Bomb Threat, DDoS Purveyor Gets Eight Years

A 22-year-old North Carolina man has been sentenced to nearly eight years in prison for conducting bomb threats against thousands of schools in the U.S. and United Kingdom, running a service that launched distributed denial-of-service (DDoS) attacks, and for possessing sexually explicit images of minors.

Timothy Dalton Vaughn from Winston-Salem, N.C. was a key member of the Apophis Squad, a gang of young ne’er-do-wells who made bomb threats to more than 2,400 schools and launched DDoS attacks against countless Web sites — including KrebsOnSecurity on multiple occasions.

The Justice Department says Vaughn and his gang ran a DDoS-for-hire service that they used to shake down victims.

“In early 2018, Vaughn demanded 1.5 bitcoin (then worth approximately $20,000) from a Long Beach company, to prevent denial-of-service attacks on its website,” reads a statement from Nicola Hanna, U.S. attorney for the Central District of California. “When the company refused to pay, he launched a DDoS attack that disabled the company’s website.”

One of many tweets from the attention-starved Apophis Squad, which launched multiple DDoS attacks against KrebsOnSecurity over the past few months.

Dalton, whose online aliases included “WantedbyFeds” and “Hacker_R_US,” pleaded guilty last year to one count of conspiracy to convey threats to injure, convey false information concerning use of explosive device, and intentionally damage a computer; one count of computer hacking; and one count of possession of child pornography.

Federal judge Otis D. Wright II sentenced Vaughn to 95 months for possessing 200 sexually explicit images and videos depicting children, including at least one toddler, the Justice Department said. Vaughn was sentenced to 60 months in federal prison for the remaining charge. The sentences will be served concurrently.

As KrebsOnSecurity noted in 2019, Vaughn’s identity was revealed by following the trail of clues from a gaming website he used that later got hacked.

Vaughn used multiple aliases on Twitter and elsewhere to crow about his attacks, including “HDGZero,” “WantedByFeds,” and “Xavier Farbel.” Among the Apophis Squad’s targets was encrypted mail service Protonmail, which reached out to this author in 2018 for clues about the identities of the Apophis Squad members after noticing we were both being targeted by them and receiving demands for money in exchange for calling off the attacks.

Protonmail later publicly thanked KrebsOnSecurity for helping to bring about the arrest of Apophis Squad leader George Duke-Cohan — a.k.a. “opt1cz,” “7R1D3n7,” and “Pl3xl3t,” — a 19-year-old from the United Kingdom who was convicted in December 2018 and sentenced to three years in prison. But the real-life identity of HDGZero remained a mystery to both of us, as there was little publicly available information at the time connecting that moniker to anyone.

The DDoS-for-hire service run by Apophis Squad listed their members.

That is, until early January 2019, when news broke that hackers had broken into the servers of computer game maker BlankMediaGames and made off with account details of some 7.6 million people who had signed up to play “Town of Salem,” a browser-based role playing game. That stolen information has since been posted and resold in underground forums.

A review of the leaked BlankMediaGames user database shows that in late 2018, someone who selected the username “hdgzero” signed up to play Town of Salem, registering with the email address xavierfarbel@gmail.com. The data also showed this person registered at the site using a Sprint mobile device with an Internet address that traced back to the Carolinas.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Denmark News Agency Refuses to Pay Hacker’s Ransom

Denmark News Agency Refuses to Pay Hacker’s Ransom

Denmark’s largest news agency has refused to pay a ransom to cyber-criminals who attacked its computer system with ransomware. 

Wire service Ritzau was knocked offline following an attack that occurred early last week. The incident infected roughly a quarter of the agency’s 100 servers with malware, causing editorial systems to be shut down.

Copenhagen-based Ritzau, which has been providing the Danish media, organizations, and companies with text and images since 1866, said it had been forced to transfer its emergency distribution to clients to six live blogs “which provide a better overview.”

CEO of Ritzau, Lars Vesterloekke, revealed that the agency had no clear idea of how much the attackers were demanding in return for the restoration of Ritzau’s encrypted files. Vesterloekke said that the agency had been instructed by its advisers not to open “a file with a message” left behind by whoever was responsible for the “professional attack.”

The news agency said that it was “hit by a serious hacker attack on Tuesday.” The attack’s instigators are yet to be identified.

An external computer forensics company has been hired by Ritzau to assist the company’s own IT department with recovering from the disruption caused by the attack. 

