# I Checked the Worst OpSec Practices So You Don’t Have To

By [Officer's Blog](https://paragraph.com/@officercia) · 2025-11-26

security, privacy, opsec

---

In an increasingly digital world, Operational Security (**OpSec**) refers to the practices and processes individuals and organizations use to protect sensitive information from adversaries. This could include hackers, criminals, or even state actors. Good OpSec involves minimizing your digital footprint, using secure communication channels, and being mindful of what you share publicly. Unfortunately, poor OpSec can lead to devastating consequences, from financial loss to physical harm. This article explores common bad OpSec practices, highlights notable failures, and delves into a recent tragic case involving Russian crypto blogger and entrepreneur Roman Novak, whose murder underscores the deadly risks of complacency.

**Common Bad OpSec Practices**
------------------------------

Bad OpSec often stems from convenience over caution or simple oversight. Here are some prevalent mistakes:

*   _Posting about your wealth, location, or daily routines can paint a target on your back. Criminals scour platforms like Instagram, X, and Facebook for clues about high-value targets._
    
*   _Photos and files often contain embedded data like GPS coordinates, timestamps, or device information that can reveal your whereabouts._
    
*   _Using simple passwords, skipping two-factor authentication (2FA), or reusing credentials across accounts makes it easy for attackers to gain access._
    
*   _Discussing sensitive matters over unencrypted channels, like regular email or SMS, exposes information to interception._
    
*   _In fields like cryptocurrency, flaunting gains or holdings publicly attracts scammers, thieves, or extortionists._
    
*   _Especially in high-stakes industries, agreeing to in-person meetings without background checks or security measures can lead to ambushes._
    

These lapses aren't just theoretical - they've led to real-world disasters.

**Notable OpSec Failures in History**
-------------------------------------

History is littered with examples where poor OpSec turned minor vulnerabilities into major catastrophes... One classic case is John McAfee, the antivirus software pioneer. In 2012, while on the run from Belizean authorities in connection with a murder investigation, McAfee allowed a Vice magazine reporter to publish photos of him. Unbeknownst to them, the images contained EXIF metadata with GPS coordinates, pinpointing his location in Guatemala.

This blunder led to his swift arrest, illustrating how a simple oversight in file handling can unravel even the most elaborate evasion plans. Another infamous failure involves Ross Ulbricht, the founder of the dark web marketplace Silk Road. Ulbricht's OpSec crumbled due to identity reuse: He used the same username ("_altoid_") on public forums to promote Silk Road as he did on Stack Overflow for coding questions, where he also mentioned his real name. Investigators connected the dots, leading to his 2013 arrest and life sentence. This highlights the dangers of not compartmentalizing online personas.

Similarly, the AlphaBay market's operator, Alexandre Cazes, was compromised in 2017 when investigators linked his dark web alias to a personal email used in clear web transactions. His OpSec faltered with visible displays of wealth and inadequate separation of digital footprints, resulting in the site's seizure and his subsequent death in custody. In the corporate world, the 2014 Sony Pictures hack exposed emails, salaries, and unreleased films because of weak passwords and unpatched systems. Employees reused credentials, and the company lacked robust monitoring, allowing North Korean hackers (allegedly) to wreak havoc.

**The Rise and Fall of Prigozhin and PMC Wagner – A Tale of Power, Privacy, and a Fatal Mistake**
-------------------------------------------------------------------------------------------------

Did you hear about Yevgeny Prigozhin and PMC Wagner? Love them or hate them, one thing is clear: this organization was _unique_. Few have dared to attempt a rebellion in Moscow in the last 100 years (aside from the Communists). But what ultimately destroyed this war machine? Wagner Group, a private military company, was a force to be reckoned with. But even the most powerful organizations can crumble under the weight of their own mistakes. And in this case, it wasn’t just geopolitics - it was also a failure in _privacy and security_.

