Search This Blog

Showing posts with label hacker. Show all posts
Showing posts with label hacker. Show all posts

Saturday, March 31, 2012

Chinese Company and Employee Deny Any Involvement in Hacking Attacks

Excerpt from an article in

The New York Times
Saturday, March 31, 2012

Chinese Company and Employee Deny Any Involvement in Hacking Attacks

By DAVID BARBOZA

SHANGHAI — Tencent, a Chinese Internet company, denied on Friday that one of its employees had been involved in a recent breach of computers belonging to Japanese and Indian companies, as well as Tibetan activists.

The company and the employee suggested that his identity might have been confused with someone else’s.

The company released a statement soon after Trend Micro, a computer security company with headquarters in Tokyo, released a report on Friday describing the breach. It was the result of a nearly yearlong effort to hack into computers and steal information from hundreds of companies and individuals in several countries, the report said.

The report never identified a hacker by name. But it linked the attacks to an alias used by a graduate of Sichuan University in western China who wrote several articles on computer hacking and defense. The researchers found the alias through its connection to an e-mail address and a QQ number, the Chinese equivalent of an instant messaging screen name.

The New York Times identified the owner of the alias as Gu Kaiyuan, based on online records of his writing. Mr. Gu is now an employee at Tencent, which offers social networking, instant messaging, online gaming and other online features.

On Thursday, when asked about the attacks, Mr. Gu said, “I have nothing to say.” On Friday, however, he denied involvement.

With Advance Warning, Bracing for Attack on Internet by Anonymous

Excerpt from an article in

The New York Times
Added on Saturday, March 31, 2012

With Advance Warning, Bracing for Attack on Internet by Anonymous

By SOMINI SENGUPTA

SAN FRANCISCO — On a quiet Sunday in mid-February, something curious attracted the attention of the behind-the-scenes engineers who scour the Internet for signs of trouble. There, among the ubiquitous boasts posted by the hacking collective Anonymous, was a call to attack some of the network’s most crucial parts.

The message called it Operation Global Blackout, and rallied Anonymous supporters worldwide to attack the Domain Name System, which converts human-friendly domain names like google.com into numeric addresses that are more useful for computers.

It declared when the attack would be carried out: March 31. And it detailed exactly how: by bombarding the Domain Name System with junk traffic in an effort to overwhelm it altogether.

There was no way to know for sure whether this was a pre-April Fool’s Day hoax or a credible threat. After all, this was Anonymous, a decentralized movement with no leaders and no coherent ideology, but a track record of considerable damage. The call to arms would have to be treated as one would treat a bomb threat called in to a high school football game. The engineers would have to prepare.

Those preparations turned into a fast-track, multimillion-dollar global effort to beef up the Domain Name System. They offer a glimpse into the largely unknown forces that keep the Internet running in the face of unpredictable, potentially devastating threats.

Among those leading the effort was Bill Woodcock, whose nonprofit based in San Francisco, Packet Clearing House, defends vital pieces of Internet infrastructure. By his calculation, the Anonymous threat was as good a reason as any to accelerate what might have been done anyway over the next several months: fortify the network, chiefly by expanding the capacity of the root servers that are its main pillar.

“Whether or not Anonymous carries out this particular attack, there are larger attacks that do happen,” Mr. Woodcock said. “A forewarning of this attack allowed everyone to act proactively for a change. We can get out in front of the bigger attacks.”

