Showing posts with label Anonymous target US security think tank Stratfor. Show all posts
Showing posts with label Anonymous target US security think tank Stratfor. Show all posts

Tuesday, February 28, 2012

WikiLeaks + Anonymous = A powerful partnership?

Though it's nothing new for WikiLeaks to publish information belonging to a private company, Monday's release of Stratfor e-mails might be an indication that for the first time, Anonymous and WikiLeaks have worked together. And that could have legal consequences for WikiLeaks' editor Julian Assange, experts say.

In December, Anonymous claimed it had hacked Stratfor, the Austin, Texas-based private company that produces intelligence reports for clients. On Monday, WikiLeaks began releasing 5 million e-mails it said belonged to Stratfor that reveal, WikiLeaks says, a litany of injustices by the company. WikiLeaks is calling the leak The Global Intelligence Files.

WikiLeaks has not said where it got the e-mails. Anonymous, an amorphous group of hackers worldwide,  is claiming on Twitter and on other social media that they gave it to the site. Numerous media outlets such as the Washington Post and Wired are reporting the partnership.

"Their [WikiLeaks and Anonymous] working together made sense. Anonymous did the hack, had the stuff and in the end decided that someone else would be better-suited to comb through this and release it," said Gregg Housh, who acts as a spokesperson for Anonymous. "Anonymous just didn't have the ability to go through all the e-mails themselves. This was a happy partnership. WikiLeaks did such an awesome job categorizing the [State Department] cables."

WikiLeaks became megawatt famous in 2010 with the Iraq and Afghanistan war leaks, and then followed up by leaking nearly a quarter million State Department cables. Meanwhile, Anonymous was making its first international headlines by disabling the Web sites of MasterCard, PayPal and Visa when the corporations stopped doing business with WikiLeaks. With intense attention on WikiLeaks and Assange's subsequent legal woes, it seemed that Anonymous might take over if WikiLeaks couldn't survive. Assange last year said that he had nothing to do with the site disabling of the companies.

Housh is a web developer in Boston and says that he observes Anonymous' IRC chat portal and communicates with anons but he doesn't participate in any hacks. Through Housh, CNN has requested phone interviews with anons, people who associate themselves with Anonymous. On Monday those requests were rebuffed –  although across the Web, anons claimed credit for the Stratfor hack. The hackers behind the Stratfor hack may be part of an Anonymous sect called "Anti-Sec," which Wired reports is known for hacking into servers.

Stratfor confirmed Monday that company e-mails had been stolen, but said in a statement that some of the messages may have been altered.

Because the Global Intelligence Files are allegedly stolen from a private company, WikiLeaks could likely be held liable for that theft, said Hemu Nigam who has worked for two decades in computer security.

"There's a huge difference between publishing information and publishing information you know to be stolen," said Nigam, who has collaborated with the U.S. Secret Service, Interpol and the FBI to implement a hacker identification program for Microsoft. He now runs SSP Blue, an advisory firm that tells major corporations how to protect against hackers and insiders looking to leak. "There are a host of criminal statues that I have no doubt Stratfor's attorneys are going over thinking about how best to sue WikiLeaks. Information that is privately owned is not the same as information that is public, that essentially belongs to the public."

Hemu says that it appears to him that the 5 million e-mails were taken by a hacker who penetrated an unprotected server and copied the entire server. "Any company that's keeping valuable or confidential information has to take a multilayered approach to Internet security," Nigam said. "There are so many ways to access a system, and a company has to stay several steps ahead of all of them."

The Stratfor leak isn't the first time that WikiLeaks has published information from a private company, said Rebecca Jeschke of the Electronic Frontier Foundation, which defends free speech and online privacy. In 2008, Swiss bank Julius Baer filed suit in federal district court in California against WikiLeaks for hosting 14 allegedly leaked documents regarding personal banking transactions of bank customers. According to Jeschke, Baer ultimately moved to dismiss the case.

Source: CNN

'Anonymous' hackers hits STRATFOR security group

Hacker group Anonymous began its promised week of Christmas hacks, assaulting a long list of targets. The first Anonymous hack resulted in stolen emails and credit card data from Stratfor, an Austin-based think tank that concentrates on security issues.
A Twitter account associated with "Anonymous" celebrated the Christmas-Day hacking of security group Stratfor.


One alleged conspirator said the goal was to use that credit card data to steal a million dollars, and give the money away as Christmas donations, the AP reports. Online images, posted to Twitter, show receipts from the donations.

Twitter account @YourAnonNews, which is supposedly linked to the group, tweeted Sunday that the reason it was able to steal the credit card data was because it had not been encrypted by Stratfor -- an embarrassing mistake for a company specializing in security.
Among the private clients on Stratfor's tightly-guarded list -- whose information Anonymous says it accessed -- are the U.S. Army, the U.S. Air Force and the Miami Police Department. The list also includes banks, law enforcement agencies, defense contractors, and technology firms such as Apple and Microsoft, the AP reports.

'Anonymous' hackers attack intel company
Anonymous also posted images showing receipts of charitable donations made to non-profits. One theft victim, Alan Barr of Austin, did not know his credit card data had been stolen until an AP reporter called him for comment.

"It was all charities, the Red Cross, CARE, Save the Children. So when the credit card company called my wife she wasn't sure whether I was just donating," Barr said.

