6 ms·
(This is slightly off the topic of this story) Believe it or not this happens often. I work with R&D / high-tech small businesses that have 1-2 patents or some
by zigzaggy 7y ago
(This is slightly off the topic of this story) Believe it or not this happens often. I work with R&D / high-tech small businesses that have 1-2 patents or some other IP. They provide services to the government but they aren't exactly flush with cash - meaning their infosec programs are slim. So they stay in contact with the FBI and other TLAs (three letter agencies) who will contact them from time to time to say "hey you may want to check your network, we think someone's broken in."
Basically the FBI is the internet police for these infrastructure / science / tech / etc. firms. It's not hard to understand why this information isn't out on the street more.
- stingraycharles 7y agoYes but we’re talking about Citrix here, not some random small business supplier. In Citrix’ case it is bad to be in the position that the FBI had to tell you someone was brute forcing your app.
- deleted 7y ago[deleted]
- zigzaggy 7y agoTrue, and I agree it is bad. But I stand by my original comment. I believe all this happens far more often than we know right now. I predict we'll be finding out in the not so distant future that we've all been targeted and breached. All our data are belong to them.
- solotronics 7y agoHow are they finding out in the first place? Either they have the capability to watch and decrypt the overall public traffic or they are already inside themselves.
- netsharc 7y agoParanoid much? Other ways could be intelligence work: the FBI might be monitoring "hacker" hangouts and someone bragged about it/is selling access. If it was a nation state: The CIA might be inside their system (technically or personnel-wise) and saw evidence, and told the FBI.
- streb-lo 7y agoOr someone trying to sell credentials or info from xyz.com tips people off in a hurry. Do we always need to jump straight to conspiracy...
- NickNameNick 7y agoUsually it will be because they were investigating something else, and either seized a hackers device, or gained access to a hackers servers. Device or servers will then have evidence of the other things the hacker and thier associates have been doing. Sometimes criminals brag about things. Other times, the compromised infrastructure is used in other criminal activity that gets detected by the next victim, and the law enforcement agencies work thier way back.
- mox1 7y agoThe NSA will pass information like this to the FBI as well (through the NCIJTF). They usually omit / redline enough information to make it Unclassified.
- kortilla 7y agoDuring other takedowns the FBI will seize a C&C server. They can then see which IP addresses it has talking to it.
- Spooky23 7y agoThere are a few programs where they get visibility. The fusion centers in each state, for example can detect some of this type of activity.
- miscPerson 7y agoThe FBI has a whole threat intel sharing program — actually, several. In this case, it could be as simple as another company noticed a breach that was reporting back to Citrix-hosted C2 and contacted the FBI, who passed the message along. Hosting C2 on compromised Citrix assets would be a great way to evade detection in a corporate environment.