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities 

U.S. Attorney’s OfficeMarch 26, 2012
  • Central District of California(213) 894-2434
LOS ANGELES—A Florida man pleaded guilty today to a series of cyber-related crimes relating to his hacking into the personal e-mail accounts of more than 50 individuals associated with the entertainment industry.
Christopher Chaney, 35, of Jacksonville, Florida, pleaded guilty to nine felony counts of a 28-count first superseding indictment, including unauthorized access to protected computers in furtherance of wiretapping and wire fraud, unauthorized damage to protected computers resulting in more than $5,000 loss and physical harm, and wiretapping. At the conclusion of the hearing, United States District Court Judge S. James Otero ordered Chaney taken into custody.
During the hearing, Chaney admitted that from at least November 2010 to October 2011, he hacked into the e-mail accounts of Scarlett Johansson, Mila Kunis, Renee Olstead, and others by taking the victims’ e-mail addresses, clicking on the “Forgot your password?” feature, and then re-setting the victims’ passwords by correctly answering their security questions using publicly available information he found by searching the Internet. Once Chaney gained exclusive control of the victims’ e-mail accounts, he was able to access all of their e-mail boxes. While in the accounts, Chaney also went through their contact lists to find e-mail addresses of potential new hacking targets.
In pleading guilty to the wiretapping charges, Chaney admitted that, for most victims, he also changed their e-mail account settings by inserting his alias e-mail address into the forwarding feature so that a duplicate copy of all incoming e-mails to the victims—including any attachments—would be sent virtually simultaneously to Chaney without the victims’ knowledge. Most victims did not check their account settings, so even after they regained control of their e-mail accounts, Chaney’s alias address remained in their account settings. As a result, for many victims, copies of their incoming e-mails, including attachments, were sent to Chaney for weeks or months without their knowledge, causing Chaney to receive thousands of victim e-mails. In addition, when a victim reset his/her password to regain control of the account, Chaney sometimes hacked into the account again and reset the password, sometimes multiple times, in order to continue illegally accessing that victim’s account.
Chaney admitted that as his hacking scheme became more extensive, he began using a proxy service called “Hide My IP” because he knew what he was doing was illegal and wanted to “cover his tracks” so that law enforcement agents could not trace the hacking back to his home computer. Even after his home computers were seized by law enforcement agents pursuant to a federal search warrant, but before he was arrested, Chaney used another computer to hack into another victim’s e-mail account.
Chaney further admitted that as a result of his hacking scheme, he obtained numerous private communications, private photographs, and confidential documents from the victims’ e-mail accounts. The confidential documents included business contracts, scripts, letters, driver’s license information, and Social Security information. On several occasions, after hacking into victim accounts, Chaney sent e-mails from the hacked accounts to friends of the victims, fraudulently posing as the victims to request more private photographs. Chaney downloaded many of the confidential documents and photographs he stole to his home computer, where he saved them on his hard drive in separate computer file folders. Chaney e-mailed many of the stolen photographs to others, including another hacker and two gossip websites. As a result, some of those stolen photographs, several of which were explicit, were later posted on the Internet.
“Today’s guilty pleas shine a bright light on the dark underworld of computer hacking,” said United States Attorney AndrĂ© Birotte, Jr., whose office prosecuted the case. “This case demonstrates that everyone, even public figures, should take precautions to shield their personal information from the hackers that inhabit that dark underworld. It also demonstrates that the Department of Justice will take whatever steps are necessary to protect Americans from harm in cyberspace.”
“Mr. Chaney’s admission to compromising victim accounts, utilizing both technically and socially engineered means, demonstrates the persistence and extent to which a hacker will go to obtain private information,” said Steven Martinez, Assistant Director in Charge of the FBI’s Los Angeles Field Office. “This case sends an important message to all users of Internet-accessible media that practicing good computer security makes us less vulnerable to this type of attack. The FBI remains committed to investigating cyber adversaries who target protected computers, whether of private citizens or the nation’s critical infrastructure.”
Each charge of unauthorized access to a protected computer carries a maximum of five years in prison, each charge of unauthorized damage to a protected computer carries a maximum charge of 10 years in prison, and each charge of wiretapping carries a maximum of five years in prison. As a result of all of today’s guilty pleas, Chaney faces a total statutory maximum sentence of 60 years in federal prison. In addition to the possible prison term, as part of his plea agreement filed in federal court, Chaney agreed to forfeit his computers and related devices seized during the investigation, to pay restitution to all of the victims for any losses they suffered, and to comply with strict restrictions regarding his future use of computers and computer-related devices. In exchange, the government agreed to dismiss the remaining counts, including nine counts of aggravated identity theft, at the time defendant is sentenced.
Chaney is scheduled to be sentenced by United States District Judge S. James Otero on July 23, 2012.
The investigation of this case was led and conducted by the Federal Bureau of Investigation.

Friday, March 30, 2012

Visa & MasterCard Security Breach

Note to Visitors:  We have moved!  For current news and information, please visit us at our successor blogs:  http://JBK-BizTech.blogspot.com and http://JBK-Current-Events.blogspot.com.  Thank you.


CNBC's Mary Thompson has the details on MasterCard and Visa investigating a potential data breach at a 3rd party processor.  To see videos, click the links below:

http://video.cnbc.com/gallery/?video=3000081506

http://video.cnbc.com/gallery/?video=3000081531

Friday, March 23, 2012

Why Hackers Set Their Sights on Small Business


If you run a small business, and think that none of your data was of interest to a hacker, consider this: what if a hacker could take stolen bank account or credit card information from your computer and package it with the same information from a hundred or a thousand other small businesses? Would it be worth something then?
"SMBs don't know how defenseless they've become, especially to automated and industrialized attack methodologies by organized crime," Christopher Porter tells PCWorld. Porter, a principal with the Verizon RISK Team, is the author of a new report from Verizon on security risk.
"[Hackers] scan the Internet, looking for remote access services, and then try the default credentials. Once they gain access, they automatically install keyloggers to collect password information [as it's typed in]," Porter says. "Then they send the information it out via e-mail or by uploading it to an FTP server or a web site. They aggregate the data and sell it on the black market."
Hackers could use the keylogger to figure out how access and drain a small business' bank account, but more commonly, Porter said, they'll target point-of-sale systems, as four Romanians did recently. "That kind of attack is increasing, because they're low-risk and low-cost attacks for organized crime." Because they're geographically widespread, it's hard for any one police department to follow up.
For more, click the link below: 


http://www.pcworld.com/businesscenter/article/252302/why_hackers_set_their_sights_on_small_businesses.html#tk.nl_bdx_h_crawl

Thursday, March 22, 2012

2011 Was the Year of the 'Hacktivist'

2011 Was the Year of the 'Hacktivist,' According to the 'Verizon 2012 Data Breach Investigations Report'
Attacks Are Increasingly Motivated by Political and Social Intent; Majority of Breaches Avoidable With Sound Security Measures
News Release ShareThis
NEW YORK – March 22, 2012 –
The "Verizon 2012 Data Breach Investigations Report" reveals the dramatic rise of "hacktivism" -- cyberhacking to advance political and social objectives.

In 2011, 58 percent of data stolen was attributed to hacktivism, according to the annual report released today from Verizon.  The new trend contrasts sharply with the data-breach pattern of past several years, during which the majority of attacks were carried out by cybercriminals, whose primary motivation was financial gain.

Seventy-nine percent of attacks represented in the report were opportunistic.  Of all attacks, 96 percent were not highly difficult, meaning they did not require advanced skills or extensive resources.  Additionally, 97 percent of the attacks were avoidable, without the need for organizations to resort to difficult or expensive countermeasures.  The report also contains recommendations that large and small organizations can implement to protect themselves.

Now in its fifth year of publication, the report spans 855 data breaches across 174 million stolen records - the second-highest data loss that the Verizon RISK (Research Investigations Solutions Knowledge) team has seen since it began collecting data in 2004.  Verizon was joined by five partners that contributed data to this year's report: the United States Secret Service, the Dutch National High Tech Crime Unit, the Australian Federal Police, the Irish Reporting & Information Security Service and the Police Central e-Crime Unit of the London Metropolitan Police.

"With the participation of our law enforcement partners around the globe, the '2012 Data Breach Investigations Report' offers what we believe is the most comprehensive look ever into the state of cybersecurity," said Wade Baker, Verizon's director of risk intelligence.  "Our goal is to increase the awareness of global cybercrime in an effort to improve the security industry's ability to fight it while helping government agencies and private sector organizations develop their own tailored security plans."