![Image](https://storage.googleapis.com/papyrus_images/5934104b1cc95d9a4c89280db1fe1db8e42d876e096098797c0d7a39a7b91668.png)

Prigozhin, Wagner’s leader, was known for his obsession with privacy. He avoided modern devices with internet or Bluetooth connectivity. Instead, he relied on two tools:

*   _An_ **_iPad_** _for secure communication._
    
*   _A_ **_Psion_**_, an old-school device with no internet or wireless capabilities._
    

Why a **Psion**? These retro devices are essentially "digital islands" - completely offline, making them immune to modern hacking techniques. Curious about how they work? Check out these resources:

*   [_Using an iPad for secure comms_](https://yawnbox.com/blog/how-to-use-an-ipad-as-a-secure-calling-and-messaging-device)
    
*   [_Psion: Breaching a digital data island_](https://richardwarrender.com/2019/03/psion-fever-breaching-a-digital-data-island/)
    
*   [_Connecting Psions to the internet_](https://zedstarr.com/2021/06/11/online-retro-connecting-psions-mc400-series-3a-machines-to-the-internet/)
    

Despite his efforts to stay off the grid, Prigozhin made one critical mistake: **he stored backups online.** These backups, containing sensitive data, were eventually hacked and leaked. This breach exposed Wagner’s operations and Prigozhin’s empire to the world. Here are some must-read articles:

*   [_Le Monde: Wagner boss exposed by hackers_](https://www.lemonde.fr/en/international/article/2023/03/22/wagner-boss-yevgeny-prigozhin-s-empire-exposed-by-hackers_6020232_4.html)
    
*   [_Risky Business: Putin’s chef cooks up an infosec disaster_](https://www.risky.biz/putins-chef-cooks-up-infosec-disaster/)
    

So, what’s the lesson here?

*   _First, making money from war is unethical and will earn you powerful enemies._
    
*   _Second, even the most secure devices can’t save you if you store sensitive backups on online servers._
    

**The Tragic Case of Roman Novak: A Cautionary Tale in Crypto OpSec**
---------------------------------------------------------------------

After his release, the couple relocated to Dubai, where they lived lavishly and documented it all on social media.The cryptocurrency world, with its promise of anonymity and wealth, is particularly rife with OpSec pitfalls. A stark recent example is the brutal murder of Russian crypto blogger and entrepreneur Roman Novak and his wife, Anna, in the United Arab Emirates. Novak, who had a history of fraud, including a prison stint for stealing $100,000 from investors, raised $500 million through a fraudulent crypto app before fleeing Russia with the funds.

Novak frequently posted photos boasting about their opulent lifestyle, including a Rolls-Royce and a vintage British Cobra sports car (valued at around $1.9 million combined), as well as family vacations to places like Disneyland. This public flaunting of wealth was a critical OpSec failure, as it signaled to potential adversaries that Novak was a lucrative target with significant crypto holdings. In the crypto community, such displays are often called "flexing," and they frequently attract physical threats, from home invasions to kidnappings.

![Image](https://storage.googleapis.com/papyrus_images/2c1b9a1c3933746fe41b1d7f13f74780c4d6cc1ac9dbc4c16f48d8901dc8102d.jpg)

**_On October 2, 2025, the Novaks were lured to a villa in Hatta, a remote mountain resort outside Dubai, by individuals posing as potential investors._** This meeting lacked any apparent verification or security precautions - another glaring OpSec lapse. Once there, they were held hostage while the kidnappers demanded the password to Novak's crypto wallet. When they discovered the wallet was empty (possibly because Novak had already spent or hidden the funds), the couple was killed, dismembered, and their body parts scattered, some even left in trash cans at a shopping mall. Their phones last pinged on October 4 in Cape Town, South Africa, before going silent, suggesting the killers may have disposed of or transported the devices. Authorities have arrested eight suspects, including defrauded investors and a former employee of Vladimir Putin's Interior Ministry, in connection with the kidnapping, extortion, and murders.

