13 ms·
U.S. Army Soldier Arrested in AT&T, Verizon Extortions
- fifteen1506 2y agoThank god EU is going to take this in consideration next time ChatControl is being proposed. /s
- cynicalsecurity 2y agoThanks flying Spaghetti monster EU is more free than US.
- daghamm 2y agoI first heard about this dude many months ago. Why did it take so long to bring him in? He was pretty open about who he is and what he is doing.
- soneca 2y agoThe article establishing his identity was only published a month ago[1] and the security expert seems to be impressed with how fast it took to bring him in. ”Between when we, and an anonymous colleague, found his opsec mistake on November 10th to his last Telegram activity on December 6, law enforcement set the speed record for the fastest turnaround time for an American federal cyber case that I have witnessed in my career,” she said. [1] https://krebsonsecurity.com/2024/11/hacker-in-snowflake-extortions-may-be-a-u-s-soldier/ https://krebsonsecurity.com/2024/11/hacker-in-snowflake-exto...
- daghamm 2y agoBy the time kerb published his story this has being going on for a long long while. He was openly bragging about being in army and stationed in SK. I mean, didn't army or some agency start investigating this before Kerb?
- jjulius 2y ago> I mean, didn't army or some agency start investigating this before Kerb? How do we know that they didn't?
- siva7 2y agoSo what was his opsec mistake so that we can learn something from this case?
- throwaway290 2y ago> On November 26, KrebsOnSecurity published a story that followed a trail of clues left behind by Kiberphantom indicating he was a U.S. Army soldier stationed in South Korea Read the article, There is a link in that sentence.
- formerly_proven 2y agohttps://news.ycombinator.com/item?id=42251799 https://news.ycombinator.com/item?id=42251799
- oefrha 2y agoThe main takeaway for me is the following. Everything you post online will end up in a public archive. That includes everything you post to supposedly private or semi-private venues, like Telegram channels. Everything you posted when you were a dumb kid will be there too, however long ago that was. So, if you’re gonna be a cybercrminal, make absolutely sure that you start with a clean slate. No one can know the connections to your past, because even if you’re careful, other idiots can let slip (like using your old moniker to address you) at any time. And don’t post fucking photos, ever.
- gorbachev 2y agoAnd don't brag about your crimes after the fact online, or anywhere else either.
- oefrha 2y agoBoasting is required in his line of work, that's how they build street rep, sell their products/services, and recruit people. (Contrast this to spycraft where the acceptable amount of boasting is zero.) What did him in was boasting from a non-clean slate identity among other things. He needed strict separation between big time jobs which require an absolute clean slate because all the attention will be there, small time jobs that are likely numerous and sloppier but no one will bother to investigate, and pleasure. He didn't have that.
- deleted 2y ago[deleted]
- perihelions 2y agoAdditional comments here, https://news.ycombinator.com/item?id=42251799 https://news.ycombinator.com/item?id=42251799 ("Hacker in Snowflake extortions may be a U.S. soldier (krebsonsecurity.com)"; 34 days ago, 195 comments)
- reversethread 2y agoFunny looking back on all the comments about how it was potentially a false flag.
- t_mann 2y agoWhich comments are you looking at? By a brief scan, the vast majority of comments, including practically all the top-voted ones, are calling out his "opsec troll" as a deflection strategy, which appears to have been confirmed now. Even if there are some that bought his story, your comment does not seem like an adequate reflection of the general tone of that thread.
- 542354234235 2y ago>your comment does not seem like an adequate reflection of the general tone of that thread. I don't think they were trying to capture the "general tone" but a pervasive idea that kept coming up in the comments. When I saw the headline, the first thing I thought about was this thread and "all the comments" talking about 3D chess false flag moves. Not the majority, not the overall sentiment, but just a significant number of eye rolling comments.
- mktemp-d 2y agoTelegram users spinning up their own honeypots and blindly trusting a client/server message encryption system is never not a great idea for new grass root criminal enterprises.