The report findings reinforced the international nature of cybercrime.  Breaches originated from 36 countries around the globe, an increase from 22 countries the year prior.  Nearly 70 percent of breaches originated in Eastern Europe, with less than 25 percent originating in North America.

External attacks remain largely responsible for data breaches, with 98 percent of them attributable to outsiders.  This group includes organized crime, activist groups, former employees, lone hackers and even organizations sponsored by foreign governments.  With a rise in external attacks, the proportion of insider incidents declined again in this year's report, to 4 percent.  Business partners were responsible for less than 1 percent of data breaches.

In terms of attack methods, hacking and malware have continued to increase. In fact, hacking was a factor in 81 percent of data breaches and in 99 percent of data lost.  Malware also played a large part in data breaches; it appeared in 69 percent of breaches and 95 percent of compromised records.  Hacking and malware are favored by external attackers, as these attack methods allow them to attack multiple victims at the same time from remote locations.  Many hacking and malware tools are designed to be easy and simple for criminals to use.

Additionally, the compromise-to-discovery timeline continues to be measured in months and even years, as opposed to hours and days.  Finally, third parties continue to detect the majority of breaches (92 percent).

(NOTE:  Additional resources supporting the "2012 Data Breach Investigations Report" are available, including high-resolution charts,  B-roll available upon request.)

Key Findings of the 2012 Report

Data from the 2012 report also demonstrates that:

  • Industrial espionage revealed criminal interest in stealing trade secrets and gaining access to intellectual property.  This trend, while less frequent, has serious implications for the security of corporate data, especially if it accelerates.
  • External attacks increased. Since hacktivism is a factor in more than half of the breaches, attacks are predominantly led by outsiders.  Only 4 percent of attacks implicate internal employees.
  • Hacking and malware dominate. The use of hacking and malware increased in conjunction with the rise in external attacks in 2011.  Hacking appeared in 81 percent of breaches (compared with 50 percent in 2010), and malware appeared in 69 percent (compared with 49 percent in 2010). Hacking and malware offer outsiders an easy way to exploit security flaws and gain access to confidential data.
  • Personally identifiable information (PII) has become a jackpot for criminals. PII, which can include a person's name, contact information and social security number, is increasingly becoming a choice target. In 2011, 95 percent of records lost included personal information, compared with only 1 percent in 2010.
  • Compliance does not equal security.  While compliance programs, such as the Payment Card Industry Data Security Standard, provide sound steps to increasing security, being PCI compliant does not make an organization immune from attacks.
"The report demonstrates that unfortunately, many organizations are still not getting the message about the steps they can take to prevent data breaches," said Baker.  "This year, we have segmented our recommendations for enterprises and small businesses in the hope that this will make our suggestions more actionable. Additionally, we believe greater public awareness about cyberthreats and user education and training are vitally important in the fight against cybercrime."
Recommendations for Enterprises
  1. Eliminate unnecessary data. Unless there is a compelling reason to store or transmit data, destroy it.  Monitor all important data that must be kept.
  2. Establish essential security controls. To effectively defend against a majority of data breaches, organizations must ensure fundamental and common sense security countermeasures are in place and that they are functioning correctly. Monitor security controls regularly.
  3. Place importance on event logs. Monitor and mine event logs for suspicious activity - breaches are usually identified by analyzing event logs.
  4. Prioritize security strategy. Enterprises should evaluate their threat landscape and use the findings to create a unique, prioritized security strategy.
Recommendations for Small Organizations
  1. Use a firewall. Install and maintain a firewall on Internet-facing services to protect data. Hackers cannot steal what they cannot reach.
  2. Change default credentials. Point-of-sale (POS) and other systems come with pre-set credentials. Change the credentials to prevent unauthorized access.
  3. Monitor third parties. Third parties often manage firewalls and POS systems.  Organizations should monitor these vendors to ensure they have implemented the above security recommendations, where applicable.
The DBIR can be downloaded in full at: www.verizon.com/enterprise/2012dbir/us.
The Verizon 2012 DBIR will be available in seven languages. The initial report is in English, and translations will be available June 6 in French, German, Italian, Japanese, Spanish and Portuguese.