“Ritzau’s web service with distribution of news to media customers is now up and online again,” the news agency said in a statement published on its restored website. “The web service is in its first version without images and other associated formats.”

The news service said that it is still working toward a full technical recovery and added that its news app is not yet back up and running. 

“As soon as there is a known time horizon for when the news app will be up again, we will announce it,” said Ritzau.

“All resources are still being put into getting the systems back in operation, and we very much regret the inconvenience that the hacker attack has caused our customers due to lack of distribution and deliveries.”

Throughout its long history, the Danish news service has been quick to embrace new technology, including the telephone that came to Copenhagen in 1881, the cable remote printer that came to Denmark in the 1930s, and the internet, which took the country by storm in the late 1990s. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attack on Baltimore County Schools

Ransomware Attack on Baltimore County Schools

A ransomware attack orchestrated two days before Thanksgiving has forced the Baltimore County Public School System to be shut down.

Online classes for 115,000 students were disrupted as a result of what school officials are calling a “catastrophic attack on our technology system.”

While specific details of the attack have not yet been shared, The Baltimore Sun reports that the school board meeting video stream dropped out suddenly toward the end of Tuesday night. 

Teachers entering grades into the school system’s computer system said on social media that they began experiencing technical difficulties at around 11:30 pm Tuesday.

The district’s website, email system, and grading system have all been impacted by the incident. It is not yet clear whether any student data was exposed to unauthorized third parties.

School officials said on social media that files that were encrypted in the incident have a .ryuk extension, suggesting that Ryuk ransomware has been used by the attackers. This suggestion has not been confirmed by authorities or local officials. 

Officials kept their comments on the incident to a minimum, confirming that an attack took place, that an investigation has been launched into it, and that the school system is working with state and federal law enforcement and the Maryland Emergency Management Agency.

Baltimore County Police Chief Melissa Hyatt told the Baltimore Sun simply that “we are in the preliminary steps of that investigation.”

Schools in the county were closed for students today and will remain so tomorrow. However, school offices are being kept open to help staff find a way to keep teaching students whose education has already been fundamentally altered by the outbreak of COVID-19.

In a tweet, the school system said that keeping offices open will provide “much-needed time for our staff to continue working to set up the instructional platform and to communicate next steps regarding devices.”

Superintendent Darryl L. Williams was unable to confirm when online classes will be able to resume.

The incident follows a number of ransomware attacks on school systems in the United States, including a September attack on the Fairfax County Public School System in Virginia. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Data Stolen from America’s Largest Fertility Clinic Operator

Data Stolen from America’s Largest Fertility Clinic Operator

Data including Social Security numbers has been stolen from the largest fertility clinic operator in the United States in a cyber-attack. 

US Fertility runs 55 clinics at various locations in 10 of America’s 50 states. The company, established in May 2020, is the result of a partnership between private equity firm Amulet Capital Partners and Shady Grove Fertility

Cyber-criminals attacked US Fertility’s network with ransomware in September, impacting almost half of its locations. The company responded by taking a number of its servers and workstations offline, launching an investigation into the incident, and notifying federal law enforcement.

The company provided notice of the incident on November 25, stating: “On September 14, 2020, USF experienced an IT security event (the “Incident”) that involved the inaccessibility of certain computer systems on our network as a result of a malware infection. We responded to the Incident immediately and retained third-party computer forensic specialists to assist in our investigation.

“Through our immediate investigation and response, we determined that data on a number of servers and workstations connected to our domain had been encrypted by ransomware.”

Digital forensic specialists found that although the ransomware had been triggered on September 14, the attackers had first gained access to US Fertility’s network a month earlier, on August 12. 

During the weeks they spent inside the network, the attackers had access to files that contained patient data. Sensitive information accessed included names, addresses, dates of birth, MPI numbers, and Social Security numbers. 

US Fertility confirmed that the attackers acquired “a limited number of files” during the period of unauthorized access. 

“Please also note that we have no evidence of actual misuse of any individual’s information as a result of the Incident,” said the company. 

Following the attack, US Fertility fortified the security of its firewall and engaged digital forensic specialists to monitor network activity and remediate any suspicious activity.

“We take this incident very seriously and are committed to protecting the security and confidentiality of health information we gather in providing services to individuals,” said Mark Segal, chief executive officer of USF.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Delaware County Pays $500,000 Ransom After Outages

Delaware County Pays $500,000 Ransom After Outages

A US county is in the process of paying half-a-million dollars to ransomware extorters who locked its local government network, according to reports.

