[HN Gopher] The Ukrainian police arrested a man for selling data...
___________________________________________________________________
The Ukrainian police arrested a man for selling data of over 300M
people
Author : jruohonen
Score : 65 points
Date : 2023-04-28 14:30 UTC (8 hours ago)
(HTM) web link (securityaffairs.com)
(TXT) w3m dump (securityaffairs.com)
| 0xDEF wrote:
| >The man was an administrator of closed groups and channels in
| the Telegram messenger, where he sold personal data of citizens
| of Ukraine and the European Union.
|
| >Depending on the amount of data offered for sale, the man
| demanded from 500 to 2000 dollars.
|
| Sounds like a small fish who downloads known leaks from the
| darknet and sells it on Telegram.
| birdyrooster wrote:
| [flagged]
| macintux wrote:
| Since your profile says "Please help me to understand!" I'll
| take a swing:
|
| You're being downvoted because HN prefers a more substantive
| discussion on topics than your comment. Security, privacy,
| currency controls...there are any number of interesting points
| in this story. A "jank" network setup isn't one of them.
|
| Probably more importantly the tone is very Reddit-esque.
| scandox wrote:
| I suspect you're being downvoted for being somewhat off topic.
| Also for commenting on downvotes which is also frowned upon.
| jruohonen wrote:
| Among the interesting speculations is how he got access to such
| data and which countries were affected.
|
| "The man had information on passport data, taxpayer numbers,
| birth certificates, driver's licenses, and bank account data."
|
| I suppose this must imply that quite a few governmental services
| have been breached (or, alternatively, a single big one).
| risyachka wrote:
| You'd be surprised how many websites (medical, financial etc)
| are leaking data. e.g. in many all you need is just to replace
| your profile id with (id+1) and get other user's data.
|
| Especially if website owner is located in non-EU or western
| countries there is basically zero responsibility for this, so
| no one even bothers to hire a dev that understands these basic
| security things. The cheaper the better.
|
| I've seen dozens of examples myself without even trying.
| Imagine what you can get if you spend more than 20 minutes on
| this.
| jruohonen wrote:
| Sure. Throughout the world, especially hospitals and
| healthcare seem to be particularly bad at infosec. But
| regarding this case, I think something like passport data is
| (or should be) fairly well-protected, which prompts further
| questions about the hypothetical breaches. Of course, it
| could as well be an insider case or something similar.
|
| Another point is that Telegram was again involved.
| rep_lodsb wrote:
| "Art. 362 (Unauthorized actions with information that is
| processed in computers, automated systems, computer networks or
| stored on carriers of such information, _committed by a person
| who has the right to access it_ )"
|
| If that is an accurate translation, seems like he worked for
| the government.
| andersentobias wrote:
| > The Ukraine cyber police revealed that the stolen data were
| also bought by Russian citizens who paid using currencies
| prohibited in the Ukrainian territory.
|
| What currencies are referred to here?
| notpeter wrote:
| Likely Rubles. "The issuing and circulation in Ukraine of
| currencies other than the hryvnia are expressly prohibited by
| Ukrainian law."
|
| https://bank.gov.ua/en/news/all/zaprovadjennya-obigu-rosiysk...
| mxuribe wrote:
| Is it me or does Netishyn (the city where the guy was caught, and
| presumably lived) seem eerily similar to the term "netizen"?
| ...Or, am I thinking/seeing things on a Friday that are not
| really there/linked? :-)
| AzzieElbab wrote:
| I haven't visited Ukraine or Russia in 10 years, but back then,
| you could buy USBs with all kinds of data at flea markets. Moscow
| would mostly have passport data, including international
| travelers. Odesa had addresses, job history, and so on.
| kspacewalk2 wrote:
| This has been used countless times by OSINT investigators to
| out Russia's covert activities, such as Novichok poisonings of
| Navalny and Skripal, identifying most operatives by cross-
| referencing e.g. flight record, passport, property and even
| taxi databases sold in Russia, sometimes overtly and sometimes
| covertly.
| pphysch wrote:
| Calling it "OSINT" is a stretch when it is state funding and
| collaboration that enables the firm you are referencing
| (according to Paul Mason).
| jruohonen wrote:
| But note that 300M is far beyond the population of Russia.
| kspacewalk2 wrote:
| Yeah, this guy's stash may or may not include any Russian
| data. What I'm saying is that it's a common problem in
| eastern Europe, in democratic countries and authoritarian
| hellholes alike. Just because the Russian state can
| arbitrarily imprison you forever without any valid reason
| does not make it capable enough as an organization to
| securely store even data that can be used to badly hurt its
| interests.
|
| The Ukrainian state has been "digitizing" by leaps and
| bounds even before the war, and now it's accelerated
| further. Everything's moving "to the cloud". They seem to
| be relatively competent these days, past lessons learned
| perhaps. But the breakneck pace of moving everything online
| (far outpacing most western European countries) will surely
| result in breaches, it's just common sense.
| jruohonen wrote:
| Yet some say Ukraine has been quite successful precisely
| because of their cloud strategy. Opinions vary, of
| course.
|
| The original announcement (via a DeepL translation)
| indicates that also data of EU citizens was involved, so
| maybe you are on the right track [1].
|
| [1] https://cyberpolice.gov.ua/news/kiberpolicziya-
| vykryla-zlovm...
| PicassoCTs wrote:
| Wasn't there a gay couple of assassins, touring Europs famous
| churches, poisoning people?
| Arrath wrote:
| Bill Browder's Red Notice[0] described using 'street sourced'
| data like this as their team dug into the illegal shenanigans
| being done against their company.
|
| [0]https://www.goodreads.com/book/show/22609522-red-notice
| charlieyu1 wrote:
| Pretty interesting to have leaked data available in flea
| markets. In Hong Kong only government agencies would have
| access to leaked data
| AzzieElbab wrote:
| Well, it is the law enforcement ppl who sell that data.
| Sometimes personally
| mistrial9 wrote:
| pretty funny that I recall walking in the "pirate shop" area
| in Hong Kong, and finding multi-thousand pirate copies of
| American shrinkwrap software, including perfect cover art and
| sometimes tiny manuals.
| charlieyu1 wrote:
| late 90s and early 00s? Those were better times...
| contingencies wrote:
| I recall Mongkok, 1998. MP3 CDs. Haha.
| moltar wrote:
| Not only flea markets. The problem was so ubiquitous that
| sellers would walk in traffic and sell CDs with data to
| drivers.
| rambojohnson wrote:
| ok
___________________________________________________________________
(page generated 2023-04-28 23:02 UTC)