Verizon, through its Terremark subsidiary, helps organizations protect their core asset: data.  The company does this through a robust suite of security services -- including governance, risk and compliance solutions; identity and access management solutions; investigative response; data protection services; threat management services; and vulnerability management services -- delivered in the cloud or on premises.  For more information, visit us at verizonbusiness.com/products/security.  For ongoing security insight and analysis from some of the world's most distinguished security researchers, read the Verizon Security Blog at securityblog.verizonbusiness.com.

Verizon Communications Inc. (NYSE, Nasdaq: VZ), headquartered in New York, is a global leader in delivering broadband and other wireless and wireline communications services to consumer, business, government and wholesale customers.  Verizon Wireless operates America's most reliable wireless network, with nearly 108 million total connections nationwide.  Verizon also provides converged communications, information and entertainment services over America's most advanced fiber-optic network, and delivers integrated business solutions to customers in more than 150 countries, including all of the Fortune 500.  A Dow 30 company with $111 billion in 2011 revenues, Verizon employs a diverse workforce of nearly 194,000.  For more information, visit www.verizon.com.

####

Tuesday, March 6, 2012

Six Hackers Charged

Six Hackers in the United States and Abroad Charged for Crimes Affecting Over One Million Victims 
Four Principal Members of “Anonymous” and “LulzSec” Charged with Computer Hacking and Fifth Member Pleads Guilty; “AntiSec” Member also Charged with Stealing Confidential Information from Approximately 860,000 Clients and Subscribers of Stratfor

