Google Search

Showing posts with label prison. Show all posts
Showing posts with label prison. Show all posts

Monday, March 18, 2013

Not-so anonymous Anonymouses head off to prison over PayPal DDoS

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Four young Englishmen who went on an Anonymous rampage back in 2010 weren't as anonymous as they might have hoped.

They were traced, identified and arrested.

We wrote at the end of 2011 that they'd been released on bail after being charged with running Distributed Denial of Service (DDoS) attacks against a number of high-profile payment processing companies.

PayPal, Mastercard and Visa ended up under the pump in the attacks, which were carried out in revenge for those companies refusing to process donations to controversial whistle-blowing outfit Wikileaks.

The fact that the DDoS might have prevented many other not-for-profit organisations from receiving donations as a side-effect didn't seem to worry the attackers.

Interestingly, the judge who granted them bail didn't ban them from using the internet during their temporary freedom, but he did place them under an unusual restriction: they weren't allowed to use their online handles, or nicknames.

That probably wasn't too onerous for Christopher Weatherhead, now 22, who had to stop going by "Nerdo", nor for Ashley Rhodes, 28, who could no longer strut his stuff as "NikonElite". But it might have been tricky for 24 year old Peter Gibson, who was apparently banned from calling himself "Peter".

(It's not clear if he had to go by the rather formal "Mr Gibson" instead, or if, paradoxically, he was permitted to adopt a pseudonym, provided it was one he hadn't used before.)

All four pleaded guilty. Three have now been sentenced: Nerdo got 18 months, NikonElite got seven and Peter, also known as Peter, got a six month suspended sentence.

The fourth hacktivist, whom we now know to be Jake Birchall, was just 16 at the time of the offence and will be sentenced separately. He too was banned from using his nick while on bail, but the court never told us what it was.

You'll find widespread reports suggesting that this attack alone cost PayPal £3.5 million (about $5.5 million), if you're wondering just how harmful a DDoS can be for an online business.

You need to take this sort of damage figure with a pinch of salt - it seems to include the cost of precautions taken after the attack by PayPal that were an investment to protect the company into the future, so it seems a little counter-intuitive to include this in the retrospective cost of recovering from an attack.

But there is little doubt that the hacktivist quartet did, and intended to do, as much damage as they could. They're said to have bragged on IRC, saying:

We have probably done some million pound of dmg to mc

(The word dmg, of course, means damage, while mc is shorthand for Mastercard.)

Now they get to regret.

Follow @duckblog


View the original article here

Friday, February 8, 2013

Man who hacked Scarlett Johansson's email gets a whopping ten years in prison

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The crook who cracked into the email of numerous celebrities, including Scarlett Johansson and Mila Kunis, has been sent to prison.

A federal judge in Los Angeles, California, sentenced 36-year-old Christopher Chaney, of Florida, USA, yesterday.

Although Chaney had already pleaded guilty, thus sparing the expense and complexity of a trial, and although the prosecution had apparently asked for a sentence of just under six years, Judge Otero hit Chaney with a mammoth ten year stretch.

One report suggests Chaney drew an over-the-odds sentence because he continued his cracking activities even after he knew he was under investigation and his computer had been seized.

As we wrote earlier this year, Chaney's modus operandi seems to have been to use the 'forgot password' feature on his victim's email accounts.

He'd then use publicly accessible information - the sort of stuff many of us share in bits and pieces on social networking sites - to answer his victims' security questions and finish off the password reset.

Having got hold of the new passwords and illegally accessed the accounts, Chaney would activate the 'forward a copy of incoming mail' option. This means he could continue to harvest his victims' private emails, even if they changed their passwords back.

Chaney stole nude photos, lurid text messages and emails. Many of these were then shared with two online celebrity gossip sites.

Interestingly, although Chaney drew a harsh penalty, we haven't heard of anything happening to the gossip sites that willingly went public with the stolen material.

The story might have been different had the gossip-mag journalists been in Australia.

Sydney-based journalist Ben Grubb, for example, was briefly arrested in Queensland, Australia, in 2011, and had his iPad confiscated, after he published a supposedly private Facebook photograph that he had acquired from a security researcher.

The researcher had apparently got hold of the photo - a privacy-protected picture of a rival's wife - as a "proof of concept" for a conference talk about a security flaw in Facebook's privacy system.

The researcher couldn't resist sharing the photo with Grubb, who couldn't resist publishing it online (albeit blurred).

Ben Grubb in hot water

In the end, Grubb wasn't charged, quickly got his iPad back, and was vindicated - at least in the public's eyes - by strong criticism of his arrest.

But Queensland police obviously felt strongly enough to go after Grubb under a Queensland law dating back to 1889, which dispassionately observes that "a person who receives tainted property, and has reason to believe it is tainted property, commits a crime."

And there are two important lessons in that:

• Don't put tainted property online, especially if it affects the privacy of others.

It's easy to say, "But the information's out there now, so the crime of getting it in the first place is already done."

Have some concern and respect for the privacy of others. The way data breaches seem to be going, you may very well need the same sort of concern and respect in return some time soon.

• Review all your account settings if you think you've been hacked.

After a malware attack, an unexpected password change, or anything else which suggests that someone else has been riffling around in your digital stuff, be sure to check your configuration settings.

Be on the alert for changes which might let the crooks carry on their dirty work even after your initial cleanup.

