[HN Gopher] The Ukrainian police arrested a man for selling data...
       ___________________________________________________________________
        
       The Ukrainian police arrested a man for selling data of over 300M
       people
        
       Author : jruohonen
       Score  : 65 points
       Date   : 2023-04-28 14:30 UTC (8 hours ago)
        
 (HTM) web link (securityaffairs.com)
 (TXT) w3m dump (securityaffairs.com)
        
       | 0xDEF wrote:
       | >The man was an administrator of closed groups and channels in
       | the Telegram messenger, where he sold personal data of citizens
       | of Ukraine and the European Union.
       | 
       | >Depending on the amount of data offered for sale, the man
       | demanded from 500 to 2000 dollars.
       | 
       | Sounds like a small fish who downloads known leaks from the
       | darknet and sells it on Telegram.
        
       | birdyrooster wrote:
       | [flagged]
        
         | macintux wrote:
         | Since your profile says "Please help me to understand!" I'll
         | take a swing:
         | 
         | You're being downvoted because HN prefers a more substantive
         | discussion on topics than your comment. Security, privacy,
         | currency controls...there are any number of interesting points
         | in this story. A "jank" network setup isn't one of them.
         | 
         | Probably more importantly the tone is very Reddit-esque.
        
         | scandox wrote:
         | I suspect you're being downvoted for being somewhat off topic.
         | Also for commenting on downvotes which is also frowned upon.
        
       | jruohonen wrote:
       | Among the interesting speculations is how he got access to such
       | data and which countries were affected.
       | 
       | "The man had information on passport data, taxpayer numbers,
       | birth certificates, driver's licenses, and bank account data."
       | 
       | I suppose this must imply that quite a few governmental services
       | have been breached (or, alternatively, a single big one).
        
         | risyachka wrote:
         | You'd be surprised how many websites (medical, financial etc)
         | are leaking data. e.g. in many all you need is just to replace
         | your profile id with (id+1) and get other user's data.
         | 
         | Especially if website owner is located in non-EU or western
         | countries there is basically zero responsibility for this, so
         | no one even bothers to hire a dev that understands these basic
         | security things. The cheaper the better.
         | 
         | I've seen dozens of examples myself without even trying.
         | Imagine what you can get if you spend more than 20 minutes on
         | this.
        
           | jruohonen wrote:
           | Sure. Throughout the world, especially hospitals and
           | healthcare seem to be particularly bad at infosec. But
           | regarding this case, I think something like passport data is
           | (or should be) fairly well-protected, which prompts further
           | questions about the hypothetical breaches. Of course, it
           | could as well be an insider case or something similar.
           | 
           | Another point is that Telegram was again involved.
        
         | rep_lodsb wrote:
         | "Art. 362 (Unauthorized actions with information that is
         | processed in computers, automated systems, computer networks or
         | stored on carriers of such information, _committed by a person
         | who has the right to access it_ )"
         | 
         | If that is an accurate translation, seems like he worked for
         | the government.
        
       | andersentobias wrote:
       | > The Ukraine cyber police revealed that the stolen data were
       | also bought by Russian citizens who paid using currencies
       | prohibited in the Ukrainian territory.
       | 
       | What currencies are referred to here?
        
         | notpeter wrote:
         | Likely Rubles. "The issuing and circulation in Ukraine of
         | currencies other than the hryvnia are expressly prohibited by
         | Ukrainian law."
         | 
         | https://bank.gov.ua/en/news/all/zaprovadjennya-obigu-rosiysk...
        
       | mxuribe wrote:
       | Is it me or does Netishyn (the city where the guy was caught, and
       | presumably lived) seem eerily similar to the term "netizen"?
       | ...Or, am I thinking/seeing things on a Friday that are not
       | really there/linked? :-)
        
       | AzzieElbab wrote:
       | I haven't visited Ukraine or Russia in 10 years, but back then,
       | you could buy USBs with all kinds of data at flea markets. Moscow
       | would mostly have passport data, including international
       | travelers. Odesa had addresses, job history, and so on.
        
         | kspacewalk2 wrote:
         | This has been used countless times by OSINT investigators to
         | out Russia's covert activities, such as Novichok poisonings of
         | Navalny and Skripal, identifying most operatives by cross-
         | referencing e.g. flight record, passport, property and even
         | taxi databases sold in Russia, sometimes overtly and sometimes
         | covertly.
        
           | pphysch wrote:
           | Calling it "OSINT" is a stretch when it is state funding and
           | collaboration that enables the firm you are referencing
           | (according to Paul Mason).
        
           | jruohonen wrote:
           | But note that 300M is far beyond the population of Russia.
        
             | kspacewalk2 wrote:
             | Yeah, this guy's stash may or may not include any Russian
             | data. What I'm saying is that it's a common problem in
             | eastern Europe, in democratic countries and authoritarian
             | hellholes alike. Just because the Russian state can
             | arbitrarily imprison you forever without any valid reason
             | does not make it capable enough as an organization to
             | securely store even data that can be used to badly hurt its
             | interests.
             | 
             | The Ukrainian state has been "digitizing" by leaps and
             | bounds even before the war, and now it's accelerated
             | further. Everything's moving "to the cloud". They seem to
             | be relatively competent these days, past lessons learned
             | perhaps. But the breakneck pace of moving everything online
             | (far outpacing most western European countries) will surely
             | result in breaches, it's just common sense.
        
               | jruohonen wrote:
               | Yet some say Ukraine has been quite successful precisely
               | because of their cloud strategy. Opinions vary, of
               | course.
               | 
               | The original announcement (via a DeepL translation)
               | indicates that also data of EU citizens was involved, so
               | maybe you are on the right track [1].
               | 
               | [1] https://cyberpolice.gov.ua/news/kiberpolicziya-
               | vykryla-zlovm...
        
           | PicassoCTs wrote:
           | Wasn't there a gay couple of assassins, touring Europs famous
           | churches, poisoning people?
        
           | Arrath wrote:
           | Bill Browder's Red Notice[0] described using 'street sourced'
           | data like this as their team dug into the illegal shenanigans
           | being done against their company.
           | 
           | [0]https://www.goodreads.com/book/show/22609522-red-notice
        
         | charlieyu1 wrote:
         | Pretty interesting to have leaked data available in flea
         | markets. In Hong Kong only government agencies would have
         | access to leaked data
        
           | AzzieElbab wrote:
           | Well, it is the law enforcement ppl who sell that data.
           | Sometimes personally
        
           | mistrial9 wrote:
           | pretty funny that I recall walking in the "pirate shop" area
           | in Hong Kong, and finding multi-thousand pirate copies of
           | American shrinkwrap software, including perfect cover art and
           | sometimes tiny manuals.
        
             | charlieyu1 wrote:
             | late 90s and early 00s? Those were better times...
        
               | contingencies wrote:
               | I recall Mongkok, 1998. MP3 CDs. Haha.
        
         | moltar wrote:
         | Not only flea markets. The problem was so ubiquitous that
         | sellers would walk in traffic and sell CDs with data to
         | drivers.
        
       | rambojohnson wrote:
       | ok
        
       ___________________________________________________________________
       (page generated 2023-04-28 23:02 UTC)