U.S. Attorney’s OfficeMarch 06, 2012
  • Southern District of New York(212) 637-2600
Five computer hackers in the United States and abroad were charged today, and a sixth pled guilty, for computer hacking and other crimes. The six hackers identified themselves as aligned with the group Anonymous, which is a loose confederation of computer hackers and others, and/or offshoot groups related to Anonymous, including “Internet Feds,” “LulzSec,” and “AntiSec.”
RYAN ACKROYD, a/k/a “kayla,” a/k/a “lol,” a/k/a “lolspoon”; JAKE DAVIS, a/k/a “topiary,” a/k/a “atopiary”; DARREN MARTYN, a/k/a “pwnsauce,” a/k/a “raepsauce,” a/k/a “networkkitten”; and DONNCHA O’CEARRBHAIL, a/k/a “palladium,” who identified themselves as members of Anonymous, Internet Feds, and/or LulzSec, were charged in an indictment unsealed today in Manhattan federal court with computer hacking conspiracy involving the hacks of Fox Broadcasting Company, Sony Pictures Entertainment, and the Public Broadcasting Service (“PBS”). O’CEARRBHAIL is also charged in a separate criminal complaint with intentionally disclosing an unlawfully intercepted wire communication.
HECTOR XAVIER MONSEGUR, a/k/a “Sabu,” a/k/a “Xavier DeLeon,” a/k/a “Leon,” who also identified himself as a member of Anonymous, Internet Feds, and LulzSec, pled guilty on August 15, 2011 in U.S. District Court to a 12-count information charging him with computer hacking conspiracies and other crimes. MONSEGUR’S information and guilty plea were unsealed today. The crimes to which MONSEGUR pled guilty include computer hacking conspiracy charges initially filed in the Southern District of New York. He also pled guilty to the following charges: a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of California related to the hacks of HBGary, Inc. and HBGary Federal LLC; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Central District of California related to the hack of Sony Pictures Entertainment and Fox Broadcasting Company; a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Northern District of Georgia related to the hack of Infragard Members Alliance; and a substantive hacking charge initially filed by the U.S. Attorney’s Office in the Eastern District of Virginia related to the hack of PBS, all of which were transferred to the Southern District of New York, pursuant to Rule 20 of the Federal Rules of Criminal Procedure, in coordination with the Computer Crime and Intellectual Property Section (“CCIPS”) in the Justice Department’s Criminal Division.
Late yesterday, JEREMY HAMMOND, a/k/a “Anarchaos,” a/k/a “sup_g,” a/k/a “burn,” a/k/a “yohoho,” a/k/a “POW,” a/k/a “tylerknowsthis,” a/k/a “crediblethreat,” who identified himself as a member of AntiSec, was arrested in Chicago, Illinois and charged in a criminal complaint with crimes relating to the December 2011 hack of Strategic Forecasting, Inc. (“Stratfor”), a global intelligence firm in Austin, Texas, which may have affected approximately 860,000 victims. In publicizing the Stratfor hack, members of AntiSec reaffirmed their connection to Anonymous and other related groups, including LulzSec. For example, AntiSec members published a document with links to the stolen Stratfor data titled, “Anonymous Lulzxmas rooting you proud” on a file sharing website.
The following allegations are based on the indictment, the information, the complaints, and statements made at MONSEGUR’s guilty plea:
Hacks by Anonymous, Internet Feds, and LulzSec
Since at least 2008, Anonymous has been a loose confederation of computer hackers and others. MONSEGUR and other members of Anonymous took responsibility for a number of cyber attacks between December 2010 and June 2011, including denial of service (“DoS”) attacks against the websites of Visa, MasterCard, and PayPal, as retaliation for the refusal of these companies to process donations to Wikileaks, as well as hacks or DoS attacks on foreign government computer systems.
Between December 2010 and May 2011, members of Internet Feds similarly waged a deliberate campaign of online destruction, intimidation, and criminality. Members of Internet Feds engaged in a series of cyber attacks that included breaking into computer systems, stealing confidential information, publicly disclosing stolen confidential information, hijacking victims’ e-mail and Twitter accounts, and defacing victims’ Internet websites. Specifically, ACKROYD, DAVIS, MARTYN, O’CEARRBHAIL, and MONSEGUR, as members of InternetFeds, conspired to commit computer hacks including: the hack of the website of Fine Gael, a political party in Ireland; the hack of computer systems used by security firms HBGary, Inc. and its affiliate HBGary Federal, LLC, from which Internet Feds stole confidential data pertaining to 80,000 user accounts; and the hack of computer systems used by Fox Broadcasting Company, from which Internet Feds stole confidential data relating to more than 70,000 potential contestants on “X-Factor,” a Fox television show.