- assanineass 2y agoBy grass root you mean not state sponsored? Agreed it’s not a good idea using Telegram as a server, people forget bots have chat history you can replay too
- duxup 2y agoI find that some folks who know just a little about security are some of the worst at it. Their ability to confidently make terrible choices and inexplicably expose themselves to more risk than some rando citizen is amazing. It's like their strong enthusiasm / personal beliefs drive them head long into inexplicable choices and now their eggs are all in one insecure basket and they put a lot of foolish things there. In contrast a more nervous / unknowing person might think "oh man I better not talk about this anywhere, I don't know who could be listening".
- JohnMakin 2y agoIt's like that classic bell curve troll meme - "oh man I better not talk about this anywhere, I don't know who could be listening" is a correct instinct, especially in a western country. Doing anything on the web, whether it be crimes and ecommerce, is absolutely not anonymous. They re-use handles or emails that have personally identifying information, they don't use clean workstations, they brag (dumbest opsec thing ever, giving away information for absolutely no reason than your big ego), they taunt law enforcement. Osama bin Laden basically vanished off the face of the planet when much of the world's most powerful intelligence and militaries were hunting him, and he wasn't hiding in a cave, but he was not connected to the internet in any way whatsoever and communicated via courier, which still got got. The only reason you are anonymous or think you are anonymous is because no one powerful or determined enough has gone looking yet. This is a fact I am convinced of, and I am much more fearful of successful obfuscation tactics and red herrings left on purpose rather than a 20 year old kid engaging in a fantasy that he's so l33t he'll never get caught. The other thing I'd say to any aspiring criminals out there is it's usually much less stressful and still profitable to get gainful employment if you are actually a talented hacker. Most of these guys seem like script kiddies, that do not understand the ramifications of what they are doing. Some of these breaches will be felt and cleaned up for decades, all so they could get a laugh and a few shekels and their e-peens stroked by other criminals.
- chuckSu 2y ago[dead]
- profsummergig 2y agoHere's the tragedy: the free world actually needs people with his skills working on their side.
- trimethylpurine 2y agoAccording to the article he attempted to sell data that a different person obtained. He didn't retrieve the data himself, so I'm not so sure that he has any skills we need. He isn't even a good salesman, apparently. >Judische said he had no interest in selling the data he’d stolen from Snowflake customers and telecom providers, and that he preferred to outsource that to Kiberphant0m and others. Meanwhile, Kiberphant0m claimed in posts on Telegram that he was responsible for hacking into at least 15 telecommunications firms, including AT&T and Verizon.
- hoofhearted 2y agoNo we don’t lol.. That’s like saying we need plumbers and electricians who come into your house and steal everything.
- alt227 2y agoMake no mistake, he will be forced into hacking for the NSA for the rest of his life under threat of child porn offenses.
- llamaimperative 2y agoSure I’ll make no mistake on this if you can share some evidence
- myko 2y agowhat an odd comment
- oyashirochama 2y agoThat's not how it works, they don't want people who have broke laws anymore especially due to the prior hacker leaks (Snowden).
- jcpham2 2y ago“Law Enforcement wants to put you in jail for a very long time” The CFAA[1][2] is an arcane and ancient piece of legislation that could use an overhaul, especially with some of the vague language it contains. A person would definitely want to make sure they are authorized prior to touching a computer or even data that may not have authorization for. Unauthorized use of a computer is the easiest felony to commit accidentally it would seem. Although in this case I don’t think that’s a legitimate argument to be made. This person or persons knew they were committing crimes. I’m not defending the hacker either, the quote at the end of the article rings true. [1] https://www.justice.gov/jm/jm-9-48000-computer-fraud https://www.justice.gov/jm/jm-9-48000-computer-fraud [2] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
- tg180 2y ago> The CFAA[1][2] is an arcane and ancient piece of legislation that could use an overhaul, especially with some of the vague language it contains. I imagine that this is the reason why the charge is "unlawful transfer of confidential phone records", which is something much more specific. From PACER, it's also stated that he filled out the CJA23 financial affidavit to demonstrate his inability to afford a lawyer (it's quite something to get caught like this and not even manage to earn enough to pay for a lawyer). Additionally, "the defendant waives the rights provided by Rule 5 and/or Rule 32.1 of the Federal Rules of Criminal Procedure" means that he is choosing to streamline the initial procedures and is waiving supervised release or probation, suggesting that the prosecution's case is strong and that he is opting for an expedited process.