The case has sent shockwaves through the crypto community, highlighting how poor OpSec - such as oversharing online and trusting unverified contacts - can escalate from digital risks to lethal real-world violence. Novak's story echoes other crypto-related incidents, like the 2023 kidnapping of a Ukrainian crypto trader in Spain or SIM-swapping attacks that have drained millions from unsecured exchange accounts.

**The best way to learn about OpSec is to learn how people fail. Here you can check a big collection of links on bad OpSec by** [**jermanuts**](https://github.com/jermanuts/bad-opsec)**:**

*   _Finnish hacker traced using Monero bad opsec_ [_Reddit investigation_](https://libreddit.bus-hit.me/r/Monero/comments/19emsfe/finlands_national_bureau_of_investigation_claims)_. Entertaining_ [_video_](https://www.youtube.com/watch?v=7CD_Nl3iwhE)
    
*   _Administrator of Incognito Market_ [_Complaint_](https://www.justice.gov/opa/media/1352571/dl)_. Entertaining_ [_video_](https://youtu.be/EJAs9Nb-XE8)
    
*   _Pompompurin (Conor Fitzpatrick) BreachForums owner_ [_Affidavit_](https://s3.documentcloud.org/documents/23723268/pompourin-affidavit-govuscourtsvaed53554220.pdf)
    
*   _Hacker who_ [_used Genesis Market_](https://www.404media.co/hacker-allegedly-wanted-to-become-the-tech-arm-of-isis/) _and wanted to join ISIS by contacting an undercover FBI agent (ISIS travel facilitator)_ [_Court docs_](https://s3.documentcloud.org/documents/24709485/pratt.pdf)
    
*   _Harvard student_ [_bomb threat_](https://slate.com/technology/2013/12/harvard-exam-bomb-threats-how-the-alleged-hoaxer-failed-to-cover-his-online-tracks.html) _and_ [_Affidavit_](https://www.washingtonpost.com/blogs/the-switch/files/2013/12/kimeldoharvard.pdf)
    
*   _leaker of classified U.S. docs (Jack Teixeira)_ [_Affidavit_](https://www.documentcloud.org/documents/23777131-jack-teixeira-affidavit)_,_ [_Some external investigations_](https://archive.is/dI9wU)_,_ [_thread 1_](https://nitter.net/AricToler/status/1646888783609049088#m) _and_ [_thread 2_](https://nitter.net/trbrtc/status/1646544312170053633#m)
    
*   _Ross Ulbricht (Silk Road admin)_ [_Couldn't keep_](https://krebsonsecurity.com/2013/11/no-bail-for-alleged-silk-road-mastermind/) _himself_ [_anonymous online_](https://arstechnica.com/information-technology/2013/10/silk-road-mastermind-unmasked-by-rookie-goofs-complaint-alleges/) _and_ [_how undercover agent helped the FBI to get him traped_](https://archive.is/BDsLI) _the_ [_Affidavit_](https://www.documentcloud.org/documents/801070-silk-road-files)
    
*   _Lapsus$_ [_kiddies_](https://blog.sekoia.io/lapsus-when-kiddies-play-in-the-big-league/)_. Video_ [_documentary_](https://youtu.be/v_z2HkVfcEA)
    
*   _BayRob Malware gang with_ [_good opsec caught_](https://www.zdnet.com/article/the-bayrob-malware-gangs-rise-and-fall/)_. Conference_ [_video_](https://youtube.com/watch?v=zXmZnU2GdVk&t=0)
    
*   _Man_ [_donated_](https://www.justice.gov/usao-nj/press-release/file/1164941/download) _to Hamas_
    
*   _APT1 and learning from their_ [_OPSEC failures_](https://www.osintme.com/index.php/2020/01/15/apt1-and-learning-from-their-opsec-failures/)_. Conference_ [_video_](https://youtu.be/StSLxFbVz0M)
    
