Search This Blog

Showing posts with label COMPUTER HACKING. Show all posts
Showing posts with label COMPUTER HACKING. Show all posts

Monday, October 3, 2016

SYRIAN NATIONAL PLEADS GUILTY IN CASE INVOLVING EXTORTION AND COMPUTER HACKING

FROM:  U.S. JUSTICE DEPARTMENT 
Wednesday, September 28, 2016
Syrian Electronic Army Hacker Pleads Guilty

Peter Romar, 37, a Syrian national affiliated with the Syrian Electronic Army (SEA), pleaded guilty today to felony charges of conspiring to receive extortion proceeds and conspiring to unlawfully access computers.  Romar was previously extradited from Germany on request of the U.S.

Assistant Attorney General for National Security John P. Carlin, U.S. Attorney Dana J. Boente for the Eastern District of Virginia, Assistant Director James Trainor of the FBI’s Cyber Division and Assistant Director in Charge Paul M. Abbate of the FBI’s Washington Field Office, made the announcement after the sentencing by U.S. District Judge Claude M. Hilton.

“Today’s guilty plea is by the latest international offender who believed that he could operate from abroad, behind the perceived veil of anonymity offered by the Internet, and use computers to threaten the security of our citizens and their property,” said Assistant Attorney General Carlin. “It shows that the Department of Justice and the FBI stand behind their pledge to hold accountable foreign actors who assist in the hacking of U.S. victims.”

According to the statement of facts filed with the plea agreement, beginning in approximately 2011, co-defendant Firas Dardar, known online as “The Shadow,” and other members of the SEA engaged in a multi-year criminal conspiracy to conduct computer intrusions against perceived detractors of Syrian President Bashar al-Assad, including media entities, the U.S. government and foreign governments.  Dardar remains at large.

Beginning in approximately 2013, Romar and Dardar engaged in an extortion scheme that involved hacking online businesses in the U.S. and elsewhere for personal profit. Court documents further allege that the conspiracy gained unauthorized access to the victims’ computers and then threatened to damage computers, delete data, or sell stolen data unless the victims provided extortion payments to Dardar and/or Romar.  If a victim could not make extortion payments to the conspiracy’s Syrian bank accounts due to sanctions targeting Syria, Romar acted as an intermediary in Germany to evade those sanctions.

“Cybercriminals cannot hide from justice,” said U.S. Attorney Dana J. Boente for the Eastern District of Virginia. “No matter where they are in the world, the United States will vigorously pursue those who commit crimes against U.S. citizens and hold them accountable for their actions.”

Romar faces a maximum penalty of five years in prison and will be sentenced on October 21. The maximum statutory sentence is prescribed by Congress and is provided here for informational purposes, as the sentencing of the defendant will be determined by the court based on the advisory Sentencing Guidelines and other statutory factors.

The case was investigated by the FBI’s Washington Field Office, with assistance from the NASA Office of the Inspector General, the Department of State Bureau of Diplomatic Security and other law enforcement agencies.

The case was prosecuted by Assistant U.S. Attorneys Maya D. Song and Jay V. Prabhu and Special Assistant U.S. Attorney Brandon L. Van Grack of the Eastern District of Virginia, and Trial Attorneys Scott McCulloch and Nathan Charles of the National Security Division’s Counterintelligence and Export Control Section.  The Justice Department’s Office of International Affairs also provided significant assistance.

Friday, September 2, 2016

GUCCIFER GOES TO JAIL

Thursday, September 1, 2016
Romanian Hacker “Guccifer” Sentenced to 52 Months in Prison for Computer Hacking Crimes

Marcel Lehel Lazar, 44, of Arad, Romania, a hacker who used the online moniker “Guccifer,” was sentenced today to 52 months in prison for unauthorized access to a protected computer and aggravated identity theft.

Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, U.S. Attorney Dana J. Boente of the Eastern District of Virginia, Assistant Director in Charge Paul M. Abbate of the FBI’s Washington Field Office, Director Bill A. Miller of the U.S. Department of State’s Diplomatic Security Service (DSS) and Special Agent in Charge Brian J. Ebert of the U.S. Secret Service’s Washington Field Office made the announcement.