In May 2011, following the publicity that they had generated as a result of their hacks, including those of Fine Gael and HBGary, ACKROYD, DAVIS, MARTYN, and MONSEGUR formed and became the principal members of a new hacking group called “Lulz Security” or “LulzSec.” Like Internet Feds, LulzSec undertook a campaign of malicious cyber assaults on the websites and computer systems of various business and governmental entities in the United States and throughout the world. Specifically, ACKROYD, DAVIS, MARTYN, and MONSEGUR, as members of LulzSec, conspired to commit computer hacks including the hacks of computer systems used by the PBS, in retaliation for what LulzSec perceived to be unfavorable news coverage in an episode of the news program “Frontline”; Sony Pictures Entertainment, in which LulzSec stole confidential data concerning approximately 100,000 users of Sony’s website; and Bethesda Softworks, a video game company based in Maryland, in which LulzSec stole confidential information for approximately 200,000 users of Bethesda’s website.
The Stratfor Hack
In December 2011, HAMMOND conspired to hack into computer systems used by Stratfor, a private firm that provides governments and others with independent geopolitical analysis. HAMMOND and his co-conspirators, as members of AntiSec, stole confidential information from those computer systems, including Stratfor employees’ e-mails as well as account information for approximately 860,000 Stratfor subscribers or clients. HAMMOND and his co-conspirators stole credit card information for approximately 60,000 credit card users and used some of the stolen data to make unauthorized charges exceeding $700,000. HAMMOND and his co-conspirators also publicly disclosed some of the confidential information they had stolen.
The Hack of International Law Enforcement
In January 2012, O’CEARRBHAIL hacked into the personal e-mail account of an officer with Ireland’s national police service, the An Garda Siochana (the “Garda”). Because the Garda officer had forwarded work e-mails to a personal account, O’CEARRBHAIL learned information about how to access a conference call that the Garda, the FBI, and other law enforcement agencies were planning to hold on January 17, 2012 regarding international investigations of Anonymous and other hacking groups. O’CEARRBHAIL then accessed and secretly recorded the January 17 international law enforcement conference call, and then disseminated the illegally-obtained recording to others.
***
MONSEGUR, 28, of New York, New York, pled guilty to three counts of computer hacking conspiracy, five counts of computer hacking, one count of computer hacking in furtherance of fraud, one count of conspiracy to commit access device fraud, one count of conspiracy to commit bank fraud, and one count of aggravated identity theft. He faces a maximum sentence of 124 years and six months in prison.
ACKROYD, 23, of Doncaster, United Kingdom; DAVIS, 29, of Lerwick, Shetland Islands, United Kingdom; and MARTYN, 25, of Galway, Ireland, each are charged with two counts of computer hacking conspiracy. Each conspiracy count carries a maximum sentence of 10 years in prison.
O’CEARRBHAIL, 19, of Birr, Ireland, is charged in the indictment with one count of computer hacking conspiracy, for which he faces 10 years in prison. He is also charged in the complaint with one count of intentionally disclosing an unlawfully intercepted wire communication, for which he faces a maximum sentence of five years in prison.
HAMMOND, 27, of Chicago, Illinois, is charged with one count of computer hacking conspiracy, one count of computer hacking, and one count of conspiracy to commit access device fraud. Each count carries a maximum sentence of 10 years in prison.
DAVIS is separately facing criminal charges in the United Kingdom, which remain pending, and ACKROYD is being interviewed today by the Police Central e-crime Unit in the United Kingdom. O’CEARRBHAIL was arrested today by the Garda.
The case is being prosecuted by the U.S. Attorney’s Office for the Southern District of New York. The investigation was initiated and led by the FBI, and its New York Cyber Crime Task Force, which is a federal, state, and local law enforcement task force combating cybercrime, with assistance from the PCeU; a unit of New Scotland Yard’s Specialist Crime Directorate, SCD6; the Garda; the Criminal Division’s CCIPS; and the U.S. Attorneys’ Offices for the Eastern District of California, the Central District of California, the Northern District of Georgia, and the Eastern District of Virginia; as well as the Criminal Division’s Office of International Affairs.
The charges contained in the indictment and complaints are merely accusations, and the defendants are presumed innocent unless and until proven guilty.

