Posts

Showing posts with the label USDoJ

Cybersecurity consultant arrested after allegedly extorting IT firm

By Bill Toulas, Bleeping Computer A former cybersecurity consultant was arrested for allegedly attempting to extort a publicly traded IT company by threatening to disclose confidential and proprietary data unless they paid him $1,500,000. A staffing company assigned Vincent Cannady, 57, to assess and remediate potential vulnerabilities in a New York-based multinational information technology infrastructure services provider. After the termination of his employment for performance reasons, on June 23, 2023, Cannady allegedly used a company-issued laptop to download proprietary and confidential information, including architectural maps, trade secrets, and lists of potential vulnerabilities, from the victim company's network, to which he still had access. The Department of Justice says Cannady threatened to publicly disclose this sensitive information unless the company agreed to pay him up to $1.5 million as a settlement for what he claimed was employment discrimination. When confron...

A US-UK agreement is changing how tech companies respond to law enforcement requests

What you should know about the Data Access Agreement. By Colleen Hagerty,  Popular Science An agreement between the United States and United Kingdom to improve cross-border law enforcement data sharing will go into effect later this year, the two nations announced in a joint statement published Thursday.  Called the Data Access Agreement, it will allow investigators from each country to “gain better access to vital data to combat serious crime,” according to the Department of Justice, as they will now be able to directly request data like messages and pictures, for example, from telecommunications providers in the other’s jurisdiction.  The US agency said that this is a first-of-its-kind agreement that could help with time-sensitive investigations, including those related to terrorism and child abuse. These requests will be “compliant with the relevant existing domestic obligations a public authority is bound by.” The agreement was created in 2019 to address the challenge...

Russia is well-prepared for cyber war

by Jurgita Lapienytė,  Cybernews For the first time ever, we are witnessing a real cyber war, Denys Tsvaig, the president of Ukraine’s national cybersecurity association, told Cybernews. The war in Ukraine caused turmoil in the cyber realm, with many pro-Ukrainian and pro-Russian citizens worldwide joining various efforts to fight. Hacktivism gained momentum soon after the invasion, causing collateral damage. Recently, the pro-Russian Killnet group made headlines after attacking Ukraine ally Lithuania’s websites in response to the Baltic country following EU sanctions. Hacktivism aside, Ukraine and Russia have used cyber weapons to support their kinetic operations. For example, Russia resorted to disinformation before many major military strikes. In its turn, Ukraine allegedly was able to cause some physical damage to Russian infrastructure using its IT resources, as unverified reports say. Some say Russia’s cyber weapons are just as weak as its artillery. The State Service of Spec...

Russian state hackers swap malware with cloud-based attacks

By Vilius Petkauskas,  Cybernews Russian adversaries increasingly focus on targeting the cloud environment, Crowdstrike’s Global Threat Report on Cloud Security revealed. Fancy Bear, a Russian adversary associated with Russia’s Main Intelligence Directorate (GRU), used to rely on malware-based spear-phishing attacks, the report claims. However, with their tactics exposed by the US Department of Justice (DoJ), hackers have refocused their attention on cloud service providers. Since Fancy Bear’s primary source of intelligence comes from various credential harvesting practices that allow penetrating target organizations and individuals, it’s no surprise that the main targets are cloud-based email providers. According to the report, Fancy Bear focused their attention on service providers such as Microsoft 365, Google’s GSuite, as well as webmail providers that individuals usually use. Meanwhile, Cozy Bear, Russia’s state-sponsored hacker group controlled by the Federal Security service...

US Justice Department Accuses AT&T of Allowing Scammers to Use IP Relay Call System to Cheat American Merchants

By Sophie Webster, Tech Times In 2002, telecommunication companies like MCI and AT&T offered free calls to the hearing impaired via internet web pages. The deaf customers will type their messages into dialog boxes similar to online chat rooms. A relay operator will then read the text, place the call, and they will verbalize the text. The entire system, called IP Relay, is created to assist deaf customers and help them communicate and make important phone calls. Unfortunately, scammers found a way to abuse that system and use it to cheat American business owners.