@YourAnonNews tweeted that Justin Bieber, Lady Gaga, Kim Kardashian and Taylor Swift were among the next targets.

What do you think of Anonymous's ironic first target of the week?
Who's next?

UPDATE: A press release is circulating, saying that the Stratfor hack is not the work of Anonymous. However, it is difficult to tell who is correct.

Source: Mashable

Thursday, December 29, 2011

#Anonymous target US security think tank “Thank you! Defense Intelligence Agency”

The loose-knit hacking movement “Anonymous” claimed Sunday to have stolen thousands of credit card numbers and other personal information belonging to clients of U.S.-based security think tank Stratfor. One hacker said the goal was to pilfer funds from individuals’ accounts to give away as Christmas donations, and some victims confirmed unauthorized transactions linked to their credit cards.

Anonymous boasted of stealing Stratfor’s confidential client list, which includes entities ranging from Apple Inc. to the U.S. Air Force to the Miami Police Department, and mining it for more than 4,000 credit card numbers, passwords and home addresses.

undefined“Not so private and secret anymore?” Anonymous taunted in a message on Twitter, promising that the attack on Stratfor was just the beginning of a Christmas-inspired assault on a long list of targets.
Anonymous said the client list it had already posted was a small slice of the 200 gigabytes worth of plunder it stole from Stratfor and promised more leaks. It said it was able to get the credit card details in part because Stratfor didn’t bother encrypting them — an easy-to-avoid blunder which, if true, would be a major embarrassment for any security-related company.

Fred Burton, Stratfor’s vice president of intelligence, said the company had reported the intrusion to law enforcement and was working with them on the investigation.

Stratfor has protections in place meant to prevent such attacks, he said.

“But I think the hackers live in this kind of world where once they fixate on you or try to attack you it’s extraordinarily difficult to defend against,” Burton said.

Hours after publishing what it claimed was Stratfor’s client list, Anonymous tweeted a link to encrypted files online with names, phone numbers, emails, addresses and credit card account details.

“Not as many as you expected? Worry not, fellow pirates and robin hoods. These are just the ‘A’s,” read a message posted online that encouraged readers to download a file of the hacked information.

The attack is “just another in a massive string of breaches we’ve seen this year and in years past,” said Josh Shaul, chief technology officer of Application Security Inc., a New York-based provider of database security software.

Still, companies that shared secret information with Stratfor in order to obtain threat assessments might worry that the information is among the 200 gigabytes of data that Anonymous claims to have stolen, he said.

“If an attacker is walking away with that much email, there might be some very juicy bits of information that they have,” Shaul said.

Lt. Col. John Dorrian, public affairs officer for the Air Force, said that “for obvious reasons” the Air Force doesn’t discuss specific vulnerabilities, threats or responses to them.

“The Air Force will continue to monitor the situation and, as always, take appropriate action as necessary to protect Air Force networks and information,” he said in an email.

Miami Police Department spokesman Sgt. Freddie Cruz Jr. said that he could not confirm that the agency was a client of Stratfor, and he said he had not received any information about a security breach involving the police department.

Anonymous also linked to images online that it suggested were receipts for charitable donations made by the group manipulating the credit card data it stole.

“Thank you! Defense Intelligence Agency,” read the text above one image that appeared to show a transaction summary indicating that an agency employee’s information was used to donate $250 to a nonprofit.

One receipt — to the American Red Cross — had Allen Barr’s name on it.

Barr, of Austin, Texas, recently retired from the Texas Department of Banking and said he discovered last Friday that a total of $700 had been spent from his account. Barr, who has spent more than a decade dealing with cybercrime at banks, said five transactions were made in total.

“It was all charities, the Red Cross, CARE, Save the Children. So when the credit card company called my wife she wasn’t sure whether I was just donating,” said Barr, who wasn’t aware until a reporter with the AP called that his information had been compromised when Stratfor’s computers were hacked.

“It made me feel terrible. It made my wife feel terrible. We had to close the account.”

Wishing everyone a “Merry LulzXMas” — a nod to its spinoff hacking group Lulz Security — Anonymous also posted a link on Twitter to a site containing the email, phone number and credit number of a U.S. Homeland Security employee.

The employee, Cody Sultenfuss, said he had no warning before his details were posted.

“They took money I did not have,” he told The Associated Press in a series of emails, which did not specify the amount taken. “I think ‘Why me?’ I am not rich.”

But the breach doesn’t necessarily pose a risk to owners of the credit cards. A card user who suspects fraudulent activity on his or her card can contact the credit card company to dispute the charge.

Stratfor said in an email to members, signed by Stratfor Chief Executive George Friedman and passed on to AP by subscribers, that it had hired a “leading identity theft protection and monitoring service” on behalf of the Stratfor members affected by the attack. The company said it will send another email on services for affected members by Wednesday.

Stratfor acknowledged that an “unauthorized party” had revealed personal information and credit card data of some of its members.

The company had sent another email to subscribers earlier in the day saying it had suspended its servers and email after learning that its website had been hacked.

One member of the hacking group, who uses the handle AnonymousAbu on Twitter, claimed that more than 90,000 credit cards from law enforcement, the intelligence community and journalists — “corporate/exec accounts of people like Fox” News — had been hacked and used to “steal a million dollars” and make donations.


Source: AnonOps