Monday, March 5, 2012

The Bright Side of Being Hacked

Excerpt from an article in

The New York Times
Monday, March 05, 2012

The Bright Side of Being Hacked

By SOMINI SENGUPTA and NICOLE PERLROTH

SAN FRANCISCO — Hackers operating under the banner Anonymous have been poking a finger in the eye of one private company after another for two years now.

They steal files from inside corporate computer systems and occasionally, as in the case of Stratfor last week, dump company e-mail online for all to see.

The Stratfor hack, in which Anonymous claimed to have joined forces with WikiLeaks, drove home a clear lesson about the era of ubiquitous “hactivism,” or hacking as a form of protest.

Despite the arrests of dozens of suspected members of Anonymous and its offshoots worldwide, it is far from diminished. Nor have most of its corporate targets been irreparably damaged by the attacks.

Rather, what Anonymous has done, experts said at the big RSA computer security conference here last week, is raise the alarm about the unguarded state of corporate computer systems.

By and large, the Anonymous break-ins take advantage of gaping computer holes and gullible human beings. The hackers ferret out weak passwords and take advantage of unencrypted e-mail stashes. They persuade company employees — one is all it takes — to click on rogue Web sites or divulge a confidential piece of information, in an exercise known as social engineering.

“Anonymous is a wake-up call,” said Roger Cressey, senior vice president of Booz Allen Hamilton, a defense and intelligence contractor that was attacked by the group last summer. “Any company that is patting themselves on the back and saying that they’re not a target or not susceptible to attack is in complete and utter denial.”

More to the point, a company that is a target of Anonymous may also be the target of a far more potent adversary. The social engineering tactics that Anonymous members have repeatedly used are often similar to those used by criminal hackers and state-sponsored actors who penetrate company systems in order to steal valuable secrets, whether for monetary gain or competitive edge.

Wednesday, February 29, 2012

25 Suspected Hackers Arrested

Excerpt from an article in

The New York Times
Wednesday, February 29, 2012

25 Suspected Hackers Arrested in International Raids

By THE ASSOCIATED PRESS

PARIS (AP) — Twenty-five suspected members of the loose-knit Anonymous hacker movement have been arrested in a sweep across Europe and South America, Interpol, the global police agency, said on Tuesday.

The arrests, in Argentina, Chile, Colombia and Spain were carried out by national law-enforcement officers working under the support of Interpol’s Latin American Working Group of Experts on Information Technology Crime, Interpol said in a statement.

Those arrested, who ranged in age between 17 and 40, are suspected of planning coordinated cyber-attacks against institutions including Colombia’s defense ministry and presidential Web sites, Chile’s Endesa electricity company and national library, and other targets.

The arrests followed an ongoing investigation begun in mid-February, which comprised searches of 40 locations in 15 cities and included the seizure of 250 pieces of information technology equipment and mobile phones, Interpol said.

Among the 25 people arrested were four suspected Anonymous hackers seized in connection with attacks on Spanish political party Web sites, the Spanish police announced. A national police statement said two servers used by the group in Bulgaria and the Czech Republic have been blocked. It said the four arrested included the suspected manager of Anonymous’s computer operations in Spain and Latin America, who was identified only by his initials and the aliases “Thunder” and “Pacotron.”

The four are suspected of defacing websites, carrying out denial-of-service attacks and publishing data online about police assigned to the royal palace and the premier’s office.

Anonymous has no real membership structure. Hackers, activists, and supporters can claim allegiance to its freewheeling principles so it is not clear what impact the arrests will have. Some Internet chatter appeared to point to the possibility of a revenge attack on Interpol’s Web site, but the police organization’s home page appeared to be operating normally late Tuesday.

Wednesday, February 15, 2012

Researchers Find Flaw in Online Encryption Method

Excerpt from an article in The New York Times
Wednesday, February 15, 2012

Researchers Find Flaw in an Online Encryption Method 

By JOHN MARKOFF

SAN FRANCISCO — A team of European and American mathematicians and cryptographers have discovered an unexpected weakness in the encryption system widely used worldwide for online shopping, banking, e-mail and other Internet services intended to remain private and secure.

The flaw — which involves a small but measurable number of cases — has to do with the way the system generates random numbers, which are used to make it practically impossible for an attacker to unscramble digital messages. While it can affect the transactions of individual Internet users, there is nothing an individual can do about it. The operators of large Web sites will need to make changes to ensure the security of their systems, the researchers said.

The potential danger of the flaw is that even though the number of users affected by the flaw may be small, confidence in the security of Web transactions is reduced, the authors said.

The system requires that a user first create and publish the product of two large prime numbers, in addition to another number, to generate a public “key.” The original numbers are kept secret. To encrypt a message, a second person employs a formula that contains the public number. In practice, only someone with knowledge of the original prime numbers can decode that message.

For the system to provide security, however, it is essential that the secret prime numbers be generated randomly. The researchers discovered that in a small but significant number of cases, the random number generation system failed to work correctly.

The importance in ensuring that encryption systems do not have undetected flaws cannot be overstated. The modern world’s online commerce system rests entirely on the secrecy afforded by the public key cryptographic infrastructure.

The researchers described their work in a paper that the authors have submitted for publication at a cryptography conference to be held in Santa Barbara, Calif., in August. They made their findings public Tuesday because they believe the issue is of immediate concern to the operators of Web servers that rely on the public key cryptography system.