FBI busts online black market selling millions of stolen Social Security numbers

By Andy Meek, BGR US law enforcement officials have shut down a series of websites making $19 million in revenue by selling stolen data. The black market data the websites trafficked in included crucial personal information like stolen Social Security numbers and birthdates. So it’s definitely a big win that this operation was dismantled. The US Justice Department announced the shutdown of the “SSNDOB Marketplace” websites on June 7. Among other things, the announcement included this shocking detail: The websites were selling around 24 million stolen Social Security numbers. For context, that number exceeds the population of the state of Florida.

IRS And FBI Seize SSNDOB Marketplace Selling Personal Info Of 24M Americans

Image
By Nathan Wasson, Hot Hardware Yesterday, we reported on a data breach at Shields Health Care Group that resulted in the theft of personal information belong to 2 million Americans. Oftentimes, data stolen in breaches like this end up on online forums or marketplaces where cybercriminals buy and sell these ill-gotten gains. Lately, US law enforcement agencies, in collaboration with law enforcement agencies in other countries, have conducted major operations with the goal of shutting down hubs of cybercriminal activity. The Federal Bureau of Investigation (FBI), the United States Secret Service, and the Department of Justice (DOJ) seized RaidForums back in April. According to the DOJ, RaidForums was home to “more than 10 billion unique records for individuals residing in the United States and internationally." Now, federal law enforcement has shut down SSNDOB Marketplace by seizing the domains of the website and its mirrors. The domains “ssndob.ws,” “ssndob.vip,” “ssndob.club,” an...

US Government Ordered Travel Companies To Spy On Russian Hacker For Years And Report His Whereabouts Every Week

Image
By Thomas Brewster, Forbes In 2015, the U.S. Secret Service was on the hunt for Aleksei Burkov, an infamous Russian hacker suspected of facilitating the theft of $20 million from stolen credit cards on the Cardplanet website. The methods the agency used to pursue him, revealed for the first time as a result of a Forbes legal challenge, show how the U.S. government was able to strong-arm two data companies into spying on him for two years based on the authority of a 233-year-old law and to issue weekly reports on his whereabouts. The government has never disclosed how many other individuals could be under such prolonged and unconventional surveillance. The two companies, Sabre in the U.S. and Travelport in the U.K., were perfect suppliers to American law enforcement because of the business they’re in. For decades, they’ve been collecting and storing information about international tourists in a so-called global distribution system. GDSs are essentially hubs of information that make trav...

FBI seizes domains used to sell stolen data, DDoS services

By Sergiu Gatlan, Bleeping Computer The Federal Bureau of Investigation (FBI) and the U.S. Department of Justice announced today the seizure of three domains used by cybercriminals to sell personal info stolen in data breaches and provide DDoS attack services. WeLeakInfo.to was selling subscriptions allowing its users to search a database containing information stolen in more than 10,000 data breaches. The roughly 7 billion records contained various personally identifiable information (PII), including names, email addresses, usernames, phone numbers, and passwords for online accounts. Two other domains, ipstress.in and ovh-booter.com, were used to provide booter or stressor attack services where clients could ask for a website or web platform of their choice to be taken down in large-scale Distributed Denial of Service (DDoS) attacks. "Today, the FBI and the Department stopped two distressingly common threats: websites trafficking in stolen personal information and sites which att...

What Counts as “Good Faith Security Research?”

By  Krebs On Security The U.S. Department of Justice (DOJ) recently revised its policy on charging violations of the Computer Fraud and Abuse Act (CFAA), a 1986 law that remains the primary statute by which federal prosecutors pursue cybercrime cases. The new guidelines state that prosecutors should avoid charging security researchers who operate in “good faith” when finding and reporting vulnerabilities. But legal experts continue to advise researchers to proceed with caution, noting the new guidelines can’t be used as a defense in court, nor are they any kind of shield against civil prosecution. In a statement about the changes, Deputy Attorney General Lisa O. Monaco said the DOJ “has never been interested in prosecuting good-faith computer security research as a crime,” and that the new guidelines “promote cybersecurity by providing clarity for good-faith security researchers who root out vulnerabilities for the common good.” What constitutes “good faith security research?” The ...