Lazar pleaded guilty before U.S. District Judge James C. Cacheris of the Eastern District of Virginia on May 25, 2016.

According to admissions made in connection with his plea agreement, from at least October 2012 to January 2014, Lazar intentionally gained unauthorized access to personal email and social media accounts belonging to approximately 100 Americans, and he did so to unlawfully obtain his victims’ personal information and email correspondence.  Lazar’s victims included an immediate family member of two former U.S. presidents, a former member of the U.S. Cabinet, a former member of the U.S. Joint Chiefs of Staff and a former presidential advisor, he admitted.  In many instances, Lazar publically released his victims’ private email correspondence, medical and financial information and personal photographs, according to the statement of facts filed with his plea agreement.

The FBI, DSS and the Secret Service investigated the case.  Senior Counsel Ryan K. Dickey and Peter V. Roman of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorneys Maya D. Song and Jay V. Prabhu of the Eastern District of Virginia are prosecuting the case.  The Criminal Division’s Office of International Affairs provided significant assistance.  The Justice Department thanks the government of Romania for their assistance in this matter.

Sunday, January 17, 2016

MAN PLEADS GUILTY TO UNAUTHORIZED ACCESS TO HOUSTON ASTROS COMPUTERS

FROM:  U.S. JUSTICE DEPARTMENT
Friday, January 8, 2016
Former St. Louis Cardinals Official Pleads Guilty to Houston Astros Computer Intrusions

The former director of Baseball Development for the St. Louis Cardinals made an initial appearance in Houston federal court today on charges of accessing the Houston Astros’ computers without authorization, announced U.S. Attorney Kenneth Magidson of the Southern District of Texas and Special Agent in Charge Perrye K. Turner of the FBI Houston Division.  Later this afternoon, the former Cardinals official then entered a guilty plea to all counts as charged.

Christopher Correa, 35, of St. Louis, was charged in a criminal information with five counts of unauthorized access of a protected computer.  No other personnel associated with the Cardinals organization have been charged.

“We have secured an appropriate conviction in this case as a result of a very detailed, thorough and complete investigation,” said U.S. Attorney Magidson.  “Unauthorized computer intrusion is not to be taken lightly.  Whether it’s preserving the sanctity of America’s pastime or protecting trade secrets, those that unlawfully gain proprietary information by accessing computers without authorization must be held accountable for their illegal actions.”

From 2009 to July 2015, Correa was employed by the St. Louis Cardinals and became the director of Baseball Development in 2013.  In this role, he provided analytical support to all areas of the Cardinals’ baseball operations.  Correa is no longer employed by the Cardinals organization.

The Astros and the Cardinals, like many teams, measured and analyzed in-game activities to look for advantages that may not have been apparent to their competitors.  To assist their efforts, the Astros operated a private online database called Ground Control to house a wide variety of confidential data, including scouting reports, statistics and contract information.  The Astros also provided e-mail accounts to their employees.  Ground Control and Astros e‑mails could be accessed online via password-protected accounts.

As part of his plea agreement, Correa admitted that from March 2013 through at least March 2014, he illicitly accessed the Ground Control and/or e-mail accounts of others in order to gain access to Astros proprietary information.

“The theft of intellectual property by computer intrusion is a serious federal crime,” said Special Agent in Charge Turner.  “The Houston Cyber Task Force stands ready to identify, pursue and defeat cyber criminals who gain unauthorized access to proprietary data.  In each and every case, we will seek to hold those accountable to the fullest extent of the law.”

In one instance, Correa was able to obtain an Astros employee’s password because that employee has previously been employed by the Cardinals.  When he left the Cardinals organization, the employee had to turn over his Cardinals-owned laptop to Correa along with the laptop’s password.  Having that information, Correa was able to access the now-Astros employee’s Ground Control and e-mail accounts using a variation of the password he used while with the Cardinals.

The plea agreement details a selection of instances in which Correa unlawfully accessed the Astros’ computers.  For example, during 2013, he was able to access scout rankings of every player eligible for the draft.  He also viewed, among other things, an Astros weekly digest page which described the performance and injuries of prospects who the Astros were considering, and a regional scout’s estimates of prospects’ peak rise and the bonus he proposed be offered.  He also viewed the team’s scouting crosscheck page, which listed prospects who were seen by higher level scouts.  During the June 2013 amateur draft, Correa intruded into that account again and viewed information on players who had not yet been drafted as well as several players drafted by the Astros and other teams.

