Tag Archive for: prosecutors

Wawa paying state prosecutors $8M to settle malware data breach | Business


Source…

U.S. prosecutors unseal indictments tied to computer hack at Kansas nuclear plant – The Wellington Daily News


By Tim Carpenter Kansas Reflector

TOPEKA — Federal prosecutors unsealed indictments against four Russian government computer hackers who targeted global infrastructure in a campaign that included breach of the business network at Wolf Creek nuclear power plant in Kansas.

The U.S. Department of Justice said indictments made public Thursday charged Russian nationals with attempting, supporting and conducting computer intrusions that together, in two separate conspiracies, targeted software and hardware systems linked to the global energy sector between 2012 and 2018.

Prosecutors alleged the hacking campaigns targeted thousands of computers at hundreds of companies and organizations in the United States and in more than 135 countries. The indictments allege wire and computer fraud and identity theft.

U.S. Attorney Duston Slinkard of Kansas said potential of cyberattacks to disrupt, if not paralyze, the delivery of critical energy services to hospitals, homes, businesses and other locations was a sobering reality.

“We must acknowledge there are individuals actively seeking to wreak havoc on our nation’s vital infrastructure system, and we must remain vigilant in our effort to thwart such attacks,” Slinkard said.

According to indictments, the energy sector campaign involved two phases. In the first phase, which took place between 2012 and 2014, conspirators engaged in a supply chain attack, compromising computer networks of system manufacturers and software providers and then hiding malware inside legitimate software updates for such systems.

After unsuspecting customers downloaded infected updates, the conspirators used malware to create backdoors into infected systems and scan victims’ networks. Through these and other efforts, prosecutors allege conspirators installed malware on more than 17,000 unique devices in the United States and abroad, including controllers used by power and energy companies.

In the second phase, which transpired between 2014 and 2017, the conspirators transitioned to more targeted specific energy sector entities and individuals and engineers. The indictments say conspirators attacked more than 3,300 users at more than 500…

Source…

SolarWinds hackers nailed federal prosecutors’ offices, Department of Justice says


Hackers hit the offices of top US federal prosecutors nationwide last December, breaking in to email accounts, the Department of Justice said Friday. As part of the SolarWinds hack, attackers accessed accounts at nearly 30 US Attorneys’ offices, including offices in Washington, DC; New York and California, the DOJ said.



a close up of a piece of paper: Hackers had access to email accounts for more than six months, the DOJ says. Samuel Corum/Getty Images


© Provided by CNET
Hackers had access to email accounts for more than six months, the DOJ says. Samuel Corum/Getty Images

The department had revealed in January that its Microsoft O365 email environment had been breached, but it hadn’t provided the information about the US Attorneys.

“The Department of Justice understands that when victims make information public about the nature and scope of computer intrusions they suffered, others can use that information to prepare themselves for the next threat,” the DOJ said in a statement Friday. “To encourage transparency and strengthen homeland resilience, today we are providing additional details about the SolarWinds intrusion in December 2020.”





© Samuel Corum/Getty Images


The DOJ said at least one employee’s account had been accessed at 27 offices from the West Coast to the East. It said at least 80% of employees at the US Attorneys’ offices in the Eastern, Northern, Southern, and Western Districts of New York had seen their accounts breached, with other districts “impacted to a lesser degree.”

Loading...

Load Error

The hackers are thought to have had access to breached accounts from about May 7 to Dec. 27 of last year, the DOJ said, adding that exposed data included sent, received and stored emails as well as attachments. The agency said in January that it had plugged the breach.

“The Department’s objective continues to be mitigating the operational, security, and privacy risks caused by the incident,” the DOJ said in its Friday statement.

The SolarWinds hack, which US intelligence agencies say likely originated in Russia, hit customers of IT software provider SolarWinds, including a number of private businesses and federal agencies. Victims included high-level officials at the Department of Homeland Security, showing that not even the government agency in charge of defending the US from foreign…

Source…

Hacker Known as Max Is a 55-Year-Old Woman, Prosecutors Say


(Bloomberg) — Alla Witte’s plans for a new career as a computer programmer included helping clients make enough money to see the world, according to YouTube videos and social media posts. She was in her late 40s with a degree in applied mathematics and an itch to do computer programming.



a close up of a sign: Epstein Friend Ghislaine Maxwell Arrested By FBI


© Photographer: Bloomberg/Bloomberg
Epstein Friend Ghislaine Maxwell Arrested By FBI

But there was a darker side to Witte’s interest in computers, according to federal prosecutors. In the six years leading to October 2018, Witte, a Latvian citizen who grew up in Russia, allegedly transformed from amateur developer to a key cog in a cybercrime syndicate known as Trickbot.

Witte, now 55, assumed the identity “Max” and started writing illicit code, according to a federal indictment unsealed on Feb. 8 after she was detained in Miami. She’s since been transferred to Cleveland, where she’s one of seven alleged members of the Trickbot gang facing charges for their role in a global fraud, data theft and ransomware operation with roots in Russia, Ukraine and Belarus.



a close up of a sign: Epstein Friend Ghislaine Maxwell Arrested By FBI


© Photographer: Bloomberg/Bloomberg
Epstein Friend Ghislaine Maxwell Arrested By FBI

But Witte is the first alleged member of the Trickbot cybergang ever to be detained in the U.S. She appeared before a U.S. magistrate judge on June 4 for her arraignment, where she waived her rights to a detention hearing. She hasn’t yet made any pleadings in the case.

Loading...

Load Error

Witte’s public defender in Cleveland, Ed Bryan, didn’t respond to requests for comment.

If Witte were to cooperate with authorities, her insights could be invaluable at a time when the Biden administration and a newly formed Justice Department task force are taking aim at ransomware and other cybercrime, said Alex Holden, the founder of the cyber-investigations firm Hold Security. She could also help U.S. officials understand the structure of a tenacious and wide-ranging cybercrime operation with so many tentacles that it managed to evade a pair of takedown operations by U.S. Cyber Command and Microsoft Corp. in 2020, he said.



a close up of a keyboard: RF Keyboard computer


© Photographer: Oliver Nicolaas Ponder/EyeEm via Getty Images
RF Keyboard computer

Read More: Botnet…

Source…