Pennsylvania’s Delaware County revealed the attack last week, claiming in a notice that it had disrupted “portions of its computer network.

“We commenced an immediate investigation that included taking certain systems offline and working with computer forensic specialists to determine the nature and scope of the event. We are working diligently to restore the functionality of our systems,” it said.

“The investigation is ongoing and we are working with computer forensic specialists to understand the full nature and scope of the event and confirm accurate information before sharing the details. County employees have been notified and provided with information and instructions.”

The county said its Bureau of Elections and Emergency Services Department were not affected, as they are served by separate networks.

However, the news comes as the authority, like much of the US, battles a surge in COVID-19 cases. Over the past four weeks it has seen a 131% increase in positive tests for the virus and a 156% increase in hospitalizations.

That will give attackers an extra incentive to attack public sector and healthcare organizations in the country over the coming months. However, it appears as if Delaware County’s decision to pay up was influenced by virtue of its insurance policy, which reportedly covers ransomware outages.

The largest cause of cyber insurance claims in North America in the first half of 2020 was ransomware, accounting for over two-fifths (41%), according to provider Coalition.

However, there are concerns that the growing take-up of such policies also emboldens cyber-criminals as it makes it more likely that victims will pay-up to regain access to networks quickly.

As long as victims keep paying, ransomware groups will keep launching attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Company Director Disqualified After Nuisance Calls

Company Director Disqualified After Nuisance Calls

The director of a marketing company that made tens of thousands of nuisance calls has been banned from running a business for six years.

Elia Bols was director of AMS Marketing Limited, a firm founded in 2016 which was the subject of scores of complaints between October that year and October 2017.

UK regulator the Information Commissioner’s Office handed Bols a fine of £100,000 after judging that, under his direction, the firm had made over 75,000 nuisance calls. It should first have used the Telephone Preference Service (TPS) list of individuals who choose not to receive unsolicited contact, the ICO said.

AMS Marketing was wound-up in 2019, with the fine still outstanding, and Bols now lives in Australia. However, in his absence, the government has ruled that AMS Marketing broke Regulation 21 of the Privacy and Electronic Communications Regulations (PECR).

As a result, he is now disqualified from acting as director or becoming directly or indirectly involved with running or promoting a company.

“Our work with the Insolvency Service has seen the successful disqualification of 17 directors who have shut their business down to try and avoid paying a fine for illegal marketing activity,” explained Andy Curry, head of investigations at the ICO.

“Nuisance calls, emails and texts can be a huge problem and often cause people real distress. By taking unscrupulous directors out of action, we can help protect the public and their privacy.”

However, despite these successes, the ICO has been found wanting in terms of its collection of outstanding fines from such offenders.

An FOI request last month revealed that £6.6m, or over 39% of total fines, are still outstanding. Just 13% of nuisance calls fines were collected, versus 54% of data breach penalties.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MasterChef Producer Hit by Double Extortion Ransomware

MasterChef Producer Hit by Double Extortion Ransomware

A multibillion-dollar TV production company has become the latest big corporate name caught out by ransomware, it emerged late last week.

French multinational firm Banijay SAS owns over 120 production firms around the world, delivering TV shows ranging from MasterChef and Big Brother to Black Mirror and The Island with Bear Grylls.

In a short update last Thursday, it claimed to be managing a “cyber-incident” affecting the networks of Endemol Shine Group and Endemol Shine International, Dutch firms it acquired in a $2.2bn deal in July.

Although ransomware isn’t named in the notice, previous reports suggest the firm is being extorted.

It admitted that data may have been taken, in what would be a classic “double extortion” attack.

“The business has reason to believe certain personal data of current and ex-employees may have been compromised, as well as commercially sensitive information,” it said.

“We are continuing to take the appropriate steps and remain committed to protecting our employees, past and present, so if we do identify any cases of data being taken or misused, we will contact the affected individuals directly.”

In the meantime, the firm said it is investigating the attack with “independent specialists” and has notified the relevant authorities in the Netherlands and the UK: the two countries affected by the incident.

Banijay would do well not to engage with the extortionists. A recent Coveware report warned that “paying a threat actor not to leak stolen data provides almost no benefit to the victim.”

The vendor claimed that several ransomware groups still publicly dox companies even after payment, while others may demand a second payment to remove any data they may have stolen.

Victim organizations should in any case assume that it has been or will be either sold to other threat actors or used in a future extortion attempt, Coveware claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk