Accused Twitter hacker arrested in Florida

U.S. authorities have arrested a 17-year-old male in connection with the breach this month in which attackers seized control of high profile Twitter accounts as part of an apparent bitcoin scam. The State Attorney in Hillsborough, County, Florida announced Friday that Graham Ivan Clark “was the mastermind” of the July 15 Twitter breach. In that incident, hackers leveraged accounts belonging to former president Barack Obama, Democratic presidential candidate Joe Biden, Tesla founder Elon Musk and others in an attempt to convince millions of followers to send bitcoin to a particular. Twitter previously said attackers had targeted 130 accounts, tweeting from 45 of those, accessing the direct messages of 36 and downloading Twitter data from seven users. Clark was charged with 30 felonies, including 17 counts of communications fraud, ten counts of fraudulent use of personal information and one count of organized fraud. “This defendant lives here in Tampa, he committed the […]

The post Accused Twitter hacker arrested in Florida appeared first on CyberScoop.

Continue reading Accused Twitter hacker arrested in Florida

Hackers breached Twitter accounts by targeting employees by phone

Twitter says the people who took over the accounts of high-profile users in order to launch a bitcoin scam used tactics focused on phones to trick company employees into giving them access. The attackers targeted a “small number of employees through a phone spear phishing attack,” Twitter said in a statement Thursday. Not all the affected employees had access to account management tools, the company said, but hackers used their credentials to gather information about Twitter’s internal processes. They then used that reconnaissance data to inform attacks on Twitter personnel with deeper access. “This attack relied on a significant and concerted attempt to mislead certain employees and exploit human vulnerabilities to gain access to our internal systems,” the company said in a blog post. The update clarifies some of the events around a July 15 breach in which attackers took over accounts belonging to former president Barack Obama, Amazon chief […]

The post Hackers breached Twitter accounts by targeting employees by phone appeared first on CyberScoop.

Continue reading Hackers breached Twitter accounts by targeting employees by phone

EU sanctions Russian intelligence, Chinese nationals and a North Korean front company for alleged hacks

The European Union has sanctioned six people and three organizations in Russia, China and North Korea in connection with three major cyberattacks dating back to 2017. EU officials announced Thursday they would enact restrictive measures against the people it deemed responsible for the WannaCry ransomware outbreak in 2017, the NotPetya campaign and Operation Cloud Hopper, a Chinese cyber-espionage effort. Penalties include a travel ban, asset freeze and prohibit people and organizations in the EU from “making funds available” to the sanctioned individuals and entities. The move follows previous U.S. allegations against many of the same parties. “Sanctions are one of the options available in the EU’s cyber diplomacy toolbox to prevent, deter and respond to malicious cyber activities directed against the EU or its member states, and today is the first time the EU has used this tool,” officials said in a statement. The sanctions name unit 74455 of Russia’s […]

The post EU sanctions Russian intelligence, Chinese nationals and a North Korean front company for alleged hacks appeared first on CyberScoop.

Continue reading EU sanctions Russian intelligence, Chinese nationals and a North Korean front company for alleged hacks

Anti-NATO disinformation effort uses coronavirus to poke political tensions

A propaganda campaign is using the coronavirus pandemic to inflame anxieties about NATO troops throughout Eastern Europe, security researchers have determined. The group, dubbed Ghostwriter, has been focused on amplifying anti-Western narratives in Poland, Latvia and Lithuania since 2017. Operatives have planted fabricated diplomatic documents, tried spreading the false narrative that Canadian soldiers had been spreading COVID-19 through Latvia and leveraged news sites to spread articles that appear to be legitimate, according to a report the security firm FireEye published Tuesday. While researchers have not attributed the effort to the Russian government, the findings are the latest addition to a growing consensus that pro-Kremlin entities are seizing on COVID-19 to inflame existing political divisions. Russia’s military intelligence agency, the GRU, is using three websites to try to spread disinformation about the U.S. response to the virus, U.S. officials told the Associated Press. “We believe the assets and operations…are for the […]

The post Anti-NATO disinformation effort uses coronavirus to poke political tensions appeared first on CyberScoop.

Continue reading Anti-NATO disinformation effort uses coronavirus to poke political tensions

Islamic State propaganda efforts struggle after Telegram takedowns, report says

The Islamic State terrorist group is reportedly struggling to regain a foothold on mainstream social networks amid tighter controls from technology firms and ongoing attention from the U.S. military. As major networks have stifled the group, it has tried to build a presence on a number of marginal social media platforms, only to be met “by increasing efforts by these companies to bring down content,” the European Union’s law enforcement agency, Europol, said Tuesday in a report examining the extremist group’s activities over 2019. Telegram, previously the primary source of terrorist propaganda online, according to Europol, said in November that it had removed more than 5,000 “terrorist accounts and bots” during a two day effort against the group, an uptick from the typical average of 200 to 300 removals. Since then, IS supporters have shifted to more fringe services, like the Russia-based TamTam and Hoop Messenger, which is hosted in Canada. Extremists also have […]

The post Islamic State propaganda efforts struggle after Telegram takedowns, report says appeared first on CyberScoop.