- oyashirochama 2y agoOne fun thing is personal recording isn't a protected right in the military and has to be stated if you're recording in an office for personal reasons. (official recording is usually stated as a usage agreement), or literally put on the device as a sticker. He's also a low level enlisted so its not surprising he was unable to afford a lawyer.
- oyashirochama 2y ago
- boomskats 2y agoSo does anyone know whether he did the full Cornholio impression when they arrested him?
- bru3s 2y ago[flagged]
- MarkusWandel 2y agoCurious: What happens to a military service member who does this? Punished within the military and then booted out (and with what kind of discharge?) Or booted out first (with what kind of discharge?) and then punished in the regular civilian system? Or possibly even retained in the military?
- christina97 2y agoIt’s called a court martial.
- oyashirochama 2y agoCourts martial, its weirdly plural since its a title/noun of something specific.
- Symbiote 2y agoIt's a court martial, since the use was singular. https://en.wikipedia.org/wiki/Court-martial https://en.wikipedia.org/wiki/Court-martial
- xyst 2y agoProbably sent here: https://en.m.wikipedia.org/wiki/United_States_Disciplinary_Barracks https://en.m.wikipedia.org/wiki/United_States_Disciplinary_B... (Leavenworth)
- oyashirochama 2y agoDepends on length, if he's convicted for greater than I think 90 days, he'll be there, less it'll be base confinement usually to his dorms/barracks. They will likely just do a quick boot and access removal since it sounds like he was just a middleman. and a BCD discharge at worst, or other-than-honorable discharge.
- bumby 2y agoThey are generally under the jurisdiction of the Uniform Code of Military Justice. So usually punished and sentenced within the military and eventually separated with a bad conduct or other-than-honorable discharge. Dishonorable discharge is exceedingly rare.
- xyst 2y agoSo this person, “kiberphant0m”, was just a middleman to sell the data? At best, he is a skid and low level foot soldier. Government using this to send a loud message to future skiddies - “don’t fuck with us”
- 9cb14c1ec0 2y agoSo an army soldier who was clearly part of military intelligence services goes rogue and does some hacking on his own. I've always wondered what it would look like if an NSA-type went rogue. Now we know.
- ChumpGPT 2y agoDid you forget about Edward Snowden?
- anonym29 2y agoThe hero who revealed to the American public that their own government was secretly treating them like hostile foreigners and lying about it to our faces? And that everyone who collaborated to build the collection infrastructure violated the oath they swore to uphold the constitution, given that the mere collection itself was ruled unconstitutional by a federal judge? That's not going rogue, that was the most heroic and patriotic thing anyone in his shoes could possibly do.
- 2OEH8eoCRo0 2y agoSnowdon is a traitor and a coward. Where is he living these days?
- booleandilemma 2y agoSomewhere our beloved leaders can't arrest him and send him to a CIA black site for the rest of his life.
- wyldfire 2y agoI don't think he's a traitor, especially if you consider the intent of his disclosures and the care he took to make sure that only the info that needed to be disclosed was. I suppose we can agree to disagree on that topic. But "cowardice" - that claim is just mind-boggling. What he did, even if you disagree with his motivations, required self sacrifice and bravery. Fleeing (what he believes to be) unjust laws that would punish him for his work is not at all cowardly.
