Showing posts with label Hackers. Show all posts
Showing posts with label Hackers. Show all posts

June 14, 2016

Russian Hackers Steal Democratic National Committee's Opposition Research On Trump




[From article]
Russian government hackers penetrated the computer network of the Democratic National Committee and gained access to the entire database of opposition research on GOP presidential candidate Donald Trump, according to committee officials and security experts who responded to the breach.
The intruders so thoroughly compromised the DNC’s system that they also were able to read all email and chat traffic, said DNC officials and the security experts.
The intrusion into the DNC was one of several targeting American political organizations. The networks of presidential candidates Hillary Clinton and Donald Trump were also targeted by Russian spies, as were the computers of some Republican political action committees, U.S. officials said. But details on those cases were not available.
A Russian Embassy spokesman said he had no knowledge of such intrusions.
[. . .]



The intrusions are an example of Russia’s interest in the U.S. political system and its desire to understand the policies, strengths and weaknesses of a potential future president — much as American spies gather similar information on foreign candidates and leaders.
The depth of the penetration reflects the skill and determination of the United States’ top cyber adversary as Russia goes after strategic targets, from the White House and State Department to political campaign organizations.
[. . .]
“It’s the job of every foreign intelligence service to collect intelligence against their adversaries,” said Shawn Henry, president of CrowdStrike, the cyber firm called in to handle the DNC breach and a former head of the FBI’s cyber division. He noted that it is extremely difficult for a civilian organization to protect itself from a skilled and determined state such as Russia.
“We’re perceived as an adversary of Russia,” he said. “Their job when they wake up every day is to gather intelligence against the policies, practices and strategies of the U.S. government. There are a variety of ways. [Hacking] is one of the more valuable because it gives you a treasure trove of information.”
[. . .]



Trump has not been a politician for very long, so foreign agencies are playing catch-up, analysts say.
“The purpose of such intelligence gathering is to understand the target’s proclivities,” said Robert Deitz, former senior councillor to the CIA director and a former general counsel at the National Security Agency. “Trump’s foreign investments, for example, would be relevant to understanding how he would deal with countries where he has those investments” should he be elected, Deitz said. “They may provide tips for understanding his style of negotiating. In short, this sort of intelligence could be used by Russia, for example, to indicate where it can get away with foreign adventurism.”
[. . .]
Within 24 hours, CrowdStrike had installed software on the DNC’s computers so that it could analyze data that could indicate who had gained access, when and how.
The firm identified two separate hacker groups, both working for the Russian government, that had infiltrated the network, said Dmitri Alperovitch, CrowdStrike co-founder and chief technology officer. The firm had analyzed other breaches by both groups over the past two years.
One group, which CrowdStrike had dubbed Cozy Bear, had gained access last summer and was monitoring the DNC’s email and chat communications, Alperovitch said.
The other, which the firm had named Fancy Bear, broke into the network in late April and targeted the opposition research files. It was this breach that set off the alarm. The hackers stole two files, Henry said. And they had access to the computers of the entire research staff — an average of about several dozen on any given day.
The computers contained research going back years on Trump. “It’s a huge job” to dig into the dealings of somebody who has never run for office before, Dacey said.
CrowdStrike is not sure how the hackers got in. The firm suspects they may have targeted DNC employees with “spearphishing” emails. These are communications that appear legitimate — often made to look like they came from a colleague or someone trusted — but that contain links or attachments that when clicked on deploy malicious software that enables a hacker to gain access to a computer. “But we don’t have hard evidence,” Alperovitch said.
The two groups did not appear to be working together, Alperovitch said. Fancy Bear is believed to work for the GRU, or Russia’s military intelligence service, he said. CrowdStrike is less sure of whom Cozy Bear works for but thinks it might be the Federal Security Service or FSB, the country’s powerful security agency, which was once headed by Putin.
[. . .]



The two groups have hacked government agencies, tech companies, defense contractors, energy and manufacturing firms, and universities in the United States, Canada and Europe as well as in Asia, he said.
Cozy Bear, for instance, compromised the unclassified email systems of the White House, State Department and Joint Chiefs of Staff in 2014, Alperovitch said.
“This is a sophisticated foreign intelligence service with a lot of time, a lot of resources, and is interested in targeting the U.S. political system,” Henry said. He said the DNC was not engaged in a fair fight. “You’ve got ordinary citizens who are doing hand-to-hand combat with trained military officers,” he said. “And that’s an untenable situation.”
The firm has installed special software on every computer and server in the network to detect any efforts by the Russian cyberspies to break in again. “When they get kicked out of the system,” Henry predicted, “they’re going to try to come back in.”

https://www.washingtonpost.com/world/national-security/russian-government-hackers-penetrated-dnc-stole-opposition-research-on-trump/2016/06/14/cf006cb4-316e-11e6-8ff7-7b6c1998b7a0_story.html

Russian government hackers penetrated DNC, stole opposition research on Trump
By Ellen Nakashima
June 14, 2016 at 11:30 AM

June 7, 2016

NFL Twitter Account Hacked, Hoax Report of Goodell's Death




In this example a prominent, wealthy corporation had its social media account compromised. They learned about it quickly. What about ordinary individuals who often do not know when their accounts are hacked? What are citizens to do to protect themselves? Police remain untrained and uninterested in how to address high tech crime. This is about computers which most people not in a coma know exist. But there are many other technologies being used by criminals to harm individual citizens by government and private criminals. For a good description of the problem see Marc Goodman's new book, Future Crimes

[From article]
The NFL’s Twitter account was reportedly hacked Tuesday and a tweet went out saying commissioner Roger Goodell had died.
[. . .]
The hacker’s tweet, which was retweeted over 2,000 times, was quickly removed, but the hacker apparently still had access to the account and sent out another tweet in response.

http://newyork.cbslocal.com/2016/06/07/nfl-twitter-hacked/

NFL Twitter Account Hacked; Hoax Tweet Said Roger Goodell Had Died
June 7, 2016 1:46 PM
CBS News New York NY

April 24, 2016

Hackers Attack Bank In Bangladesh, Almost Got $1 billion




[From article]
Hackers involved in one of the biggest bank robberies in history thought they had won the jackpot - until they were caught out by a simple spelling mistake.
Some 20 people are believed to be behind the £60 million heist ($81m), which targeted the central bank of Bangladesh - which has no firewall.
The hackers also attempted to steal a further £600 million ($850m) but were caught out when they spelt 'foundation' as 'fandation'.
If the hackers had used a dictionary, they would have made off with nearly $1 billion.
Leading investigators in the case said the lack of security made the bank an easy target - and also makes it difficult to find out how the hackers operated, and where from.
Cyber criminals broke into Bangladesh Bank's system in early February and tried to make fraudulent transfers totalling $951 million from its account at the Federal Reserve Bank of New York.
Most of the payments were blocked, but $81 million was routed to accounts in the Philippines and diverted to casinos there.
Most of those funds remain missing, and the masterminds behind the heist have yet to be identified.
Bangladesh police said they had identified 20 foreigners involved in the heist but said they appear to be people who received some of the payments, rather than those who initially stole the money.
[. . .]
'You are talking about an organisation that has access to billions of dollars and they are not taking even the most basic security precautions,' said Jeff Wichman, a consultant with cyber firm Optiv.
[. . .]