Correa later intruded into that account during the July 31, 2013, trade deadline and viewed notes of the Astros’ trade discussions with other teams.

Another set of intrusions occurred in March 2014.  The Astros reacted by implementing security precautions to include the actual Ground Control website address (URL) and required all users to change their passwords to more complex passwords.  The team also reset all Ground Control passwords to a more complex default password and quickly e‑mailed the new default password and the new URL to all Ground Control users.

Shortly thereafter, Correa illegally accessed the aforementioned person’s e‑mail account and found the e‑mails that contained Ground Control’s new URL and the newly-reset password for all users.  A few minutes later, Correa used this information to access another person’s Ground Control account without authorization.  There, he viewed a total of 118 webpages including lists ranking the players whom Astros scouts desired in the upcoming draft, summaries of scouting evaluations and summaries of college players identified by the Astros’ analytics department as top performers.

On two more occasions, he again illicitly accessed that account and viewed confidential information, such as projects the analytics department was researching, notes of the Astros’ trade discussions with other Major League Baseball teams and reports of players in the Astros’ system and their development.

The parties agreed that Correa masked his identity, his location and the type of device that he used, and that the total intended loss for all of the intrusions is approximately $1.7 million.

Each conviction of unauthorized access of a protected computer carries a maximum possible sentence of five years in federal prison and a possible $250,000 fine.

The charges and conviction are the result of an investigation conducted by the FBI.  Assistant U.S. Attorney Michael Chu of the Southern District of Texas is prosecuting the case.

Sunday, December 13, 2015

FORMER STATE DEPARTMENT EMPLOYEE PLEADS GUILTY TO CRIMES RELATED TO COMPUTER HACKING

FROM:  U.S. JUSTICE DEPARTMENT 
Wednesday, December 9, 2015
Former U.S. State Department Employee Pleads Guilty to Extensive Computer Hacking, Cyberstalking and "Sextortion" Scheme

A former U.S. State Department employee pleaded guilty today to perpetrating a widespread, international e-mail phishing, computer hacking and cyberstalking scheme against hundreds of victims in the United States and abroad.

Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, U.S. Attorney John A. Horn of the Northern District of Georgia, Director Bill A. Miller of the U.S. Department of State’s Diplomatic Security Service and Special Agent in Charge J. Britt Johnson of the FBI’s Atlanta Field Office made the announcement.

Michael C. Ford, 36, of Atlanta, was indicted by a grand jury in the U.S. District Court for the Northern District of Georgia on Aug. 18, 2015, with nine counts of cyberstalking, seven counts of computer hacking to extort and one count of wire fraud.  The names of the victims are being withheld from the public to protect their privacy.

Ford pleaded guilty to all charges and admitted that between January 2013 and May 2015, he used various aliases that included “David Anderson” and “John Parsons” and engaged in a widespread, international computer hacking, cyberstalking and “sextortion” campaign designed to force victims to provide Ford with personal information as well as sexually explicit videos of others.  Ford targeted young females, some of whom were students at U.S. colleges and universities, with a particular focus on members of sororities and aspiring models.

Ford posed as a member of the fictitious “account deletion team” for a well-known e-mail service provider and sent phishing e-mails to thousands of potential victims, warning them that their e-mail accounts would be deleted if they did not provide their passwords.  Ford then hacked into hundreds of e-mail and social media accounts using the passwords collected from his phishing scheme, where he searched for sexually explicit photographs.  Once Ford located such photos, he then searched for personal identifying information (PII) about his victims, including their home and work addresses, school and employment information, and names and contact information of family members, among other things.

Ford then used the stolen photos and PII to engage in an ongoing cyberstalking campaign designed to demand additional sexually explicit material and personal information.  Ford e-mailed his victims with their stolen photos attached and threatened to release those photos if they did not cede to his demands.  Ford repeatedly demanded that victims take sexually explicit videos of “sexy girls” undressing in changing rooms at pools, gyms and clothing stores, and then send the videos to him.

