News: 1713526126

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cybercriminals threaten to leak all 5 million records from stolen database of high-risk individuals

(2024/04/19)


The World-Check database used by businesses to verify the trustworthiness of users has fallen into the hands of cybercriminals.

The Register was contacted by a member of the GhostR group on Thursday, claiming responsibility for the theft. The authenticity of the claims was later verified by a spokesperson for the London Stock Exchange Group (LSEG), which maintains the database.

A spokesperson said the breach was genuine, but occurred at an unnamed third party, and work is underway to further protect data.

[1]

"This was not a security breach of LSEG/our systems," said an LSEG spokesperson. "The incident involves a third party's data set, which includes a copy of the World-Check data file.

[2]

[3]

"This was illegally obtained from the third party's system. We are liaising with the affected third party, to ensure our data is protected and ensuring that any appropriate authorities are notified."

The World-Check database aggregates information on undesirables such as terrorists, money launderers, dodgy politicians, and the like. It's used by companies during Know Your Customer (KYC) checks, especially by banks and other financial institutions to verify their clients are who they claim to be.

[4]

No bank wants to be associated with a known money launderer, after all.

World-Check is a subscription-only service that pulls together data from open sources such as official sanctions lists, regulatory enforcement lists, government sources, and trusted media publications.

We asked GhostR about its motivations over email, but it didn't respond to questioning. In the original message, the group said it would begin leaking the database soon. The first leak, so it claimed, will include details on thousands of individuals, including "royal family members."

[5]

The miscreants provided us with a 10,000-record sample of the stolen data for our perusal, and to verify their claims were genuine. The database allegedly contains more than five million records in total.

A quick scan of the sample revealed a slew of names from various countries, all on the list for different reasons. Political figures, judges, diplomats, suspected terrorists, money launderers, drug lords, websites, businesses – the list goes on.

Known cybercriminals also appear on the list, including those suspected of working for China's APT31, such as Zhao Guangzong and Ni Gaobin, who were [6]added to sanctions lists just weeks ago . A Cypriot spyware firm is also nestled in the small sample we received.

World-Check data includes full names, the category of person (such as being a member of organized crime or a political figure), in some cases their specific job role, dates and places of birth (where known), other known aliases, social security numbers, their gender, and a small explanation of why they appear on the list.

Long term readers will remember that a previous edition of the database was [7]leaked in 2016 back when World-Check was owned by Thomson Reuters. Back then, only 2.2 million records were included, so the current version implicates many more individuals, entities, and vessels.

A month later, the database was reportedly being [8]flogged online , with copies fetching $6,750 a pop.

Despite aggregating data from what are supposed to be reliable sources, being added to the World-Check list has been known in the past to affect innocent people. At the time of the first leak nearly eight years ago, investigations revealed inaccuracies in its data and a range of false terrorism designations.

Various Britons were found to have had their HSBC bank accounts closed in 2014 after they were allegedly added to the World-Check list in error.

[9]US charges Chinese nationals with cyber-spying on pretty much everyone for Beijing

[10]Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op

[11]World-Check terror suspect DB hits the web at just US$6750

[12]Global 'terror database' World-Check leaked

One of the affected parties was a mosque in London's Finsbury Park, which in the past was attended by known Al Qaeda members and affiliates of the Beslan Seige. Back in 1997, convicted terrorist Abu Hamza al-Masri was also the institution's imam.

However, per our 2016 reporting, the mosque was being run by a group supported by London's Metropolitan Police which, as an aside, [13]celebrated a big win in cyberspace this week .

Sources speaking to The Register at the time claimed HSBC also may have closed the mosque's account because of a donation made to an unspecified Palestinian org during its 2015 war with Israel. In 2021, the [14]mosque won a libel case against the news agency, which had to pay unspecified damages as its wrongful placement on the list caused banks to refuse to accept the mosque as a customer. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZiKVG-MR7sC2fuBLePHHSgAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZiKVG-MR7sC2fuBLePHHSgAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZiKVG-MR7sC2fuBLePHHSgAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZiKVG-MR7sC2fuBLePHHSgAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZiKVG-MR7sC2fuBLePHHSgAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/03/25/china_apt31_charges/

[7] https://www.theregister.com/2016/06/29/global_terror_database_worldcheck_leaked_online/

[8] https://www.theregister.com/2016/07/19/6750_buys_you_22_million_worldcheck_citizen_terror_records/

[9] https://www.theregister.com/2024/03/25/china_apt31_charges/

[10] https://www.theregister.com/2024/04/18/police_lab_host/

[11] https://www.theregister.com/2016/07/19/6750_buys_you_22_million_worldcheck_citizen_terror_records/

[12] https://www.theregister.com/2016/06/29/global_terror_database_worldcheck_leaked_online/

[13] https://www.theregister.com/2024/04/18/police_lab_host/

[14] https://www.bbc.com/news/uk-england-london-38824925

[15] https://whitepapers.theregister.com/



"work is underway to further protect data"

Pascal Monett

Then, when the next breach occurs, further work will "be underway".

Sometimes it would be so nice to be able to just stand those idiots in a line and slap all of them in one fell swoop.

I don't care that security is hard. You know that the database is critical. Get yourselves an $800 million dollar budget and secure the damn thing.

Re: "work is underway to further protect data"

Anonymous Coward

From my limited knowledge of this topic, there isn't really 'a database' to secure: this is not a central database that organisations consult to see if a potential customer is on a list, because no organisation wants to let someone else know who is coming through their doors.

Instead, subscribers regularly get a copy so they can use it to populate their own internal database that they consult. Because the schema is rather basic, I believe it is not much more complicated than a gigantic CSV, XML or JSON file, to make it easy for organisations to ingest no matter what technology they use.

So, not one copy to protect, lots. And no-one knows where all of them are.

But ...

Mike 137

As the list ostensibly consists of profiles of "bad people", the greatest societal threat would seem to be fabrication of records about innocent folks, rather than leaking of real records.

Re: But ...

KarMann

But it's not just 'bad people', it's also what are known as 'Politically Exposed Persons', including such as the judges mentioned. They, for example, aren't just judges on the take, but any judge who might be a target for bribery. And whilst many may have a lower opinion of politicians as a class, for the most part, they aren't the sort that should be barred from banking just for being a politician.

Re: But ...

KarMann

Thinking it through even a bit further, even a judge who hadn't been corrupted, might be made more vulnerable to corruption by the kind of info in this breach. So no, not good at all.

(This was to be an ETA, but I ran out of time to edit just as I was finishing typing it.)

GhostR contacted El Reg

Khaptain

Is there something we don't know about, like an El Reg insider that has a secondary past-time ?

You know....the sort of people who accept Fortnum & Masons bags stuffed with folding......

Anonymous Coward

....guess who? I wonder what the database details say?

Robert Grant

> Sources speaking to The Register at the time claimed HSBC also may have closed the mosque's account because of a donation made to an unspecified Palestinian org during its 2015 war with Israel. In 2021, the mosque won a libel case against the news agency, which had to pay unspecified damages as its wrongful placement on the list caused banks to refuse to accept the mosque as a customer.

For anyone else who couldn't follow who "the news agency" was, it's Thompson Reuters, mentioned way up higher in the article.

sitta_europea

"No bank wants to be associated with a known money launderer, after all."

Now if they're *unknown* money-launderers, well...

Are lists of dodgy criminals secret ?

JimmyPage

In the UK they're in the public domain. It's called "The Cabinet"

"Can you program?" "Well, I'm literate, if that's what you mean!"