Tom Kellermann, a former member of the World Bank security team, said the security shortcomings described by Alam were 'egregious,' and that he believed there were 'a handful' of central banks in developing countries that were equally insecure.
[. . .]
When the hackers attempted to steal a further $850 million by bombarding the New York bank with dozens of transfer requests, the bank's security systems and typing errors in some requests prevented the full theft.
The central bank governor, his two deputies and the country's top banking bureaucrat have lost their jobs over the incident and the government has been desperately attempting to contain the damage from the scandal.

http://www.dailymail.co.uk/news/article-3555298/Hackers-steal-81-million-Bangladeshi-bank-no-firewall-caught-illiterate-fraudsters-spelt-foundation-fandation.html

Hackers steal $81 million from a Bangladeshi bank with no firewall... and were only caught out when the illiterate fraudsters spelt 'foundation' as 'fandation'
Hackers thought they had made off with $81m jackpot in electronic heist
Targeted the central bank of Bangladesh but were caught out by spelling
The sum was one of the largest amounts stolen from a bank in history
Some 20 people behind the heist and attempted to steal a further $850m
By AMIE GORDON FOR MAILONLINE
PUBLISHED: 10:37 EST, 23 April 2016 | UPDATED: 04:45 EST, 24 April 2016

March 7, 2016

Wi-Fi Based Computer Health Devices, Cars, Can Be Hacked To Cause Death




[From article]
Researcher Marie Moe woke up after emergency surgery in 2011 with a new pacemaker to correct a heart condition. What she didn't realize at the time was that the lifesaving device in her chest exposed her to a completely different kind of threat.
The pacemaker keeping her alive has wireless connectivity capabilities — a detail her doctors didn't tell her — meaning it could be hacked.
Moe was understandably disturbed that it never occurred to her doctors to tell her that her device had wireless capability, and they had not considered the security implications.
"They really had not thought about the pacemaker security at all," she said.
Vulnerabilities like Moe's are moving quickly from the rare to the extremely common.
[. . .]
Frustrated with her doctors and the manufacturer of her pacemaker, Moe has turned her life's work into finding out more on behalf of all patients.
She has testified in front of the FDA and worked with grassroots organization I Am The Cavalry to develop a Hippocratic Oath for Connected Devices. Her goal is to force transparency into an industry where doctors are uninformed, code is proprietary and third-party access limited.
[. . .]
"It's about time hospitals started worrying about computer viruses, not just ordinary germs," said Moe.
"That's what we have to look at today, to invest in the area to make sure we are solving those problems today, not four years from now when the problem is too heavy to be solved," said Google vice president, security and privacy Gerhard Eschelbeck at the RSA Conference on Tuesday.
[. . .]
Of course, it's not just medical devices that pose a threat. Well-publicized car hacks by researchers have shown just how easy it is for hackers to take remote control of certain car models.
[. . .]
The average GM car has 30 computers, all built by different partners and suppliers. (For example, a car stereo system may be integrated with Apple CarPlay or Android Auto.)
[. . .]
Of course, when weighing the adoption of connected devices, it's important to take into account the risks and potential rewards, said John Stewart, senior vice president, chief security and trust officer at Cisco.
"For the most part, all of this is going to be beneficial more than it's going to be endangering and risky," said Stewart. "This security conference has a tendency to think the whole world's going to melt down by tomorrow. [But] We're still here 20 years after we thought it was going to meltdown 20 years ago."

http://www.cnbc.com/2016/03/04/how-the-internet-of-things-could-be-fatal.html

How the 'Internet of Things' could be fatal
Harriet Taylor | @Harri8t
March 4, 2016

February 24, 2016

Harvard University Students Targets Of Hackers




To learn more about what hackers are doing, from foreign criminals to domestic crime families, terrorists and big data, enabled by your ever friendly Apple Computer and iPhone, Facebook, Snapchat, Google and others, take a look at Marc Goodman's book, Future Crime. Amazing how easily anyone can lose it all.

http://www.thecrimson.com/article/2016/2/24/students-admins-phishing-email/

Students, Staff, and Faculty Targeted by Phishing Scam
By HANNAH NATANSON,
Harvard CRIMSON STAFF WRITER
February 24, 2016

February 1, 2016

Harvard University Berkman Center Criticizes FBI Concerns About Surveillance Capabilities




See also Marc Goodman's book, Future Crimes, in which he describes the exponential development of new technologies that are overwhelming laws, and government. Criminals adapt in ways that bureaucracies cannot. Politicians and journalists appear to be clueless about technology. Few politicians read. They remain focused on identity theft and cannot even protect citizens and corporations from that.  

[From article]
For more than two years the F.B.I. and intelligence agencies have warned that encrypted communications are creating a “going dark” crisis that will keep them from tracking terrorists and kidnappers. Now, a study in which current and former intelligence officials participated concludes that the warning is wildly overblown, and that a raft of new technologies — like television sets with microphones and web-connected cars — are creating ample opportunities for the government to track suspects, many of them worrying. “ ‘Going dark’ does not aptly describe the long-term landscape for government surveillance,” concludes the study, to be published Monday by the Berkman Center for Internet and Society at Harvard. The study argues that the phrase ignores the flood of new technologies “being packed with sensors and wireless connectivity” that are expected to become the subject of court orders and subpoenas, and are already the target of the National Security Agency as it places “implants” into networks around the world to monitor communications abroad. The products, ranging from “toasters to bedsheets, light bulbs, cameras, toothbrushes, door locks, cars, watches and other wearables,” will give the government increasing opportunities to track suspects and in many cases reconstruct communications and meetings. The study, titled, “Don’t Panic: Making Progress on the ‘Going Dark’ Debate,” is among the sharpest counterpoints yet to the contentions of James B. Comey, the F.B.I. director, and other Justice Department officials, mostly by arguing that they have defined the issue too narrowly.
[. . .]



