For Immediate Release
January 18, 2011 United States Attorney's Office
District of New Jersey
Contact: (973) 645-2888
Two Men Charged in New Jersey with Hacking AT&T’s Servers
Defendants Allegedly Stole E-Mail Addresses and Personal Information Belonging to 120,000 Apple iPad 3G Subscribers
NEWARK, NJ—Two self-described Internet “trolls” were arrested today for allegedly hacking AT&T’s servers and stealing e-mail addresses and other personal information belonging to approximately 120,000 Apple iPad users who accessed the Internet via AT&T’s 3G network, United States Attorney Paul J. Fishman announced.
Andrew Auernheimer, 25, of Fayetteville, Ark., and Daniel Spitler, 26, of San Francisco, Calif., were taken into custody this morning by special agents of the FBI—each charged with an alleged conspiracy to hack AT&T’s servers and for possession of personal subscriber information obtained from the servers. Auernheimer was arrested in Fayetteville while appearing in Arkansas state court on unrelated drug charges, and is expected to appear this afternoon before United States Magistrate Judge Erin L. Setser in Fayetteville federal court. Spitler surrendered to FBI agents in Newark and is expected to appear in Newark federal court before United States Magistrate Judge Claire C. Cecchi.
According to the Complaint unsealed today:
The iPad is a touch-screen tablet computer, developed and marketed by Apple Computers, Inc., which allows users to, among other things, access the Internet and send and receive electronic mail. Since the introduction of the iPad in January 2010, AT&T has provided iPad users with Internet connectivity via AT&T’s 3G wireless network. During the registration process for subscribing to the network, a user is required to provide an e-mail address, billing address, and password.
Prior to mid-June 2010, AT&T automatically linked an iPad 3G user’s e-mail address to the Integrated Circuit Card Identifier (“ICC-ID”), a number unique to the user’s iPad, when he registered. As a result, every time a user accessed the AT&T website, his ICC-ID was recognized and his e-mail address was automatically populated for faster, user-friendly access to the site. AT&T kept the ICC-IDs and associated e-mail addresses confidential.
At that time, when an iPad 3G communicated with AT&T’s website, its ICC-ID was automatically displayed in the Universal Resource Locator, or “URL,” of the AT&T website in plain text. Seeing this, and discovering that each ICC-ID was connected to an iPad 3G user e-mail address, hackers wrote a script termed the “iPad 3G Account Slurper”and deployed it against AT&T’s servers.
The Account Slurper attacked AT&T’s servers for several days in early June 2010, and was designed to harvest as many ICC-ID/e-mail address pairings as possible. It worked by mimicking the behavior of an iPad 3G so that AT&T’s servers would be fooled into granting the Account Slurper access. Once deployed, the Account Slurper used a process known as a “brute force” attack—an iterative process used to obtain information from a computer system—against the servers, randomly guessing at ranges of ICC-IDs. An incorrect guess was met with no additional information, while a correct guess was rewarded with an ICC-ID/e-mail pairing for a specific, identifiable iPad 3G user.
From June 5 through June 9, 2010, the Account Slurper stole for its hacker-authors approximately 120,000 ICC-ID/e-mail address pairings for iPad 3G customers. Immediately following the theft, the hacker-authors of the Account Slurper provided the stolen e-mail addresses and ICC-IDs to the website Gawker, which published the stolen information in redacted form, along with an article concerning the breach. The article indicated that the breach “exposed the most exclusive e-mail list on the planet,”and named a number of famous individuals whose e-mails had been compromised, including Diane Sawyer, Harvey Weinstein, Mayor Michael Bloomberg, and Rahm Emanuel. The article also stated that iPad users could be vulnerable to spam marketing and malicious hacking. A group calling itself “Goatse Security” was identified as obtaining the subscriber data.
According to its website, Goatse Security is a loose association of Internet hackers and self-professed Internet “trolls”—people who intentionally, and without authorization, disrupt services and content on the Internet—to which both Spitler and Auernheimer belong.
Auernheimer previously has been outspoken about his trolling activities, bragging to The New York Times in August 2008: “I hack, I ruin, I make piles of money.” Auernheimer has also made Internet video postings taking credit for trolling Amazon.com and causing a “one billion dollar change in their market capitalization.”
During the data breach, Spitler and Auernheimer communicated with one another using Internet Relay Chat, an Internet instant messaging program. Those chats not only demonstrate that Spitler and Auernheimer were responsible for the data breach, but also that they conducted the breach to simultaneously damage AT&T and promote themselves and Goatse Security. As the data breach continued, so too did the discussions between Spitler, Auernheimer, and other Goatse Security members about the best way to take advantage of the breach and associated theft. On June 10, 2010, immediately after going public with the breach, Spitler and Auernheimer discussed destroying evidence of their crime.
U.S. Attorney Fishman stated: “Hacking is not a competitive sport, and security breaches are not a game. Companies that are hacked can suffer significant losses, and their customers made vulnerable to other crimes, privacy violations, and unwanted contact. Computer intrusions and the spread of malicious code are a threat to national security, corporate security, and personal security. Those who use technological expertise for malicious purposes take note: your activities in cyberspace can have serious consequences for you in the real world.”
“One primary principle of our society is confidence in a reasonable expectation of personal privacy, which includes expectations of financial privacy, medical privacy, and privacy in our communications,” said Michael B. Ward, Special Agent in Charge of the FBI’s Newark field office. “Unauthorized intrusions into personal privacy adversely affect individual citizens, businesses, and even national security. Such intrusion cases, regardless if the motive is criminal gain or prestige among peers in the cyber-hacking world, must and will be aggressively pursued to ensure these rights are protected to the highest degree.”
