Article Details

Scrape Timestamp (UTC): 2024-03-20 06:52:34.192

Source: https://thehackernews.com/2024/03/ukraine-arrests-trio-for-hijacking-over.html

Original Article Text

Click to Toggle View

Ukraine Arrests Trio for Hijacking Over 100 Million Email and Instagram Accounts. The Cyber Police of Ukraine has arrested three individuals on suspicion of hijacking more than 100 million emails and Instagram accounts from users across the world. The suspects, aged between 20 and 40, are said to be part of an organized criminal group living in different parts of the country. If convicted, they face up to 15 years in prison. The accounts, authorities said, were taken over by carrying out brute-force attacks, which employ trial-and-error methods to guess login credentials. The group operated under the direction of a leader, who distributed the hacking tasks to other members. The cybercrime group subsequently monetized their ill-gotten credentials by putting them up for sale on dark web forums. Other threat actors who purchased the information used the compromised accounts to conduct a variety of fraudulent schemes, including those in which scammers reach out to the victim's friends to urgently transfer money to their bank account. "You can protect your account from this method of hacking by setting up two-factor authentication and using strong passwords," the agency said. As part of the operation, officials conducted seven searches in Kyiv, Odesa, Vinnytsia, Ivano-Frankivsk, Donetsk, and Kirovohrad, confiscating 70 computers, 14 phones, bank cards, and cash worth more than $3,000. The development comes as a U.S. national pleaded guilty to breaching over a dozen entities in the U.S., including a medical clinic in Griffin, and exfiltrating the personal information of more than 132,000 individuals. He is scheduled for sentencing on June 18, 2024. Robert Purbeck (aka Lifelock or Studmaster) "aggravated his crimes by weaponizing sensitive data in an egregious attempt to extort his victims," U.S. Attorney Ryan K. Buchanan said. According to the U.S. Department of Justice (DoJ), Purbeck, who pleaded guilty today to federal charges of computer fraud and abuse, purchased access to the clinic's computer server from the darknet in 2017, leveraging it to siphon medical records and other documents that contained data pertaining to over 43,000 individuals, such as names, addresses, birthdates, and social security numbers. The defendant also bought credentials associated with the City of Newnan, Georgia, Police Department server on an underground marketplace. He then plundered records consisting of police reports and documents that had information belonging to no less than 14,000 people. As part of the plea agreement, Purbeck agreed to pay more than $1 million in restitution to the impacted 19 victims. He was indicted by a federal jury in March 2021. Goodbye, Atlassian Server. Goodbye… Backups? Protect your data on Atlassian Cloud from disaster with Rewind's daily backups and on-demand restores. Take Action Fast with Censys Search for Security Teams Stay ahead of advanced threat actors with best-in-class threat intelligence from Censys Search.

Daily Brief Summary

CYBERCRIME // Ukraine Detains Three for Global Email and Instagram Account Hijacking

Ukrainian Cyber Police arrested three people for hacking over 100 million email and Instagram accounts worldwide.

The suspects are accused of conducting brute-force attacks to gain unauthorized access to accounts and selling credentials on the dark web.

Arrested individuals could face up to 15 years in prison if found guilty.

Authorities executed seven searches across Ukraine, seizing computers, phones, and other assets.

A U.S. national admitted to computer fraud for breaching over a dozen entities and exfiltrating personal data of 132,000 individuals.

The U.S. defendant, who caused harm by extorting victims with sensitive data, agreed to pay over $1 million in restitution.

The mention of Atlassian Server referring to Rewind's services and Censys Search appears to be unrelated promotional content.