The Harvard study, funded by the Hewlett Foundation, was unusual because it involved technical experts, civil libertarians and officials who are, or have been, on the forefront of counterterrorism. Larry Kramer, the former dean of Stanford Law School, who heads the foundation, noted Friday that until now “the policy debate has been impeded by gaps in trust — chasms, really — between academia, civil society, the private sector and the intelligence community” that have impeded the evolution of a “safe, open and resilient Internet.” 
[. . .]



Jonathan Zittrain, a professor of law and computer science at Harvard [. . .] noted that in the current stalemate there was little discussion of the “ever-expanding ‘Internet of things,’ where telemetry from teakettles, televisions and light bulbs might prove surprisingly, and worryingly, amenable to subpoena from governments around the world.” Those technologies are already being exploited: The government frequently seeks location data from devices like cellphones and EZ Passes to track suspects. The study notes that such opportunities are expanding rapidly. A Samsung “smart” television contains a microphone [. . .] and a Hello, Barbie brought out by Mattel last year records children’s conversations with the doll, processes them over the Internet and sends back a response. The history of technology shows that what is invented for convenience can soon become a target of surveillance. “Law enforcement or intelligence agencies may start to seek orders compelling Samsung, Google, Mattel, Nest or vendors of other networked devices to push an update or flip a digital switch to intercept the ambient communications of a target,” the report said. 
[. . .]



Apple users routinely back up the contents of their phones to iCloud — a service that is not encrypted and now is almost a routine target for investigators or intelligence agencies. So are the tracking and mapping systems for cars that rely on transmitted global positioning data. “I think what this report shows is that the world today is like living in a big field that is more illuminated than ever before,” said Joseph Nye, a Harvard government professor and former head of the National Intelligence Council. “There will be dark spots — there always will be. But it’s easy to forget that there is far more data available to governments now than ever before.”

http://www.nytimes.com/2016/02/01/us/politics/new-technologies-give-government-ample-means-to-track-suspects-study-finds.html?_r=0

New Technologies Give Government Ample Means to Track Suspects, Study Finds
By DAVID E. SANGER
JAN. 31, 2016

September 14, 2015

EZ Passes Vulnerable To Hacking, Tracking




[From article]
Universal electronic tolling on the Pike is due by the end of next year. It is seen as a way to eliminate the state’s costly, patronage-laden brigade of toll takers and let Pike drivers whiz through tolls without stopping. But it could force tens of thousands of drivers who now use pocket change to switch to E-ZPasses. But experts say the electronic transponders are susceptible to hacking and already have triggered Big Brother concerns in New York.
“They’re not using encryption, so unbeknownst to most E-ZPass users, the tag can be read from almost anywhere,” cybersecurity expert Gary Miliefsky said, adding that crooks could travel free of charge on your dime. “Hackers could easily read your number from your car and make their own pass using your account number.”
While most drivers stick them to their windshields and forget about them, Miliefsky advises drivers to store their E-ZPasses in the glove compartment or a secure spot to prevent hackers from accessing information.
Meanwhile, in New York, city and state officials have been tracking E-ZPass users all over the city — even in locations that were nowhere near a toll — according to a recent report by the New York Civil Liberties Union.
Michael Versekes, spokesman for the state Department of Transportation, said the state has worked to protect Bay State drivers’ cybersecurity. He noted that state law prohibits drivers’ information from being used for anything beyond the collection of tolls.
[Lots of laws on the books, and lots of them are ignored and violated by government officials. See, e.g., IRS.]
[. . .]
“The real issue is what is the government doing with that information, and are they collecting more surreptitious information that they haven’t told us about,” said Kade Crockford, director of the Technology for Liberty project at the ACLU of Massachusetts.
Crockford said state officials need to be transparent about who the information will be shared with, such as law enforcement or even insurance agencies. “We need to make sure that when people travel down the Turnpike they have a sense of who is getting their information, where their information is being collected, for what purpose and for how long their information stays on file,” she said.

http://www.bostonherald.com/news_opinion/local_coverage/2015/09/cyber_experts_warn_of_driver_risk_for_e_zpass_hack_track

Cyber experts warn of driver risk for E-ZPass hack, track
Monday, September 14, 2015
By: Hillary Chabot
Boston Herald

August 14, 2015

Team of Hackers, One Pastor, Break Into Business Wire Services, Obtained $100 million In Scheme


Posted August 12, 2015 7:17 PM ET; Last updated August 14, 2015 3:42 PM ET



[From article]
The Pennsylvania pastor arrested on Tuesday for pocketing profits of $17.5 million using illegal inside information won’t be tending his flock this Sunday — because he’s in jail.
A rare legal smackdown between federal judges resulted late Tuesday night with the freezing of the bail order freeing the pastor, Vitaly Korchevsky, head of the Slavic Evangelical Baptist Church in Brookhaven, Pa.
A Brooklyn federal court judge overturned a Philaelphia magistrate judge’s order that would have freed the pastor on a $100,000 bond.

http://nypost.com/2015/08/13/pastor-saved-souls-by-day-stole-millions-at-night-feds/

Pastor saved souls by day, stole millions at night: feds
By Michelle Celarier
New York Post
August 13, 2015 | 12:25am
* * *

