Search This Blog

Showing posts with label intrusions. Show all posts
Showing posts with label intrusions. Show all posts

Saturday, March 31, 2012

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities

Florida Man Pleads Guilty to Computer Intrusion and Wiretapping Scheme Targeting Celebrities 

U.S. Attorney’s OfficeMarch 26, 2012
  • Central District of California(213) 894-2434
LOS ANGELES—A Florida man pleaded guilty today to a series of cyber-related crimes relating to his hacking into the personal e-mail accounts of more than 50 individuals associated with the entertainment industry.
Christopher Chaney, 35, of Jacksonville, Florida, pleaded guilty to nine felony counts of a 28-count first superseding indictment, including unauthorized access to protected computers in furtherance of wiretapping and wire fraud, unauthorized damage to protected computers resulting in more than $5,000 loss and physical harm, and wiretapping. At the conclusion of the hearing, United States District Court Judge S. James Otero ordered Chaney taken into custody.
During the hearing, Chaney admitted that from at least November 2010 to October 2011, he hacked into the e-mail accounts of Scarlett Johansson, Mila Kunis, Renee Olstead, and others by taking the victims’ e-mail addresses, clicking on the “Forgot your password?” feature, and then re-setting the victims’ passwords by correctly answering their security questions using publicly available information he found by searching the Internet. Once Chaney gained exclusive control of the victims’ e-mail accounts, he was able to access all of their e-mail boxes. While in the accounts, Chaney also went through their contact lists to find e-mail addresses of potential new hacking targets.
In pleading guilty to the wiretapping charges, Chaney admitted that, for most victims, he also changed their e-mail account settings by inserting his alias e-mail address into the forwarding feature so that a duplicate copy of all incoming e-mails to the victims—including any attachments—would be sent virtually simultaneously to Chaney without the victims’ knowledge. Most victims did not check their account settings, so even after they regained control of their e-mail accounts, Chaney’s alias address remained in their account settings. As a result, for many victims, copies of their incoming e-mails, including attachments, were sent to Chaney for weeks or months without their knowledge, causing Chaney to receive thousands of victim e-mails. In addition, when a victim reset his/her password to regain control of the account, Chaney sometimes hacked into the account again and reset the password, sometimes multiple times, in order to continue illegally accessing that victim’s account.
Chaney admitted that as his hacking scheme became more extensive, he began using a proxy service called “Hide My IP” because he knew what he was doing was illegal and wanted to “cover his tracks” so that law enforcement agents could not trace the hacking back to his home computer. Even after his home computers were seized by law enforcement agents pursuant to a federal search warrant, but before he was arrested, Chaney used another computer to hack into another victim’s e-mail account.
Chaney further admitted that as a result of his hacking scheme, he obtained numerous private communications, private photographs, and confidential documents from the victims’ e-mail accounts. The confidential documents included business contracts, scripts, letters, driver’s license information, and Social Security information. On several occasions, after hacking into victim accounts, Chaney sent e-mails from the hacked accounts to friends of the victims, fraudulently posing as the victims to request more private photographs. Chaney downloaded many of the confidential documents and photographs he stole to his home computer, where he saved them on his hard drive in separate computer file folders. Chaney e-mailed many of the stolen photographs to others, including another hacker and two gossip websites. As a result, some of those stolen photographs, several of which were explicit, were later posted on the Internet.
“Today’s guilty pleas shine a bright light on the dark underworld of computer hacking,” said United States Attorney AndrĂ© Birotte, Jr., whose office prosecuted the case. “This case demonstrates that everyone, even public figures, should take precautions to shield their personal information from the hackers that inhabit that dark underworld. It also demonstrates that the Department of Justice will take whatever steps are necessary to protect Americans from harm in cyberspace.”
“Mr. Chaney’s admission to compromising victim accounts, utilizing both technically and socially engineered means, demonstrates the persistence and extent to which a hacker will go to obtain private information,” said Steven Martinez, Assistant Director in Charge of the FBI’s Los Angeles Field Office. “This case sends an important message to all users of Internet-accessible media that practicing good computer security makes us less vulnerable to this type of attack. The FBI remains committed to investigating cyber adversaries who target protected computers, whether of private citizens or the nation’s critical infrastructure.”
Each charge of unauthorized access to a protected computer carries a maximum of five years in prison, each charge of unauthorized damage to a protected computer carries a maximum charge of 10 years in prison, and each charge of wiretapping carries a maximum of five years in prison. As a result of all of today’s guilty pleas, Chaney faces a total statutory maximum sentence of 60 years in federal prison. In addition to the possible prison term, as part of his plea agreement filed in federal court, Chaney agreed to forfeit his computers and related devices seized during the investigation, to pay restitution to all of the victims for any losses they suffered, and to comply with strict restrictions regarding his future use of computers and computer-related devices. In exchange, the government agreed to dismiss the remaining counts, including nine counts of aggravated identity theft, at the time defendant is sentenced.
Chaney is scheduled to be sentenced by United States District Judge S. James Otero on July 23, 2012.
The investigation of this case was led and conducted by the Federal Bureau of Investigation.

Sunday, January 29, 2012

Atlanta Man Sentenced on Computer Hacking Charge

Press release from the FBI, Atlanta Division:


Atlanta Man Sentenced on Computer Hacking Charge
McNeal Illegally Accessed Database of Competitor’s Medical Practice

U.S. Attorney’s Office January 10, 2012
  • Northern District of Georgia (404) 581-6000


ATLANTA—ERIC McNEAL, 38, of Atlanta, Georgia, was sentenced today by United States District Judge Willis B. Hunt, Jr. for intentionally accessing a protected computer of a competing medical practice without authorization, including personal information of the patients, in order to send marketing materials to these patients.

United States Attorney Sally Quillian Yates said, “Anyone who gives their personal information to a doctor or medical facility does not expect that their information will be hacked and used to make money. The cost of medical care is already high enough without patients having to pay a heavier cost with the loss of their privacy. This is cybercrime. Electronic information is bought, sold and stolen, often by someone who knows a system and, with a few keystrokes, makes our community vulnerable.”

McNEAL was sentenced to one year and one month in prison, to be followed by three years of supervised release, and was ordered to perform 120 hours of community service. McNEAL pleaded guilty to the charge on September 28, 2011.

According to United States Attorney Yates, the charge,s and other information presented in court: McNEAL worked as an information technology specialist for “A.P.A.,” a perinatal medical practice in Atlanta.

McNEAL separated from employment with A.P.A. in November 2009, and subsequently joined a competing perinatal medical practice, which was located in the same building as A.P.A. In April 2010, MCNEAL used his home computer to hack into A.P.A.’s patient database without authorization. MCNEAL downloaded the names, telephone numbers, and addresses of A.P.A.’s patients, and then “wiped” A.P.A.’s database, deleting all the patient information from A.P.A.’s system. McNEAL subsequently used the patient names and contact information to launch a direct-mail marketing campaign for the benefit of his new employer. There is no evidence that McNEAL downloaded or misused specific patient medical information.

This case was investigated by special agents of the Federal Bureau of Investigation.