*   _Crypto "Mixer" Bitcoin Fog_ [_Affidavit_](https://storage.courtlistener.com/recap/gov.uscourts.dcd.230456/gov.uscourts.dcd.230456.1.1_1.pdf)
    
*   _The 'one tiny slip' that put_ [_LulzSec chief Sabu in the FBI's pocket_](https://www.theregister.com/2012/03/07/lulzsec_takedown_analysis/)
    
*   _Hacker_ [_Jeremy Hammond_](https://www.justice.gov/archive/usao/nys/pressreleases/March12/hackers/hammondjeremycomplaint.pdf)_. Entertaining_ [_video_](https://www.youtube.com/watch?v=qLgCzFN_LDo&t=722)
    
*   _John William Kirby Kelley_ [_Member of 'DeadNet' & .onion 'Doxbin'_](https://krebsonsecurity.com/2020/01/alleged-member-of-neo-nazi-swatting-group-charged/)_._ [_Affidavit_](https://www.courtlistener.com/recap/gov.uscourts.vaed.464952/gov.uscourts.vaed.464952.2.0.pdf)
    
*   _How the FBI goes after_ [_DDoS_](https://techcrunch.com/2023/08/12/fbi-ddos-for-hire-cyberattackers) _._
    

**Lessons Learned: Strengthening Your OpSec**
---------------------------------------------

The Novak tragedy and other failures serve as grim reminders that OpSec isn't optional in a connected world. To avoid similar fates:

*   _Scrub metadata from photos before posting._
    
*   _Use pseudonyms and separate accounts for different activities._
    
*   _Enable 2FA everywhere and use password managers._
    
*   _Avoid public displays of wealth, especially in volatile fields like crypto._
    
*   _Verify contacts through multiple channels before meetings, and consider escorts or neutral locations._
    
*   _Employ VPNs, encrypted messaging (e.g., Signal), and hardware wallets for assets._
    

In the end, good OpSec is about vigilance. As Novak's case shows, one slip can cost everything. By learning from these failures, individuals can better protect themselves in an era where information is both power and peril. **If you want to support my work, please, consider donating me:**

*   _0x1191b7d163bde5f51d4d2c1ac969d514fb4f4c62_ or _officercia.eth_ - all supported EVM chains;
    
*   _17Ydx9m7vrhnx4XjZPuGPMqrhw3sDviNTU_ or _bc1q75zgp5jurtm96nltt9c9kzjnrt33uylr8uvdds_ - Bitcoin;
    
*   _BLyXANAw7ciS2Abd8SsN1Rc8J4QZZiJdBzkoyqEuvPAB_ - Solana;
    
*   _0zk1qydq9pg9m5x9qpa7ecp3gjauczjcg52t9z0zk7hsegq8yzq5f35q3rv7j6fe3z53l7za0lc7yx9nr08pj83q0gjv4kkpkfzsdwx4gunl0pmr3q8dj82eudk5d5v_ - Railgun;
    
*   _TYWJoRenGB9JFD2QsdPSdrJtaT6CDoFQBN_ - TRX;
    
*   _4AhpUrDtfVSWZMJcRMJkZoPwDSdVG6puYBE3ajQABQo6T533cVvx5vJRc5fX7sktJe67mXu1CcDmr7orn1CrGrqsT3ptfds_ - XMR;
    
*   _DQhux6WzyWb9MWWNTXKbHKAxBnAwDWa3iD_ - Doge;
    
*   _UQBIqIVSYt8jBS86ONHwTfXCLpeaAjgseT8t\_hgOFg7u4umx_ - TON.
    

If you enjoy my content and want to help keep it ad-free, please consider supporting my work through donations. Your contributions will allow me to dedicate more time to crafting in-depth articles and sharing even more valuable insights.

**Thank you!**
--------------

---

*Originally published on [Officer's Blog](https://paragraph.com/@officercia/i-checked-the-worst-opsec-practices-so-you-don-t-have-to)*