Crooks can add new accounts to your PC, set email forwarding options (like Chaney did), change firewall settings, install remote access software, and much more. If you are unsure what to look for, ask someone you know and trust for help.

Follow @duckblog

Image of hands courtesy of Shutterstock.


View the original article here

Saturday, November 17, 2012

LulzSec hacker pleads guilty to Sony Pictures attack, faces prison sentence

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Man with clapperboard. Image from ShutterstockRaynaldo Rivera, from Tempe, Arizona, has admitted hacking into computer systems belonging to Sony Pictures, and stealing the personal information and passwords of thousands of innocent internet users

The attack, which took place in May last year, was part of a concerted attack against Sony websites by LulzSec and Anonymous hackers during 2011.

Rivera, who was arrested by the FBI in August, admitted his guilt in the form of a plea agreement filed with Los Angeles Federal Court.

Rivera - who used online nicknames including "neuron", "royal", and "wildicv" - admitted launching an SQL injection attack against the Sony Pictures website, extracting confidential and personal user information - such as the names, birth dates, addresses, emails, phone numbers and passwords of people who had entered Sony contests.

The stolen information was subsequently published online by the LulzSec hacking gang, compounding the risk to innocent users.

The hack is said to have cost Sony more than $605,000 in losses.

HideMyAss logoIn an attempt to hide his true identity during the attack, Rivera used the HideMyAss anonymising proxy service to disguise his IP address as he probed the Sony Pictures' website for vulnerabilities.

However, Rivera had not been careful enough in disguising his tracks - and HideMyAss co-operated with the authorities when a court order was received by the anonymising proxy service.

Others considering committing crimes on the net might be wise to stop believing that using an anonymising proxy service will necessarily keep them out of the clutches of the law.

Under the plea agremement, Rivera will pay restitution to his victims. He also faces a maximum five year prison sentence, and a fine of at least $250,000.

Follow @gcluley

Man with clapperboard image from Shutterstock.


View the original article here

Wednesday, July 11, 2012

Baltic SpyEye malware trio sent to prison

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Convictions for malware-related cybercriminality are uncommon, notably because of the international jurisdictional complexities of investigating and prosecuting such offences.

Despite the challenges, however, the cops sometimes do get their man - or men.

We think it's worth reminding you when this happens.

So we were pleased to receive, over the weekend, a press release on just such a topic from the UK's Police Central e-crime Unit.

The PCeU, jointly funded by the Home Office and London's Metropolitan Police, is the UK's national investigative response team for cybercrime.

Here's what they had to say:

Two men who used malicious computer software to steal the personal banking details for unsuspecting victims have been sentenced to nine years for offences under the Computer Misuse Act, and for other crimes including making articles for use in fraud, possession of articles for use in fraud, and for offences under the Proceeds of Crime Act.

The two men, Pavel Cyganok and Ilja Zakrevski, who hail from Lithunia and Estonia respectively, were pinched after PCeU investigators were alerted by their counterparts in the Estonian Police.

A third man, Aldis Krummins, who hails from Latvia, was sent down for two years for money-laundering crimes related to the malware attacks. (Once you've stolen money electronically, you still need to work it through the system to realised your ill-gotten gains.)

According to the PCeU, the crooks netted about £100,000 ($155,000) by using the SpyEye Trojan to help them break into online bank accounts.

They used the stolen money to fund and expand their criminal infrastructure, and to make online purchases of luxury items that they resold on auction sites.

With victims identified not just from the UK but also from Denmark, The Netherlands and New Zealand, the global nature of malware-related cybercrookery is obvious, so we all need to play our part.

As the police press release concludes:

The PCeU would like to remind the public that everyone can make it harder for cybercriminals by taking sensible precautions to protect personal data. Unprotected computers are more prone to infection and leave data exposed.

Follow @duckblog
-

Image of hazard sign courtesy of Shutterstock

Tags: conviction, denmark, latvia, lithuania, Malware, Netherlands, new zealand, pceu, prison, sentencing, SpyEye, stonia, UK


View the original article here

Saturday, July 7, 2012

Hacker who stole Tony Blair's address book faces prison

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Tony Blair. Image by Sougata Ghosh / Creative CommonsA hacker who stole private information belonging to former British Prime Minister Tony Blair has pleaded guilty at London’s Southwark Crown Court and faces a prison sentence for conspiracy and computer crime offences.

18-year-old Junaid Hussain, of Birmingham, broke into the online account of Blair aide Katie Kay and stole information including Tony Blair's address and phone book - containing email addresses, phone numbers and postal addresses for Blair's family, friends and MPs.

Members of Team Poison, who like to use the keyboard-challenging moniker "TeaMp0isoN", published the hacked information on the internet a year ago, sparking security fears about the safety of the former Prime Minister, his friends and family.

Message posted by Team Poison

Hussain, who used the online handle "Trick", also admitted making more than 100 hoax calls to the UK's national anti-terrorism telephone hotline, preventing genuine callers from getting through.

Hussain is scheduled to be sentenced on July 27, and was told by Judge Peter Testar that he should be "under no illusions" that he could go to prison.

The authorities are said to be continuing to investigate other possible offences committed by members of the Team Poison hacking gang.

Follow @gcluley

Image of Tony Blair by Sougata Ghosh / Creative Commons.


View the original article here