Data Breach on DEA Law Enforcement System Grants Cyber Criminals Access to 16 Databases

By Alicia Hope, CPO Magazine U.S. Drug Enforcement Agency (DEA) is investigating a potential law enforcement system data breach associated with an online harassment community that impersonates police officers. KrebsOnSecurity journalist Brian Krebs received a tip that hackers gained unauthorized access to the esp.usdoj.gov data portal, the Law Enforcement Inquiry and Alerts (LEIA) system. Krebs obtained the information from the administrator of the Doxbin cyberbullying community identified as “KT” with links to the LAPSUS$ hacking group. Doxbin members post personal information online and participate in “swatting,” while LAPSUS$ was responsible for high-profile data breaches on Microsoft, NVIDIA, Okta, Samsung, and others. LAPSUS$ also sells a service for making Emergency Data Requests to tech companies, social media platforms, and mobile service providers. The imposters trick organizations by claiming that the data requests could not wait for warrants because of their emergency nature...

U.S. DOJ will no longer prosecute ethical hackers under CFAA

By Bill Toulas , Bleeping Computer The U.S. Department of Justice (DOJ) has announced a revision of its policy on how federal prosecutors should charge violations of the Computer Fraud and Abuse Act (CFAA), carving out "good-faith" security research from being prosecuted. With this policy update, the DOJ is separating cases of good-faith security research from ill-intended hacking, which were previously distinguished by a blurred line that frequently placed ethical security research in a problematic, gray legal area. Under these new policies, software testing, investigation, security flaw analysis, and network breaches intended to promote the security and safety of the target devices or services are not to be prosecuted by federal prosecutors. "Computer security research is a key driver of improved cybersecurity," said Deputy Attorney General Lisa O. Monaco.  "The department has never been interested in prosecuting good-faith computer security research as a cri...

US links Thanos and Jigsaw ransomware to 55-year-old doctor

Image
By Sergiu Gatlan,  Bleeping Computer The US Department of Justice today said that Moises Luis Zagala Gonzalez (Zagala), a 55-year-old cardiologist with French and Venezuelan citizenship residing in Ciudad Bolivar, Venezuela, created and rented Jigsaw and Thanos ransomware to cybercriminals. Zagala (aka Nosophoros, Aesculapius, and Nebuchadnezzar) also offered support to cybercriminals who bought the malware and shared profits earned after ransoming victims worldwide. "As alleged, the multi-tasking doctor treated patients, created and named his cyber tool after death, profited from a global ransomware ecosystem in which he sold the tools for conducting ransomware attacks, trained the attackers about how to extort victims, and then boasted about successful attacks, including by malicious actors associated with the government of Iran," said US Attorney Breon Peace. "We allege Zagala not only created and sold ransomware products to hackers, but also trained them in their use...

Why your website is about to get more expensive

Image
By Leah Nulen, Politico The most popular websites are about to get more expensive because of a no-bid deal between the Trump administration and the company that holds a monopoly on managing a prime part of the internet. And the Biden team isn’t sure it can back out of the arrangement. Planned price spikes by Verisign in the coming years may add just a few dollars to the cost of registering or renewing an internet addressing ending in “.com.” But critics say that extra expense — totaling an estimated $85 million for the first year alone — will cascade through the online economy, ultimately hitting consumers. And they fault the U.S. government for not even trying to get a better deal by bidding out the contract that Verisign has held for more than two decades. “When it’s a government monopoly, you should have some mechanism to protect the consumer interests,” said Deb Garza, a former federal antitrust official who had been involved in contract discussions with Verisign during the George...