[From article]
An international hacking ring armed with tens of thousands of corporate secrets pocketed more than $100 million from illicit trades, targeting a core vulnerability of the financial system in one of the digital age's most sprawling insider-trading schemes, federal investigators said Tuesday.
Since 2010, more than 30 hackers and traders across the U.S., Ukraine, Russia and other countries coordinated to steal and profit from more than 150,000 press releases, which were scheduled to be delivered to investors from corporate wire services Business Wire, PR Newswire and Marketwired.
[. . .]
Unlike the recent high-profile hacks of health insurers and government agencies, the sophisticated hacks targeted not just people's identities, but corporate intelligence, and some hackers and traders were even aided by former broker-dealers registered with the Securities and Exchange Commission.
By breaking into the wire services, some of Wall Street's most vital and unnoticed information hubs, investigators said the hackers and traders were able to defraud investors on a massive scale while leaving no public trace, a worrying development for the increasingly intricate networks that keep the financial world online.
[. . .]
“The traders were market-savvy, using equities and options … to maximize their profits.”
The years-long subterfuge highlights the hidden danger of modern finance and the broader Web, in which any one compromised link in the larger chain can quietly endanger the system for years. The hackers, experts said, didn't have to breach many individual companies or vacuum up a large amount of files to succeed. Instead, they hit data-rich clearinghouses knowing exactly what they wanted, ensuring an efficient attack.
[. . .]
Federal agents on Tuesday began arresting suspects Tuesday, with nine facing criminal charges for their role in grabbing $30 million in profits.
Authorities said they have also seized a house boat, an apartment complex, a shopping center and a dozen other properties, as well as more than a dozen brokerage accounts holding $6.5 million.
[. . .]
The ability to see a stock's near-future generated windfalls at warp speed; in one instance, traders made half a million dollars in 36 minutes. In a 2013 scheme, the traders bought more than $8 million in shares of Align Technology after stolen documents showed that the medical-device maker's revenues had recently soared. One day later, when the news went public, the traders cashed out for a profit of more than $1.4 million.
[. . .]
The hackers tapped an armament of brute-force, injection and "spear-phishing" attacks, bulldozing through security systems, implanting malicious code or persuading employees to click on booby-trapped links.
[. . .]
The traders were helped by four co-conspirators in Alpharetta and Suwanee, Georgia; Glenn Mills, Pennsylvania; and Brooklyn, two of whom were formerly broker-dealers registered with the SEC.
[. . .]
In 2013, investigators said, the team explored even newer ways of defrauding trades, including tricking sellers by rapidly buying and cancelling trades, which one called a "special daytrading strategy."
[. . .]
another hacker group, called FIN4, had targeted the computer networks of more than 100 health care, law and pharmaceutical firms, hoping to grab insider intelligence on "impending market catalysts" that could help the group rake in cash from lucrative trades.

https://www.washingtonpost.com/news/the-switch/wp/2015/08/11/hackers-who-breached-corporate-wires-made-millions-off-insider-trading/

Hackers who breached corporate wires made millions off insider trading
By Drew Harwell
August 11, 2015 at 12:47 PM

* * *


Vitaly Korchevsky, 50, is escorted in handcuffs from his home in Pennsylvania by agents from the FBI in Pennsylvania on Tuesday morning. He was one of nine people arrested on Tuesday morning.
[video embedded]
[From article]
An international web of hackers and traders made $100million on Wall Street by stealing a look at corporate press releases before they went out and then trading on that information ahead of the pack, federal authorities charged Tuesday.
Authorities said it was the biggest scheme of its kind ever prosecuted, and one that demonstrated yet another way in which the financial world is vulnerable to cybercrime.
The hackers pulled it off by breaking into the computers of some of the biggest business newswire services, which put out earnings announcements and other press releases for a multitude of corporations.
Those releases were by Marketwired of Toronto, PR Newswire in New York and Business Wire of San Francisco.
Nine people in the U.S. and Ukraine were indicted on federal criminal charges, including securities fraud, computer fraud and conspiracy.
[. . .]
Prosecutors said the Ukraine-based hackers were given 'shopping lists' of press releases by the traders.
The hackers then created a 'video tutorial' to help traders see the stolen releases and were paid a portion of the profits from trades based on the information in them, prosecutors said.
Authorities said the scheme involved trades on such companies as Acme Packet Inc, Align Technology Inc, Caterpillar Inc, Dealertrack Technologies Inc, Dendreon Corp, Edwards Lifesciences Corp, Hewlett-Packard Co, Home Depot Inc and Panera Bread Co.
[. . .]
In 2013, for example, the hackers got an early peek at a press release from Panera Bread Company announcing that it was lowering its earnings projections.
The hacking ring bet correctly the stock would fall when the news came out, and turned a profit of about $1million the very next day, according to the indictment.
[. . .]
The most serious charges in the indictment - wire fraud and securities fraud - carry up to 20 years in prison.

http://www.dailymail.co.uk/news/article-3194559/Hackers-100MILLION-Wall-Street-stealing-corporate-press-releases.html

Hackers made $100MILLION on Wall Street by stealing corporate press releases before they were released and then trading on the information
Hackers stole from Marketwired, PR Newswire, and Business Wire
Prosecutors said the Ukraine-based hackers were given 'shopping lists' of press releases by the traders
Hackers then created a 'video tutorial' to help traders see the stolen releases and were paid a portion of the profits from trades
Scheme involved trades on Panera Bread, Hewlett-Packard, Home Depot and Acme Packet, among others
Nine people in the US and Ukraine were indicted on federal criminal charges, including securities and computer fraud and conspiracy
By Associated Press
Daily Mail (UK)
Published: 21:33 EST, 11 August 2015 | Updated: 01:45 EST, 12 August 2015

July 27, 2015

Forty Six Women and Counting Claim Sexual Assaults by Bill Cosby; NY Magazine Site Hacked



Cover of New York Magazine, July 27, 2015

[Video and text embedded of individual women telling their stories]
[From article]
In 2005, a former basketball star named Andrea Constand, who met Cosby when she was working in the athletic department at Temple University, where he served on the board of trustees, alleged to authorities that he had drugged her to a state of semi-consciousness and then groped and digitally penetrated her. After her allegations were made public, a California lawyer named Tamara Green appeared on the Today show and said that, 30 years earlier, Cosby had drugged and assaulted her as well. Eventually, 12 Jane Does signed up to tell their own stories of being assaulted by Cosby in support of Constand’s case. Several of them eventually made their names public. But they were met, mostly, with skepticism, threats, and attacks on their character.
[. . .]
He asked a modeling agent to connect him with young women who were new in town and “financially not doing well.” In the deposition, Cosby seemed confident that his behavior did not constitute rape; he apparently saw little difference between buying someone dinner in pursuit of sex and drugging them to reach the same goal. As for consent, he said, “I think that I’m a pretty decent reader of people and their emotions in these romantic sexual things.” If these women agreed to meet up, his deposition suggested, he felt that he had a right to them. And part of what took the accusations against Cosby so long to surface is that this belief extended to many of the women themselves (as well as the staff and lawyers and friends and others who helped keep the incidents secret).
[. . .]
[In 2012] when a 14-year-oldMissouri cheerleader accused a popular older boy at her school of sexual assault, her classmates shamed her on social media and the family’s house was burned down. The whole world watched online. How could this kind of thing still be happening?
[. . .]
There are now 46 women who have come forward publicly to accuse Cosby of rape or sexual assault; the 35 women here are the accusers who were willing to be photographed and interviewed by New York. The group, at present, ranges in age from early 20s to 80 and includes supermodels Beverly Johnson and Janice Dickinson alongside waitresses and Playboy bunnies and journalists and a host of women who formerly worked in show business. Many of the women say they know of others still out there who’ve chosen to remain silent.