Each defendant is charged with one count of conspiracy to access a computer without authorization and one count of fraud in connection with personal information. Each count with which the defendants are charged carries a maximum potential penalty of five years in prison and a fine of $250,000.
U.S. Attorney Fishman credited special agents of the FBI, under the direction of Special Agent in Charge Michael B. Ward in Newark, with the investigation leading to the charges. He also thanked special agents of the FBI, under the direction of Special Agent in Charge Valerie Parlave in Little Rock, Ark., and the U.S. Attorney’s Office for the Western District of Arkansas, under the direction of U.S. Attorney William Conner Eldridge.
The government is represented by Assistant United States Attorneys Lee Vartan and Zach Intrater of the Computer Hacking and Intellectual Property Section of the United States Attorney’s Office Economic Crimes Unit.
OneTrueFan
أرشيف المدونة الإلكترونية
-
▼
2011
(137)
-
▼
يناير
(68)
- Google Sidewiki-inlägg av mayas
- الهلال الأحمر السوداني العضوية = "https://blogger...
- مدون الطنين : بالاضافة الى انك قد انتقل!
- مدون الطنين : بالاضافة الى انك قد انتقل!
- Earth Friendly Biz
- var _gaq = _gaq || []; _gaq.push(['_setAcco...
- بلدي Blogg من أجل النجاح!
- ! -- google_ad_client = "كاليفورنيا ، حانة - 3674...
- <!-- google_ad_client = "ca-pub-3674505408284363";...
- My Blogg For Success!: the lara27.com
- WindowBuilder يصبح مشروع جديد مفتوح المصدر -- جوجل...
- a href="http://ff4e4igxek6ufyct3cw3v9zipl.hop.clic...
- <!-- google_ad_client = "ca-pub-3674505408284363";...
- <!-- google_ad_client = "ca-pub-3674505408284363";...
- 'المايا' : جوجل : لدينا هدية كبيرة للشركات الصغيرة
- <!-- Begin Code Amber Ticker code. --> <!-- end ...
- بلا عنوان
- Censura à imprensa – A luta continua
- جعل حلول سريعة أسرع على جوجل المشروع استضافة -- جو...
- جعل حلول سريعة أسرع على جوجل المشروع استضافة -- جو...
- يورونيوز نتائج المصادقة : 20hound http://moneymaki...
- ظات كامل كما أعدت للمساعد المدير المسؤول في جانيس ...
- معلومات ملاحظات كامل كما أعدت للمساعد المدير المس...
- وسائل الاعلام الاستشارية في المؤتمر الصحفي على إطل...
- n Sentenced for Child Pornography Offense Info S...
- معلومات مشاركة 14 عضوا جامبينو الأسرة الجريمة وال...
- معلومات مشاركة 14 عضوا جامبينو الأسرة الجريمة وال...
- ب التحقيقات الفدرالي صحفية إحصائيات الجريمة البنك ...
- مكتب التحقيقات الفدرالي أخبار العشرة قصص للأسبوع ا...
- من الميثامفيتامين الفعلية. القصة الكاملة
- معلومات الملكات المدعي بأنه مذنب في محكمة مانهاتن...
- Alleged Terrorist Charged with Conspiracy to Kill ...
- معلومات مانهاتن وزير العدل الامريكي رسوم برونكس ا...
- معلومات راندال Thysse عامل خاص باسم المسؤول عن مج...
- ق مكتب المدعي الاميركي ' 13 يناير 2011 * شم...
- المافيا انهاء الخدمة اعتقال أكبر المنسقة في مكتب ا...
- For Immediate Release January 14, 2011 United Sta...
- For Immediate Release January 14, 2011 United Sta...
- ustice Press Release white spacer For Immediate Re...
- For Immediate Release January 14, 2011 United Sta...
- stice Press Release white spacer For Immediate Rel...
- January 14, 2011 U.S. Department of Justice Offic...
- United States Attorney's Office District of Maryla...
- January 14, 2011 United States Attorney's Offi...
- الولايات المتحدة مكتب المدعي العام المنطقة الشمالي...
- For Immediate Release January 14, 2011 U.S. De...
- January 14, 2011 United States Attorney's Offi...
- January 14, 2011 U.S. Department of Justice Of...
- For Immediate Release January 18, 2011 United ...
- January 14, 2011 United States Attorney's Offi...
- وزارة العدل بيان صحفي white spacer للنشر الفوري 18...
- For Immediate Release January 18, 2011 United ...
- للنشر الفوري 18 يناير 2011 الولايات المتحدة مك...
- سر انطلاقة جديدة هو كل ما تحتاجه الآن لكي احصل على...
- Get Google™ Ads Free!
- WinZip Learn More | Kaspersky Lab United States
- من اجل الجمال والعنايةفي البشرةولاخ
- الحصول على جوجل ™ ؛ الإعلانات الحرة!
- internetmarketersmall.com
- بلا عنوان
- Post to my social network or blog
- <p align="center"><a href="http://cbpirate.com/mai...
- View HTML
- http://www.automatedtraffic.com/auto_ads/generateB...
- http://www.automatedtraffic.com/auto_ads/generateB...
- Personality vs Brand: And The Winner is...
- Personality vs Brand: And The Winner is...
-
▼
يناير
(68)
Code Amber News Service (CANS) - The Web's Amber 8
المتابعون
الثلاثاء، 18 يناير 2011
الاشتراك في:
تعليقات الرسالة (Atom)
ليست هناك تعليقات:
إرسال تعليق