When the victims refused to comply, threatened to go to the police or begged Ford to leave them alone, Ford responded with additional threats.  For example, Ford wrote in one e-mail “don’t worry, it’s not like I know where you live,” then sent another e-mail to the same victim with her home address and threatened to post her photographs to an “escort/hooker website” along with her phone number and home address.  Ford later described the victim’s home to her, stating “I like your red fire escape ladder, easy to climb.”  Ford followed through with his threats on several occasions, sending his victims’ sexually explicit photographs to family members and friends.

Ultimately, Ford sent thousands of fraudulent “phishing” email messages to potential victims, successfully hacked into at least 450 online accounts belonging to at least 200 victims, and forwarded to himself at least 1,300 stolen email messages containing thousands of sexually explicit photographs.  Ford sent threatening and “sextortionate” online communications to at least 75 victims.

During the relevant time period, Ford was employed by the U.S. Embassy in London.  The majority of Ford’s phishing, hacking and cyberstalking activities were conducted from his computer at the U.S. Embassy.

“With nothing more than a computer and a few keystrokes, modern predators like Michael Ford can victimize hundreds of people around the world,” said Assistant Attorney General Caldwell.  “While this criminal prosecution may never return the victims’ sense of security, I hope that today’s guilty plea brings them some peace of mind.”

“Ford engaged in an international sextortion campaign,” said U.S. Attorney Horn.  “He tormented numerous women by threatening to humiliate them unless they provided him with sexually explicit photos and videos, and in some cases, he followed through on his threats.  This case demonstrates the need to be careful in safeguarding personal information and passwords, especially in response to suspicious e-mails.”

“When a public servant in a position of trust commits any form of misconduct, to include federal crimes such as cyberstalking and computer hacking, we vigorously investigate such claims,” said Director Miller.  “The Diplomatic Security Service is firmly committed to investigating and working with the Department of Justice, U.S. Attorney’s Office and our other law enforcement partners to investigate criminal allegations and bring those who commit these crimes to justice.”

“The allegations contained in this federal indictment portray an individual consumed with sexually themed cyber-stalking and exploitation as well as an individual who felt he was beyond detection and grasp of authorities,” said Special Agent in Charge Johnson.  “The FBI is proud of the role it played in working with our law enforcement partners to bring Mr. Ford in for prosecution.”

U.S. District Judge Eleanor L. Ross of the Northern District of Georgia scheduled Ford’s sentencing hearing for Feb. 16, 2016.

The Diplomatic Security Service and the FBI are investigating the case.  Senior Trial Attorney Mona Sedky of the Criminal Division’s Computer Crime and Intellectual Property Section, Trial Attorney Jamie Perry of the Criminal Division’s Human Rights and Special Prosecutions Section and Assistant U.S. Attorney Kamal Ghali of the Northern District of Georgia are prosecuting the case.  The Criminal Division’s Office of International Affairs and the U.S. Embassy in London provided assistance in this case.

Thursday, July 16, 2015

DOJ SAYS 12 CHARGED IN INTERNATIONAL COMPUTER HACKING

FROM:  U.S. DEPARTMENT OF JUSTICE 
Wednesday, July 15, 2015
Major Computer Hacking Forum Dismantled

As Part of Coordinated Law Enforcement Efforts in 20 Countries, United States Charges 12 Defendants in Connection with Computer Fraud Conspiracy

The computer hacking forum known as Darkode was dismantled, and criminal charges have been filed in the Western District of Pennsylvania and elsewhere against 12 individuals associated with the forum, announced Assistant Attorney General Leslie R. Caldwell of the Justice Department’s Criminal Division, U.S. Attorney David J. Hickton of the Western District of Pennsylvania and Deputy Director Mark F. Giuliano of the FBI.

“Hackers and those who profit from stolen information use underground Internet forums to evade law enforcement and target innocent people around the world,” said Assistant Attorney General Caldwell.  “This operation is a great example of what international law enforcement can accomplish when we work closely together to neutralize a global cybercrime marketplace.”

“Of the roughly 800 criminal internet forums worldwide, Darkode represented one of the gravest threats to the integrity of data on computers in the United States and around the world and was the most sophisticated English-speaking forum for criminal computer hackers in the world,” said U.S. Attorney Hickton.  “Through this operation, we have dismantled a cyber hornets’ nest of criminal hackers which was believed by many, including the hackers themselves, to be impenetrable.”

“This is a milestone in our efforts to shut down criminals’ ability to buy, sell, and trade malware, botnets and personally identifiable information used to steal from U.S. citizens and individuals around the world,” said Deputy Director Giuliano.  “Cyber criminals should not have a safe haven to shop for the tools of their trade and Operation Shrouded Horizon shows we will do all we can to disrupt their unlawful activities.”

As alleged in the charging documents, Darkode was an online, password-protected forum in which hackers and other cyber-criminals convened to buy, sell, trade and share information, ideas, and tools to facilitate unlawful intrusions on others’ computers and electronic devices.  Before becoming a member of Darkode, prospective members were allegedly vetted through a process in which an existing member invited a prospective member to the forum for the purpose of presenting the skills or products that he or she could bring to the group.  Darkode members allegedly used each other’s skills and products to infect computers and electronic devices of victims around the world with malware and, thereby gain access to, and control over, those devices.  

The takedown of the forum and the charges announced today are the result of the FBI’s infiltration, as part of Operation Shrouded Horizon, of the Darkode’s membership.  The investigation of the Darkode forum is ongoing, and the U.S. Attorney’s Office of the Western District of Pennsylvania is taking a leadership role in conjunction with the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS).

The charges announced today are part of a coordinated effort by a coalition of law enforcement authorities from 20 nations to charge, arrest or search 70 Darkode members and associates around the world.  The nations comprising the coalition include Australia, Bosnia and Herzegovina, Brazil, Canada, Colombia, Costa Rica, Cyprus, Croatia, Denmark, Finland, Germany, Israel, Latvia, Macedonia, Nigeria, Romania, Serbia, Sweden, the United Kingdom and the United States.  Today’s actions represent the largest coordinated international law enforcement effort ever directed at an online cyber-criminal forum.

The following defendants face charges in the Western District of Pennsylvania:

Johan Anders Gudmunds, aka Mafi aka Crim aka Synthet!c, 27, of Sollebrunn, Sweden, is charged by indictment with conspiracy to commit computer fraud, conspiracy to commit wire fraud, and conspiracy to commit money laundering.  He is accused of serving as the administrator of Darkode, and creating and selling malware that allowed hackers to create botnets.Gudmunds also allegedly operated his own botnet, which at times consisted of more than 50,000 computers, and used his botnet to steal data from the users of those computers on approximately 200,000,000 occasions.

Morgan C. Culbertson, aka Android, 20, of Pittsburgh, is charged by criminal information with conspiring to send malicious code.  He is accused of designing Dendroid, a coded malware intended to remotely access, control, and steal data from Google Android cellphones.  The malware was allegedly offered for sale on Darkode.

Eric L. Crocker, aka Phastman, 39, of Binghamton, New York, is charged by criminal information with sending spam.He is accused of being involved in a scheme involving the use of a Facebook Spreader which infected Facebook users’ computers, turning them into bots which Crocker controlled through the use of command and control servers.  Crocker sold the use of this botnet to others for the purpose of sending out massive amounts of spam.

Naveed Ahmed, aka Nav aka semaph0re, 27, of Tampa, Florida; Phillip R. Fleitz, aka Strife, 31, of Indianapolis; and Dewayne Watts, aka m3t4lh34d aka metal, 28, of Hernando, Florida, are each charged by criminal information with conspiring to send spam.  They are accused of participating in a sophisticated scheme to maintain a spam botnet that utilized bulletproof servers in China to exploit vulnerable routers in third world countries, and that sent millions of electronic mail messages designed to defeat the spam filters of cellular phone providers.

Murtaza Saifuddin, aka rzor, 29, of Karachi, Sindh, Pakistan, is charged in an indictment with identity theft.Saifuddin is accused of attempting to transfer credit card numbers to others on Darkode.

The following defendant faces charges in the Eastern District of Wisconsin:

Daniel Placek, aka Nocen aka Loki aka Juggernaut aka M1rr0r, 27, of Glendale, Wisconsin, is charged by criminal information with conspiracy to commit computer fraud.He is accused of creating the Darkode forum, and selling malware on Darkode designed to surreptitiously intercept and collect email addresses and passwords from network communications.
The following defendants face charges in the District of Columbia:

Matjaz Skorjanc, aka iserdo aka serdo, 28, of Maribor, Slovenia; Florencio Carro Ruiz, aka NeTK aka Netkairo, 36, of Vizcaya, Spain; and Mentor Leniqi, aka Iceman, 34, of Gurisnica, Slovenia, are each charged in a criminal complaint with racketeering conspiracy; conspiracy to commit wire fraud and bank fraud; conspiracy to commit computer fraud, access device fraud and extortion; and substantive computer fraud.Skorjanc also is accused of conspiring to organize the Darkode forum and of selling malware known as the ButterFly bot.

The following defendant faces charges in the Western District of Louisiana:

Rory Stephen Guidry, aka k@exploit.im, of Opelousas, Louisiana, is charged with computer fraud. He is accused of selling botnets on Darkode.

The charges and allegations are merely accusations.  A defendant is presumed innocent until and unless proven guilty.

This investigation, Operation Shrouded Horizon, is being conducted by the FBI with assistance from Europol and their European Cyber Crime Center (EC3).  This case is being prosecuted by Assistant U.S. Attorneys James T. Kitchen and Charles A. Eberle of the Western District of Pennsylvania and Trial Attorneys Gavin A. Corn, Marie-Flore Johnson and Harold Chun of CCIPS, Assistant U.S. Attorney Erica O’Neil of the Eastern District of Wisconsin and Assistant U.S. Attorney Myers Namie of the Western District of Louisiana.  The Criminal Division’s Office of International Affairs also provided significant assistance.

*****

In a related case, Aleksandr Andreevich Panin, aka Gribodemon, 26, of Tver, Russia; and Hamza Bendelladj, aka Bx1, 27, of Tizi Ouzou, Algeria, pleaded guilty on Jan. 28, 2014, and June 26, 2015, respectively, in the Northern District of Georgia in connection with developing, distributing and controlling SpyEye, a malicious banking trojan designed to steal unsuspecting victims’ financial and personally identifiable information.  Bendelladj and Panin advertised SpyEye to other members on Darkode.  One of the servers used by Bendelladj to control SpyEye contained evidence of malware that was designed to steal information from approximately 253 unique financial institutions around the world.  Panin and Bendelladj will be sentenced at a later date.

This case is being prosecuted by Assistant U.S. Attorneys Steven Grimberg and Kamal Ghali of the Northern District of Georgia.

Monday, September 2, 2013

SELLING A WAY IN: ENTERING COMPUTER NETWORKS THROUGH THE BACKDOOR

FROM:  U.S. JUSTICE DEPARTMENT
Tuesday, August 27, 2013
Pennsylvania Man Pleads Guilty in Massachusetts to Hacking into Multiple Computer Networks

A Pennsylvania man pleaded guilty today to charges stemming from his participation in a scheme to hack into computer networks and sell access to those networks.

The guilty plea was announced by Acting Assistant Attorney General Mythili Raman of the Justice Department’s Criminal Division and U.S. Attorney Carmen M. Ortiz of the District of Massachusetts.

Andrew James Miller, 23, of Devon, Penn., pleaded guilty before U.S. District Judge Mark Wolf in the District of Massachusetts to one count of conspiracy and two counts of computer intrusion.

According to court documents, from 2008 to 2011, Miller remotely hacked into a variety of computers located in Massachusetts and elsewhere, and, in some instances, surreptitiously installed “backdoors” into those computers.  These “backdoors” were designed to provide future administrator-level, or “root,” access to the compromised computers.  According to court documents, Miller obtained log-in credentials to the compromised computers.  He and his co-conspirators then sold access to these backdoors, as well as other log-in credentials.  The access sold by Miller and his co-conspirators allowed unauthorized people to access various commercial, education and government computer networks.

Judge Wolf scheduled sentencing for Nov. 19, 2013.  The maximum penalty for the conspiracy count is five years in prison.  One of the computer intrusion counts carries a maximum penalty of five years in prison and the other, involving intentional damage to a protected computer, carries a maximum penalty of 10 years in prison.