http://www.nymag.com/thecut/2015/07/bill-cosbys-accusers-speak-out.html

‘I’m No Longer Afraid’: 35 Women Tell Their Stories About Being Assaulted by Bill Cosby, and the Culture That Wouldn’t Listen
By Noreen Malone and Amanda Demme
New York Magazine

* * *


Barbara Bowman

[From article]
Their stories remained a secret for decades, because they feared no one would believe them if they spoke out.
Now, nearly 60 years since Bill Cosby's first alleged sexual assault, a group of women who say 'America's favorite dad' attacked them have come forward to reveal their harrowing experiences.
The 35 women, ranging in age from their early 20s to 80, have bravely agreed to be pictured for an issue of New York magazine, set to be published on Monday, while revealing the details of their encounter with the disgraced comedian.
The waitresses, actresses, Playboy bunnies, journalists and writers described how they were allegedly drugged, raped or molested by the star.
[. . .]
The claims span experiences from the 1960s all the way to 2008, when Chloe Gains, 24, said the embattled film star spiked her drink during a party at the Playboy mansion.
[. . .]
He also stated that he obtained prescriptions for quaaludes by claiming it was for a sore back, but actually gave the drug to women
Interviewed in a Philadelphia hotel over four days by a lawyer acting on behalf of a 30-year-old Temple University employee Andrea Constand, Cosby claimed he believed their encounters to be consensual.
[. . .]
Barbara Bowman, 48, told the magazine: 'I went into this thinking he was going to be my father. To wake up half-dressed and raped by the man that said he was going to love me like a father? That's pretty sick.'

http://www.dailymail.co.uk/news/article-3175673/We-t-disappeared-35-Bill-Cosby-s-rape-accusers-come-powerful-magazine-cover-tell-harrowing-experiences-hands-America-s-favorite-dad.html

'We can't be disappeared': 35 of Bill Cosby's rape accusers come together in powerful magazine shoot to recount their experiences at the hands of America's once favorite dad
Women came forward and agreed to be pictured for the publication
Each one described their encounters with the disgraced TV star
They include waitresses, actresses, Playboy bunnies and journalists
The brave group range in age from their early 20s to 80
They came forward a week after a shocking deposition from 2005 surfaced
Comedian admitted he gave quaaludes to women he had sex with
By WILLS ROBINSON FOR DAILYMAIL.COM
PUBLISHED: 00:18 EST, 27 July 2015 | UPDATED: 04:54 EST, 27 July 2015



* * *


[From article]
A self-described hacker called ThreatKing, who says he hates New York City, claims he has successfully overwhelmed the site with a distributed denial-of-service attack (DDoS), overloading its servers with traffic. As of this writing, New York is completely inaccessible.[. . .]
ThreatKing provided a link to Vikingdom's Soundcloud page, which gives a hint into the group's reasoning. There, in a recording titled “Warning Message to the United States,” a robotic voice says “We are going to destroy state websites, city websites, agency websites and court websites of the United States. You have took away our country and its time to get it back by destroying the United States.”

http://www.dailydot.com/crime/new-york-magazine-ddos-bill-cosby-cover/

Anti-NYC hacker takes New York magazine offline
By William Turton
Jul 27, 2015, 6:58am CT | Last updated Jul 27, 2015, 3:48pm CT

July 14, 2015

One Million Digital Fingerprints of U.S. Government Employees Hacked




More and more theft of personal information enabling identity theft. Yet the mindless politicians and government bureaucrats continue to encourage more and more Wi-Fi and internet usage without providing or requiring informed consent for use of their personal private information to the users of this technology. It is not only a problem of a dumbed down population but a dumbed down government.  

[From article]
The Office of Personnel Management announced last week that the personal data for 21.5 million people had been stolen. But for national security professionals and cybersecurity experts, the more troubling issue is the theft of 1.1 million fingerprints.
Much of their concern rests with the permanent nature of fingerprints and the uncertainty about just how the hackers intend to use them. Unlike a Social Security number, address, or password, fingerprints cannot be changed—once they are hacked, they're hacked for good. And government officials have less understanding about what adversaries could do or want to do with fingerprints, a knowledge gap that undergirds just how frightening many view the mass lifting of them from OPM.
"It's probably the biggest counterintelligence threat in my lifetime," said Jim Penrose, former chief of the Operational Discovery Center at the National Security Agency and now an executive vice president at the cybersecurity company Darktrace. "There's no situation we've had like this before, the compromise of our fingerprints. And it doesn't have any easy remedy or fix in the world of intelligence."
[. . .]



Questions also remain about what the ultimate goal of the OPM hackers is, and the administration so far continues to refuse to publicly blame China for the intrusion. Some have likened the breach to an enormous surveillance operation, one that Beijing conducted in order to build databases on the ins and out of the U.S. government and to potentially coerce, blackmail, or bribe officials into divulging closely guarded secrets.
Whatever the motives, the stolen fingerprints are viewed as a uniquely important and unprecedented data heist—one that could reap huge rewards for the hackers for decades to come.
[. . .]
Part of the worry, cybersecurity experts say, is that fingerprints are part of an exploding field of biometric data, which the government is increasingly getting in the business of collecting and storing. Fingerprints today are used to run background checks, verify identities at borders, and unlock smartphones, but the technology is expected to boom in the coming decades in both the public and private sectors.
"There's a big concern [with the OPM hack] not because of how much we're using fingerprints currently, but how we're going to expand using the technology in the next 5-10 years," said Robert Lee, cofounder of Dragos Security, which develops cybersecurity software.
[. . .]
Also problematic is that there is "no way to reissue a fingerprint," Lee said, meaning that once a set is in the hands of a foreign adversary they are vulnerable as long as that person is working in government.
That reality could create a squeeze on government for decades to come, as agencies may be forced to forgo fingerprints for things like two-factor authentication and instead rely on another biometric, such as facial recognition or iris scans. But those could also someday be hacked, as the OPM hack showed that just about anything stored in a government database can be up for grabs.
[. . .]
But fingerprints are likely only going to grow in importance for the government in the coming years, he said, and that is true for hackers, too.
"You never know down the line where we are going to use the fingerprints," Kesanupalli said.
Penrose, the former NSA official, also speculated that most of the stolen fingerprints were likely digital scans and not the older ink-based records, which may suggest that the bulk of the prints belong to active or recent employees.

http://www.nationaljournal.com/tech/opm-hack-fingerprints-china-20150714

How Much Damage Can the OPM Hackers Do With a Million Fingerprints?
The pilfering of 1.1 million fingerprints is “probably the biggest counterintelligence threat in my lifetime,” one former NSA official said.
BY DUSTIN VOLZ
July 14, 2015

June 11, 2015

White House Negligence Enabled Chinese Hackers To Steal Government Employees Personal Information




Chinese hackers obtained all personnel records of U.S. government employees. No one knows what they will do with this information. The misguided White House demanded that all medical records be online using taxpayer funds to encourage medical facilities and professionals to place the information online. In another level of clueless public officials making policy the Cambridge City Council (and other governmental bodies) encouraged Wi-Fi nodes be installed across the city to allow everyone to enjoy access to the internet. There was no discussion of the lack of security of using this new technology. My queries to city officials who are teaching people to use Facebook without explaining how their information is a business went unanswered. Be prepared for any and all of your personal information being available to anyone with evil intent as easily as it is to those with good intentions. 

[From article]
Hackers stole personnel data and Social Security numbers for every federal employee, a government worker union said Thursday, asserting that the cyber theft of U.S. employee information was more damaging than the Obama administration has acknowledged.
[. . .]
The OPM data file contains the records of non-military, non-intelligence executive branch employees, which covers most federal civilian employees but not, for example, members of Congress and their staffs.
The union believes the hackers stole military records and veterans' status information, address, birth date, job and pay history, health insurance, life insurance and pension information; and age, gender and race data
[. . .]



"We believe that Social Security numbers were not encrypted, a cybersecurity failure that is absolutely indefensible and outrageous," Cox said in the letter. The union called the breach "an abysmal failure on the part of the agency to guard data that has been entrusted to it by the federal workforce."
Samuel Schumach, an OPM spokesman, said that "for security reasons, we will not discuss specifics of the information that might have been compromised."
The central personnel data file contains up to 780 separate pieces of information about an employee.
[. . .]
In the Senate on Thursday, Democrats blocked a Republican effort to add a cybersecurity bill to a sweeping defense measure. The vote was 56-40, four votes short of the number necessary.

http://hosted.ap.org/dynamic/stories/U/US_GOVERNMENT_HACKED?SITE=AP&SECTION=HOME&TEMPLATE=DEFAULT&CTIME=2015-06-11-15-58-33

Jun 11, 8:09 PM EDT
UNION: HACKERS HAVE PERSONNEL DATA ON EVERY FEDERAL EMPLOYEE
BY KEN DILANIAN
AP INTELLIGENCE WRITER

May 23, 2015

Adult Dating Site Hacked, Exposing Fetishes, Kinky Preferences, 6 Percent of Users Identified As Male





[From article]
Of the 3.9 million AFF members who were hacked, only 1,596 of the 26,939 users with a UK email address - less than six per cent - were identified as female.
[. . .]
That means the ratio of male to female AFF members in the UK is 16:1, Channel 4 News reported.

http://www.dailymail.co.uk/news/article-3095198/Hack-shows-UK-AdultFriendFinder-users-men.html

Hacked data from casual dating website reveals less than 6 per cent of the British users are female
Only 1,596 of the 26,939 users with a UK email address identified as female
3.9 million AFF members had highly sensitive information exposed in hack
Birthdays, ZIP codes, sexual orientations and IP addresses all revealed
AFF has more than 7 million British users and 63 million users worldwide
Offers traditional partners, swinger groups, threesomes and alternatives
By EVAN BLEIER FOR DAILYMAIL.COM
PUBLISHED: 11:57 EST, 24 May 2015 | UPDATED: 18:00 EST, 24 May 2015

* * *

[From article]
The site, which boasts 64 million members, claims to have "helped millions of people find traditional partners, swinger groups, threesomes, and a variety of other alternative partners."
The information Adult FriendFinder collects is extremely personal in nature. When signing up for an account, customers must enter their gender, which gender they're interested in hooking up with and what kind of sexual situations they desire. Suggestions AdultFriendfinder provides for the "tell others about yourself" field include, "I like my partners to tell me what to do in the bedroom," "I tend to be kinky" and "I'm willing to try some light bondage or blindfolds."

http://money.cnn.com/2015/05/22/technology/adult-friendfinder-hacked/index.html

Adult dating site hack exposes sexual secrets of millions
By David Goldman and Jose Pagliery
May 22, 2015

April 11, 2015

Maine Sheriff Pays Ransom To Gain Access to Hacked Police Computers





[From article]
The Portland station said the Lincoln County Sheriff’s Office and four towns paid $300 to the hackers after a virus, called a “megacode,” was downloaded on a computer system they share. Lincoln County Sheriff Todd Bracket said that the computer system was unusable until the fee was paid, and that the hackers claimed the program, called “ransomware,” would wipe the entire computer system clean if the fee wasn’t paid.
The creator of the virus gave the sheriff’s office a code to unlock the computer system after the money was received. The county paid in bitcoins, an online currency.
“We needed our programs to get back online,” said Damariscotta Police Chief Ron Young. “That was a choice we all discussed and took to get back online to get our information.”
Brackett told WCSH that the FBI tracked the payment to a Swiss bank account, but no further.
The Houlton Police Department told the station that it was hit with a similar virus early this week and its computer system was locked up until ransom was paid.
Last summer, the FBI, foreign governments and private security firms dismantled an operation, based in Russia, that commandeered as many as a million computers and drew money out of bank accounts, The Washington Post reported. The operation also included a ransomware scheme and officials said they had identified the 30-year-old Russian behind the operation but had not apprehended him.

http://www.pressherald.com/2015/04/10/police-departments-pay-hackers-to-unlock-computer-system/

