|
Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Amberleigh Jack. This week's edition is sponsored by Authentik. You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.
Listen here Last week, Krebs On Security broke the story of a newly launched dark web service calling itself Nexus that was selling access to identity documents, including 153 million drivers licences from US and Canadian citizens. This is a huge breach that will not only be used for run-of-the-mill cybercrime, but will also feed the intelligence machines of America's adversaries. Nexus claimed, in a cybercrime forum post, that it had access to a major identity verification company and had spent more than a year "continuously" exfiltrating new data into a private database. Krebs On Security noted in a single day the number of licences in the database increased by nearly 400,000, suggesting regular ingestion of new data. Krebs On Security was able to verify that the drivers licences held by the service were genuine. In addition to his own, it contained licences from nine of his friends and family members. Secretary of War Pete Hegseth, an assistant director at the FBI and other high-ranking US government officials also had licences in the mix. Based on a variety of circumstantial evidence, Krebs linked the incident to identity verification service IDScan. The service's website says it helps to reduce fraud by confirming that an ID is authentic and being presented by its legitimate owner and by detecting fraudulent documents. The FBI is looking into the incident and IDScan has confirmed it is investigating a data breach. The Nexus service also disappeared from the dark web shortly after Krebs published his story, although the people responsible do not claim to have deleted the data. Presumably they are laying low till the publicity dies down. Licences and identity documents can be used to facilitate identity theft and phishing attacks, but because the data can be used to inform intelligence operations, an incident like this also has national security implications. For the intelligence world licences are particularly valuable because they're key identity documents and licence numbers are often used in other databases. These databases, whether hacked or purchased, become much more valuable when records can be linked directly to a particular person with home address and photo included. And it's not a theoretical threat. In the mid-2010s, Chinese cyber espionage actors stole complementary data from a variety of sources that, together, would be useful for analysing the US intelligence apparatus. Various Chinese APT groups stole information from the health insurance company Anthem, credit reporting company Equifax, Marriott hotels, United Airlines and, perhaps most significantly, security clearance information from the Office of Personnel Management. The US intelligence community is certain that stolen data was used to counter American intelligence efforts against China, as described in this series of Foreign Policy articles by Zach Dorfman. Of course, China itself isn't known for releasing detailed reports describing how it exploits its stolen data, but investigative research outfit Bellingcat has shown exactly how similar data can be used to uncover covert government activity. In 2022 a hacked database provided a key piece of travel information that helped Bellingcat identify a deep cover GRU agent (Russian military intelligence) trying to infiltrate a NATO command post in Naples, Italy. And in another striking example these three Bellingcat reports from 2018 identified suspects in the attempted assasination of Sergei Skripal with the Novichok nerve agent. Clearly, leaked and hacked databases are incredibly useful for Bellingcat's Russia-related investigations. In 2020 it said it had "acquired dozens of leaked databases over the past few years, giving us a large number of data points to cross-reference and verify any new data we acquire". If a small investigative outfit is hoovering up Russian data when it is leaked, you can bet your bottom yuan that China's intelligence services are doing the same for any American data that pops up. The IDScan breach is big. The number of US licences in the database is roughly 63 percent of the country's total licences. But breaches from identity verification companies occur depressingly frequently. In the last two years breaches have occurred at AU10TIX, Discord's age verification service provider 5CA, and at National Public Data. Identity verification services are necessary to help to prevent fraud, but are also a point of vulnerability when security is poorly done. The sheer volume of sensitive data these services handle means that they should be subject to strict regulation and oversight. We're realists here at Seriously Risky Business, though, and recognise that there is no chance of swift government action. In the short term, we can only hope that significant financial consequences will help encourage these firms to shore up their security. Law firms are already lining up class action suits against IDScan, but a little federal government attention from the FTC wouldn't go astray either. The US Military's Ad Tracking Fig LeafBack in June Reuters reported that commercial location data was being used to target US military personnel in the Middle East. At the time we wrote that the Department of Defence's (DoD) existing policies regarding the issue, which already included disabling advertising identifiers on military-owned devices, did "not fill us with confidence". They simply weren't comprehensive enough. It turns out that these policies weren't even being well implemented. This week, Reuters reported that some branches of the US military have finally gotten around to disabling some advertising identifiers on military-owned devices. The Air Force said it disabled Windows and Android advertising identifiers in late July, although they were already disabled on Apple devices. The Army told Reuters it disabled advertising identifiers on Android and Apple devices by default in February. And US Special Operations Command said that identifiers on Windows computers were "recently" disabled. Turning off these advertising identifiers is a fundamental mitigation that should have been implemented years ago. The US military was first briefed in 2016 about the potential for commercial location data to be used to track its people to sensitive locations. In a striking 2018 example, an Australian twitter user pointed out that Strava's global heat map could be used to identify US military bases and even servicepeople's jogging routes. Disabling advertising identifiers on military devices is also an incomplete solution. It makes it harder to track them, but not impossible. And as it happens, many US service people also use personal devices. Having a locked down work phone is step one, but having good policies for personal devices is equally important. Disabling advertising identifiers by default is the simplest short-term measure that might improve OPSEC, but it is impossible to know if it will make much of a difference without assessing the US military's OPSEC posture holistically. Does disabling advertising identifiers on government devices reduce risk to an acceptable level? Probably not. It's good that the US military is finally disabling advertising identifiers by default. But we’re concerned the military has no idea how effective it will be. "White Hats" Are Kidding ThemselvesOver the weekend self-proclaimed white-hat hackers stole USD$320 million worth of Bitcoin stolen from the Liquid Network cryptocurrency platform. By Wednesday the hackers had returned 85% of the funds, but kept around $47 million. In recent years there has been a regular drumbeat of steal-first-claim-reward-later hacks. We begrudgingly categorise several of these as successes as the perpetrators have not (yet) been arrested or jailed. In 2021 a hacker stole USD$610 million worth of cryptocurrency from Poly Network. This was eventually returned in full, minus the company's offer of $500,000 for the attacker it referred to as Mr White Hat. Hacks of Multichain (2022), Huobi (2023) and Tender.fi (2023) had similar outcomes: millions were stolen and returned, with the hackers taking a cut of tens or hundreds of thousands in cryptocurrency as a "reward" or "bug bounty". The standout example is the 2022 hack of Mango Markets, in which a hacker extracted $USD110 million from the decentralised exchange. The individual responsible, Avraham Eisenberg, described his actions at the time as a "highly profitable trading strategy". He claimed all his actions were legal and he used the protocol as designed, "even if the development team did not fully anticipate all the consequences of setting parameters the way they are". Eisenberg returned $67 million to Mango Markets to recapitalise it, and the Mango community voted to give him a cool $47 million for his time. Eisenberg was convicted of fraud in a 2024 jury trial, but those convictions were overturned by a US judge last year. In our view, the perpetrators of these hacks are deceiving themselves. By returning most of the money, they're deluding themselves into thinking they're acting responsibly. As for consequences, the law won't chase me down if I return the majority and the victim says it's fine… right? In Eisenberg's case, it did turn out to be right. But the FBI has been clear that victims cannot guarantee that perpetrators will not be prosecuted. One wrinkle in the Liquid Network case is, as far as we can tell, the company never agreed to allow the hacker to keep a 15% cut. It feels possible that this self-proclaimed good guy might have to spend some of that $47 million on a good lawyer. Watch James Wilson and Tom Uren discuss this edition of the newsletter: |