Continue reading Islamic State propaganda efforts struggle after Telegram takedowns, report says

Garmin confirms ransomware attack, keeps quiet on possible Evil Corp. involvement

Finally, Garmin customers who have put off their exercise routine because of outages on the website and mobile app can lace up their running shoes again. Garmin said in a statement Monday that it has started restoring services following a ransomware attack that locked “some” systems on July 23. While the company says it has no indication that scammers accessed customer data, the attack did interrupt website functionality, customer support services, user apps and corporate communications, according to the statement. “Affected systems are being restored and we expect to return to normal operation over the next few days,” Garmin said. “We do not expect any material impact to our operations or financial results because of this outage.” The official update confirms prior reporting that hackers had infiltrated Garmin’s systems and demanded an extortion fee to allow the company to resume activity as normal. Garmin previously said its mobile app was […]

The post Garmin confirms ransomware attack, keeps quiet on possible Evil Corp. involvement appeared first on CyberScoop.

Continue reading Garmin confirms ransomware attack, keeps quiet on possible Evil Corp. involvement

TikTok dumps QAnon channels, following Twitter’s crackdown

The only thing social media companies can seemingly agree upon when it comes to moderating content on their platforms is that QAnon crosses the line. TikTok has removed a number of hashtags associated with the far-right conspiracy theory group is poised to limit the spread of the group that the FBI has described as a domestic terrorism threat. The company has made it more difficult for users to search for popular hashtags, reportedly including “QAnon” and “QAnonTruth,” among others, following a similar announcement from Twitter that it would remove 7,000 accounts and limit 150,000 more. QAnon has pushed the unfounded conspiracy theory that President Donald Trump is fighting a “deep state” of government officials, celebrities and business leaders who secretly work as child sex traffickers and control global order. Its supporters frequently harass Trump critics, while believers have been linked to real-world acts of violence throughout the country. One supporter […]

The post TikTok dumps QAnon channels, following Twitter’s crackdown appeared first on CyberScoop.

Continue reading TikTok dumps QAnon channels, following Twitter’s crackdown

Insurer’s huge data exposure draws charges from New York state

New York regulators have charged an insurer with violating state cybersecurity law for allegedly exposing hundreds of millions of documents that included Americans’ personal data, including Social Security numbers and financial information. The New York State Department of Financial Services announced legal action Wednesday against the First American Title Insurance Company, the second-largest real estate title insurer in the U.S. The company is accused of exposing customers’ Social Security numbers, bank account information, driver’s license numbers and mortgage and tax records through a software vulnerability that went undetected between May 2014 and December 2018. Upon discovering the flaw during a routine security test, the insurance company failed to fix it, DFS alleged. “After the data exposure was discovered by an internal penetration test in December 2018, First American failed to conduct a reasonable investigation into the scope and cause of the exposure, reviewing only 10 of the millions of documents exposed and […]

The post Insurer’s huge data exposure draws charges from New York state appeared first on CyberScoop.

Continue reading Insurer’s huge data exposure draws charges from New York state

Hackers accessed Twitter DMs from 36 accounts in bitcoin scam attack

Hackers who breached Twitter’s systems last week likely accessed private messages belonging to 36 of the 130 accounts targeted, including messages for a Dutch politician, the company said Wednesday. In an updated blog post, Twitter said attackers accessed the direct message inbox of 36 accounts, meaning the intruders were able to view conversations belonging to affected users. The company did not disclose the accounts that hackers had accessed, other than one elected leader in the Netherlands. Twitter has “no indication that any other former or current elected official had their DMs accessed,” the statement said. The statement suggests that hackers had access to private conversations from some of the most famous people on the site. For a span of hours on July 15, attackers hijacked accounts belonging to Democratic presidential nominee Joe Biden, former president Barack Obama, Amazon founder Jeff Bezos and Tesla chief executive Elon Musk. The high profile […]

The post Hackers accessed Twitter DMs from 36 accounts in bitcoin scam attack appeared first on CyberScoop.

Continue reading Hackers accessed Twitter DMs from 36 accounts in bitcoin scam attack

$2 million in rewards posted for accused SEC hackers

It’s just like the old saying goes: If you can’t beat ’em, tweet about it. The U.S. government embarked on a public awareness campaign Wednesday seeking help in the apprehension of two Ukrainian men accused of hacking the U.S. Securities and Exchange Commission. The State Department offered rewards of up to $1 million apiece for information leading to the arrest or conviction of Artem Radchenko and Oleksandr Ieremenko. The bounty that comes more than a year after the pair were indicted in a scheme to breach an SEC database, steal nonpublic information and then sell it for a profit. The Secret Service, meanwhile, sent a series of tweets highlighting existing charges against the pair, and asked other Twitter users to provide more information. The effort to breach an SEC database resulted in more than $4.5 million in profit, the Secret Service tweeted. “As their criminal reach is worldwide, we welcome the cooperation and […]

The post $2 million in rewards posted for accused SEC hackers appeared first on CyberScoop.

Continue reading $2 million in rewards posted for accused SEC hackers