Posted April 9, 2015 at 11:10 PM
Updated April 10, 2015
Maine police departments pay hackers to unlock computer system
The Lincoln County Sheriff's Office and four towns that share a system say they paid $300 after the hackers claimed the 'ransomware' program would wipe the system clean.
FROM STAFF REPORTS

February 28, 2015

Teen, 16, Hacked High School Computers To Change His Grades



Eric Walstrom, at his home Thursday, allegedly hacked into computers at New Dorp High School and changed his grades.
[From article]
Eric Walstrom, 16, a junior at New Dorp HS, made it past a password barrier and software security system using a computer in the school and set up the network so he could access it from his smartphone, the sources said.
Between Dec. 14 and Feb. 9, he pulled up his report cards and transcripts and “changed those grades,” according to a criminal complaint.
[. . .]
He was caught when a school IT worker noticed the unauthorized log-ins to the system, sources said. The school notified police, and Walstrom was arrested Wednesday.
He was charged as an adult with forgery, computer trespass, unauthorized use of a computer, computer tampering and criminal possession of forgery devices.
Walstrom learned some of his high-tech tricks at an elite summer camp at NYU.

http://nypost.com/2015/02/27/cyber-hacking-si-student-changed-grades-from-his-smartphone-cops/

Kid charged with using smart phone to hack school, change his grades
By Frank Rosario, Erin Calabrese and Natalie O'Neill
February 27, 2015 | 2:07am
New York Post

February 20, 2015

Hackers Steal $1 billion From 100 Banks By Watching How Employees Entered Transacations



An ATM keypad. Hackers are believed to have infiltrated dozens of banks and even programmed ATMs to dispense money at specific times.
Photograph: Sarah Lee/Sarah Lee

[From article]
The bank’s internal computers, used by employees who process daily transfers and conduct bookkeeping, had been penetrated by malware that allowed cybercriminals to record their every move. The malicious software lurked for months, sending back video feeds and images that told a criminal group — including Russians, Chinese and Europeans — how the bank conducted its daily routines, according to the investigators.
Then the group impersonated bank officers, not only turning on various cash machines, but also transferring millions of dollars from banks in Russia, Japan, Switzerland, the United States and the Netherlands into dummy accounts set up in other countries.
[. . .]


"The goal was to mimic their activities,” said Sergey Golovanov of Kaspersky, about how the thieves targeted bank employees.
CreditRaphael Satter/Associated Press

In many ways, this hack began like any other. The cybercriminals sent their victims infected emails — a news clip or message that appeared to come from a colleague — as bait. When the bank employees clicked on the email, they inadvertently downloaded malicious code. That allowed the hackers to crawl across a bank’s network until they found employees who administered the cash transfer systems or remotely connected A.T.M.s.
Then, Kaspersky’s investigators said, the thieves installed a “RAT”— remote access tool — that could capture video and screenshots of the employees’ computers.
“The goal was to mimic their activities,” said Sergey Golovanov, who conducted the inquiry for Kaspersky Lab. “That way, everything would look like a normal, everyday transaction,” he said in a telephone interview from Russia.
The attackers took great pains to learn each bank’s particular system, while they set up fake accounts at banks in the United States and China that could serve as the destination for transfers. Two people briefed on the investigation said that the accounts were set up at J.P. Morgan Chase and the Agricultural Bank of China.
[. . .]
But the largest sums were stolen by hacking into a bank’s accounting systems and briefly manipulating account balances. Using the access gained by impersonating the banking officers, the criminals first would inflate a balance — for example, an account with $1,000 would be altered to show $10,000. Then $9,000 would be transferred outside the bank. The actual account holder would not suspect a problem, and it would take the bank some time to figure out what had happened.
Method:
Hackers send email containing a malware program called Carbanak to hundreds of bank employees, hoping to infect a bank’s administrative computer.
Programs installed by the malware record keystrokes and take screen shots of the bank’s computers, so that hackers can learn bank procedures. They also enable hackers to control the banks’ computers remotely.
By mimicking the bank procedures they have learned, hackers direct the banks’ computers to steal money in a variety of ways:
Transferring money into hackers’ fraudulent bank accounts
Using e-payment systems to send money to fraudulent accounts overseas
Directing A.T.M.s to dispense money at set times and locations

http://www.nytimes.com/2015/02/15/world/bank-hackers-steal-millions-via-malware.html?_r=0

Bank Hackers Steal Millions via Malware
By DAVID E. SANGER and NICOLE PERLROTH New York Times FEB. 14, 2015

* * *

[From article]
The Financial Services Information Sharing and Analysis Center, a nonprofit that alerts banks about hacking activity, said in a statement that its members received a briefing about the report in January.

http://www.theguardian.com/technology/2015/feb/16/hackers-steal-1bn-in-online-bank-thefts-says-report

Hackers steal $1bn in series of online bank thefts says report
Security firm says hackers infiltrated more than 100 banks and ‘watched’ employees to gain knowledge of systems
Associated Press
Sunday 15 February 2015 22.19 EST

February 19, 2015

Government Spies Hack Cell Phone SIM Cards



Diagram from a top-secret GCHQ slide.
[From article]
AMERICAN AND BRITISH spies hacked into the internal computer network of the largest manufacturer of SIM cards in the world, stealing encryption keys used to protect the privacy of cellphone communications across the globe, according to top-secret documents provided to The Intercept by National Security Agency whistleblower Edward Snowden.
The hack was perpetrated by a joint unit consisting of operatives from the NSA and its British counterpart Government Communications Headquarters, or GCHQ. The breach, detailed in a secret 2010 GCHQ document, gave the surveillance agencies the potential to secretly monitor a large portion of the world’s cellular communications, including both voice and data.
[. . .]
With these stolen encryption keys, intelligence agencies can monitor mobile communications without seeking or receiving approval from telecom companies and foreign governments. Possessing the keys also sidesteps the need to get a warrant or a wiretap, while leaving no trace on the wireless provider’s network that the communications were intercepted. Bulk key theft additionally enables the intelligence agencies to unlock any previously encrypted communications they had already intercepted, but did not yet have the ability to decrypt.
[. . .]
Leading privacy advocates and security experts say that the theft of encryption keys from major wireless network providers is tantamount to a thief obtaining the master ring of a building superintendent who holds the keys to every apartment. “Once you have the keys, decrypting traffic is trivial,” says Christopher Soghoian, the principal technologist for the American Civil Liberties Union. “The news of this key theft will send a shock wave through the security community.”
[. . .]
The U.S. and British intelligence agencies pulled off the encryption key heist in great stealth, giving them the ability to intercept and decrypt communications without alerting the wireless network provider, the foreign government or the individual user that they have been targeted. “Gaining access to a database of keys is pretty much game over for cellular encryption,” says Matthew Green, a cryptography specialist at the Johns Hopkins Information Security Institute. The massive key theft is “bad news for phone security. Really bad news.”