The case was investigated by the FBI.  It is being prosecuted by Trial Attorney Mona Sedky of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Adam Bookbinder of the U.S. Attorney’s Office for the District of Massachusetts.

Monday, November 28, 2011

HUNGARIAN SEEKER PLEADS GUILTY TO HACKER CRIMES

The following excerpt is from the Department of Justice website:

Wednesday, November 23, 2011
“Hungarian Citizen Pleads Guilty to Hacking into Marriott Computers and Extorting Employment from the Company
WASHINGTON – A Hungarian citizen pleaded guilty today to intentionally causing damage by transmitting a malicious code to Marriott International Corporation computers and to threatening to reveal confidential information obtained from the company’s computers if Marriott did not offer him a job.
The guilty plea was announced by Assistant Attorney General Lanny A. Breuer of the Justice Department’s Criminal Division, U.S. Attorney for the District of Maryland Rod J. Rosenstein and Special Agent in Charge David Beach of the U.S. Secret Service, Washington Field Office.
Attila Nemeth, 26, pleaded guilty in the District of Maryland before U.S. District Judge J. Frederick Motz.
According to Nemeth’s plea agreement, on Nov. 11, 2010, Nemeth sent an initial email to Marriott personnel, advising that he had been accessing Marriott’s computers for months and had obtained proprietary information. Nemeth threatened to reveal this information if Marriott did not give him a job maintaining the company’s computers. On Nov. 13, 2010, after receiving no response from Marriott, Nemeth sent another email containing eight attachments, seven of which were confirmed as documents stored on Marriott’s computer system. These documents included financial documentation and other confidential and proprietary information. Nemeth admitted that through an infected email attachment sent to specific Marriott employees he was able to install malicious software on Marriott’s system that gave him a “backdoor” into the system. Using the “backdoor,” Nemeth was able to access proprietary email and other files belonging to Marriott.
According to the plea agreement, on Nov. 18, 2010, Marriott created the identity of a fictitious Marriott employee for the use by the U.S. Secret Service in an undercover operation to communicate with Nemeth. Nemeth, believing he was communicating with Marriott human resources personnel, continued to call and email the undercover agent, and demanded a job with Marriott in order to prevent the public release of the Marriott documents. Nemeth emailed a copy of his Hungarian passport as identification and offered to travel to the United States.
On Jan. 17, 2011, Nemeth arrived at Washington Dulles Airport on a ticket purchased by Marriott, for an “employment interview.” The “interview” was conducted by a Secret Service agent assuming the role of the Marriott employee with whom Nemeth believed he had been communicating. During the course of the “interview,” Nemeth admitted that he accessed Marriott’s computer systems; stole Marriott’s confidential and proprietary information; and initiated the emails to Marriott threatening to publicly release Marriott’s data unless he was given a job on his terms by Marriott. To further prove his identity as the perpetrator, Nemeth demonstrated exactly how he accessed the Marriott network; his continued ability to access the Marriott network; and the location of the stolen Marriott proprietary data on a computer server located in Hungary.
As a result of the compromise of its computer network, Marriott was compelled to engage more than 100 of its employees in a thorough search of its network to determine the scope of the compromise and to identify the data that may have been compromised. The loss to Marriott as a result of the intentional damage caused by Nemeth is between $400,000 and $1 million dollars in salaries, consultant expenses and other costs associated with Nemeth’s intrusion.
Nemeth faces a maximum penalty of 10 years in prison for the transmission of the malicious code and a maximum of five years in prison for threatening to expose confidential and proprietary information if Marriott did not give him a job. Sentencing is scheduled for Feb. 3, 2012, at 11 a.m. Nemeth remains detained.
The case is being investigated by the U.S. Secret Service and prosecuted by Special Assistant U.S. Attorney Anthony V. Teelucksingh assigned from the Computer Crime and Intellectual Property Section of the Justice Department’s Criminal Division.”
a href="http://gan.doubleclick.net/gan_click?lid=41000613802101859&pubid=21000000000397724">Furniture Event - Save up to 50% at officemax.com