- ChumpGPT 2y ago[flagged]
- datavirtue 2y agoThat bold font needs to die in a fire.
- c64d81744074dfa 2y agoFor some reason I find this kind of sad. This kid seems like a Dunning Kruger effect poster boy. I mean, when I was younger I would have been gleeful about some bragging idiot getting busted but now, *shrug*, everyone just has some "condition".
- chmod775 2y agoAm I the only one who feels that Brian's tendency to include lots of personal details (of suspects and people he doesn't like) in his articles is weird and creepy? His reporting looks more and more like the Daily Mail of cybersecurity. Occasionally very good investigative journalism, yet always aggressively devoid of class.
- mardifoufs 2y agoYes, not sure what it adds to the articles either. The only thing that it ends up doing is making any miss from his end a much more serious thing, because he basically can't get stuff wrong without more or less defaming someone (which has happened in the past)
- ipdashc 2y ago> Am I the only one Nope, I've heard others mention it before as well. I subscribed to the newsletter at one point and I don't think I've gotten a single useful technical article (which is fair, that's not necessarily his niche), but I have gotten a bunch of emails that just doxx random people.
- santoshalper 2y agoI don't see how you're going to catch people like this without doxxing them. They rely on opsec and misdirection to avoid getting caught. Do you have examples where the information was gratuitous?
- chmod775 2y agoI'm specifically speaking of what he chooses to include in his articles.
- simoncion 2y agoThe following isn't really directed at you, but are more general questions for the folks who are throwing around doxxing claims: When the has-never-been-sealed Federal Grand Jury indictment that the article links to has the fellow's full name and alleged area of operation during the alleged crime, is publishing their full name in your article doxing them? If it isn't, is providing screenshots of their publicly-available Facebook profile photos doxxing? Is providing the presumably-willingly-given-for-publication name of the person's mother who you performed an on-the-record interview for the topic of the article doxxing? Is it doxxing to provide details from previous investigative articles that you've done into folks who use their handles to credibly publicly declare that they've committed noteworthy computer crimes?
- smrtinsert 2y ago“I know that young people involved in cybercrime will read these articles,” Nixon said. “You need to stop doing stupid shit and get a lawyer. Law enforcement wants to put all of you in prison for a long time.” I think law enforcement types are just built differently. Fearless even when threats are being made against them.
- boogieknite 2y ago"Allison Nixon has three passions, tracking down bad guys, growing tomatoes, and making puns." - https://www.unit221b.com/leadership https://www.unit221b.com/leadership i think i could have guessed 2 and 3 at a glace. if Allison speaks like this all the time she needs her own tv show
- spooky777 2y agoThe recent arrest of a U.S. Army soldier accused of extorting AT&T and Verizon highlights a troubling misallocation of resources by law enforcement, especially when juxtaposed against critical nation-state cyber threats. While prosecuting such crimes is necessary, it diverts attention from larger systemic vulnerabilities, such as the recent breach of the U.S. Treasury Department and nine major American telecommunications companies by Chinese state actors. These breaches granted access to sensitive communications and revealed the glaring weaknesses in American cybersecurity infrastructure. Corporations like AT&T and Verizon, entrusted with protecting sensitive data, have often failed to implement robust defenses, leaving systems exposed to exploitation and forcing law enforcement into a reactive cleanup role. This misdirected focus is particularly concerning given the escalating geopolitical tensions and the strategic importance of cybersecurity in national defense. Nation-state actors like China are leveraging advanced capabilities to outpace U.S. defenses, eroding trust in American institutions and diminishing global standing. With the potential for conflict over Taiwan and other critical flashpoints, resources spent on low-value cybercrime cases should instead fortify critical infrastructure and counter nation-state threats. A proactive approach is essential to prevent breaches, hold corporations accountable, and ensure the U.S. remains resilient in an increasingly volatile cyber landscape.
- JohnnyLarue 2y agoIf this dink were Chinese, he'd be called a "state-sponsored hacking group"