https://firstlook.org/theintercept/2015/02/19/great-sim-heist/

THE GREAT SIM HEIST
HOW SPIES STOLE THE KEYS TO THE ENCRYPTION CASTLE
BY JEREMY SCAHILL AND JOSH BEGLEY @jeremyscahill@joshbegley
TODAY AT 2:25 PM

January 22, 2015

Seven-Year-Old Hacks Into Public Wi-Fi in 11 Minutes


Betsy Davies (pictured) watched an online video tutorial before being asked to hack into a Wi-Fi hotspot. It took the seven-year-old 11 minutes to infiltrate the network by setting up a rogue access point - frequently used by attackers to activate a ‘man in the middle’ attack, and begin eavesdropping on - or ‘sniffing’ - traffic.
[From article]
Just two days after an investigation revealed how much personal information public Wi-Fi networks can ‘suck’ from phones, a child has shown how easy the hotspots are to hack.
A seven-year-old broke into a Wi-Fi hotspot in just 10 minutes and 54 seconds after watching an online video tutorial.
The ethical hacking demo was carried out under the supervision of an online security expert to highlight just how vulnerable the networks are.

[. . .]
An investigation by 5 News earlier this week found that hackers can force customers in a café to switch their phones from a legitimate Wi-Fi network to a fake one, without them knowing.


Rogue Access Points are wireless access points, installed on a company’s network without the company’s knowledge. Ms Davies began by searching for, and watching, a freely available video tutorial detailing how to hack a network - a Google search returns over 11 million results, and YouTube lists 14,000 tutorials (pictured)
http://www.dailymail.co.uk/sciencetech/article-2919762/Hacking-Wi-Fi-s-child-s-play-Seven-year-old-shows-easy-break-public-network-11-minutes.html

Hacking Wi-Fi is child’s play! 7-year-old shows how easy it is to break into a public network in less than 11 MINUTES
Experts predict a rise in criminals hacking ‘free Wi-Fi’ in 2015
To highlight the dangers, a virtual private network provider asked a seven-year-old to hack a network
The child watched an online tutorial before hacking into the Wi-Fi hotspot
It took her just 10 minutes and 54 seconds to infiltrate the network
By VICTORIA WOOLLASTON FOR MAILONLINE
PUBLISHED: 06:07 EST, 21 January 2015 | UPDATED: 14:29 EST, 22 January 2015




January 12, 2015

French Websites Hacked To Show ISIS Flag




The hacked Terre D'Argence site referred to Palestine.
An Algerian group called "L'Apoca-DZ" took credit for the hacks and provided links to contact them.
Authorities have identified a 17-year-old with "no connection" to ISIS as the culprit, news.com.au reported.
ot-terredargence.fr/


[From article]
Several French websites were hacked to display the ISIS flag as the country reels from the Charlie Hebdo magazine massacre that killed 12 innocents in Paris Thursday.
The black and white extremist banner invaded the websites of at least five town governments on the outskirts of Paris, including Piscop, Val D'Oise, Ezanville and Jouy-le-Moutier, according to Global News.
"The Islamic State Stay Inchallah, Free Palestine, Death to France, Death to Charlie," the hacked sites read as Arabic music played in the background.

http://www.nydailynews.com/news/world/sites-hacked-display-isis-flag-paris-slaughter-article-1.2071357

French websites hacked to display ISIS flag in aftermath of Charlie Hebdo slaughter
The infamous banner and other extremist imagery appeared on the websites of at least five town governments outside Paris, including Piscop, Val D'Oise, Ezanville and Jouy-le-Moutier, late Thursday.
BY RACHELLE BLIDNER 
NEW YORK DAILY NEWS
Friday, January 9, 2015, 6:57 AM

December 23, 2014

Anonymous Threatens SONY, Claims Credit For Hack, Says It's Not North Korea





[From anonymous Message]
We shall first-off begin this message with an expression of sympathy as you have failed to release “The Interview” as you believe that hackers shall carry out a new operation to cause malicious damage within your organisation.
I would like to inform you that we all know the hacks didn’t come from North Korea (we think everybody knows about this already).
[. . .]
Obviously, this document was only created by a group of 25 – 30 Anons, but there are more of us on the internet than you can possibly imagine.
We are Anonymous,
We are Legion,
We do not forgive,
We do not forget,
Expect us.

http://www.showbiz411.com/2014/12/21/sony-gets-a-new-threat-anonymous-says-hackers-arent-korean-release-film-or-more-hacks-coming

Sony Gets a New Threat– “Anonymous” Says Hackers Aren’t Korean, Release Film Or More Hacks Coming
by Roger Friedman
December 21, 2014 12:09 am

November 9, 2014

Four Hundred Million Financial Records Stolen Online




[From article[
Federal officials warned companies Monday that hackers have stolen more than 500 million financial records over the past 12 months, essentially breaking into banks without ever entering a building.
"We're in a day when a person can commit about 15,000 bank robberies sitting in their basement," said Robert Anderson, executive assistant director of the FBI's Criminal Cyber Response and Services Branch.
The U.S. financial sector is one of the most targeted in the world, FBI and Secret Service officials told business leaders at a cybersecurity event organized by the Financial Services Roundtable. The event came in the wake of mass hacking attacks against Target, Home Depot, JPMorgan Chase and other financial institutions.
"You're going to be hacked," Joseph Demarest, assistant director of the FBI's cyberdivision, told the business leaders. "Have a plan."
Nearly 439 million records were stolen in the past six months, said Supervisory Special Agent Jason Truppi of the FBI. Nearly 519 million records were stolen in the past 12 months, he said.

http://www.usatoday.com/story/news/politics/2014/10/20/secret-service-fbi-hack-cybersecuurity/17615029/

Officials warn 500 million financial records hacked
Erin Kelly
USA TODAY
8:10 p.m. EDT October 20, 2014