward Snowden story, noted, maintaining perfect security over months or years is extraordinarily difficult. The compromise between mundane accounts and high-security ones is hard to sustain, and one lapse—a forgotten VPN, a reused phone number, a McDonald’s delivery—can be enough to bring down an entire operation.

In a separate but equally revealing incident, the AI music generation platform Suno was hacked, exposing the company’s internal operations and training data practices. Suno allows users to generate music by providing lyrics and genre prompts, producing passable compositions that have sparked intense debate about AI’s impact on the music industry. The company is currently facing lawsuits from major record labels over how it trained its models.

The breach was carried out using a 2025 worm called Shaihulud, which targeted the npm JavaScript package registry. A developer at Suno installed a booby-trapped package, and the malware quietly stole credentials before spreading to other packages maintained by the same developer. The attacker gained access to Suno’s GitHub repositories, customer lists, emails, phone numbers, and Stripe payment details. The hacker provided samples of the stolen data to 404 Media, which appeared legitimate.

What makes this breach particularly significant is what it revealed about Suno’s training data. The hacked code and annotations showed that Suno had ingested 113,879 hours of YouTube Music, 12,287 hours of Deezer, and 3,722 hours of Jamendo, alongside only 410 hours from a copyright-free source. This data appears to confirm that Suno trained on vast amounts of copyrighted music scraped from platforms whose terms of service explicitly prohibit such use. The company had previously been evasive in discovery about its training data sources.

The hacker told 404 Media they had “no specific motivation” for targeting Suno, stating simply, “I like to hack anything and everything.” Whether this is true or a cover for a more strategic motive—such as corporate espionage or ideological opposition to AI’s impact on creative industries—the breach has handed a powerful weapon to the record labels suing Suno. The exposed data will almost certainly be pulled into ongoing litigation, potentially undermining the company’s legal position.

What These Cases Reveal About Digital Security

Both stories illustrate the same fundamental principle: operational security is only as strong as its weakest link. For Obrezhko, the weak link was a Chicken McNuggets delivery that tied him to a Russian government ministry. For Suno, it was a developer who installed a malicious npm package. In both cases, the attackers (or investigators) exploited the gap between an organisation’s security posture and the messy reality of daily operations.

For individuals, the lesson is clear: never reuse credentials across personal and sensitive accounts, use a VPN with a verified no-logs policy when conducting any activity that requires privacy, and maintain separate digital identities for different aspects of your life. For businesses, the takeaway is equally stark: continuous monitoring of your attack surface, automated vulnerability management, and strict access controls are not optional—they are essential. The Suno breach demonstrates that even companies with significant technical resources can be compromised by a single careless action.

What Affected Users Should Do Now

If you were a customer of Suno, change your password immediately and enable two-factor authentication on your account. Monitor your financial accounts for any unusual activity, as payment details were exposed in the breach. Be alert for phishing emails that may attempt to exploit the breach to steal additional information.

For the broader community, these incidents serve as a reminder that digital security is a practice, not a one-time fix. Use a reputable password manager with end-to-end encryption to generate and store unique credentials for every service. Enable multi-factor authentication wherever it is available. And consider using a VPN with a verified no-logs policy and a kill switch when connecting to public Wi-Fi or when you need to protect your online activity from surveillance.

Ultimately, the most important security measure is awareness. The hackers who investigate you—whether they are state-sponsored threat actors or corporate rivals—are looking for the one mistake you make when you are tired, hungry, or distracted. The Chicken McNuggets order and the compromised npm package are both reminders that in cybersecurity, the smallest details often matter most.

Share This Article