News: 1715812213

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Crook brags about US Army and $75b defense biz pwnage

(2024/05/16)


An extortionist claims to have stolen files from the US Army Aviation and Missile Command in August 2023, and now claims they are selling access to a $75 billion aerospace and defense company.

US Army Aviation and Missile Command (AMCOM) develops and maintains the Army's aviation, missile and drone capabilities

According to the criminal(s), who has been especially active lately and goes by the moniker IntelBroker — and it's important to keep in mind that crims aren't necessarily the most trustworthy folks — the AMCOM data dump includes maintenance tasks, PDFs, png files and some .txt files.

[1]

A spokesperson for the US Army didn't immediately respond to The Register 's inquiries.

[2]

[3]

Hackmanac, an infosec firm that scours the dark web, spotted IntelBroker's alleged AMCOM leak. But [4]added : "The confirmation or denial of these claims has yet to be verified."

Shortly afterwards the same individual or crew put up for sale what it alleges is data stolen from a $75 billion US aerospace and defense contractor. The compromised data, according to the leak site, includes a ton of code, including source software, swiped from the defense company's CI/CD pipeline, Bitbucket, Github and Apache SVN repositories.

[5]

The listing, spotted and [6]shared via social media by Dark Web Informer, went up on Wednesday, with IntelBroker asking would-be buyers to "Message me offers. XMR only."

[7]Europol confirms incident following alleged auction of staff data

[8]Feds probe alleged classified US govt data theft and leak

[9]Home Depot confirms worker data leak after miscreant dumps info online

[10]Cybersec chiefs team up with insurers to say 'no' to ransomware bullies

This particular miscreant has been especially active in recent months targeting law enforcement and government agencies.

On Monday, Europol [11]confirmed that it is investigating IntelBroker's claims about stealing confidential data from the Europol Platform for Experts user group.

"No core systems of Europol are affected and therefore, no operational data from Europol has been compromised," a spokesperson told The Register .

The crook also [12]bragged about stealing data belonging to the Pentagon and other national security agencies last month.

[13]

Also in April, Home Depot [14]confirmed that one of its third-party vendors accidentally exposed some of its employees' personal details after IntelBroker purportedly shared the info on BreachForums, a site currently taken down by the Feds.

At the time, the thief claimed to have posted a Home Depot database containing corporate information belonging to 10,000 employees from an April attack. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZkWE4PRDlZcGfHvZCoucaAAAAAc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkWE4PRDlZcGfHvZCoucaAAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkWE4PRDlZcGfHvZCoucaAAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://twitter.com/H4ckManac/status/1790618838876250584

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkWE4PRDlZcGfHvZCoucaAAAAAc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://twitter.com/DarkWebInformer/status/1790736072504479933

[7] https://www.theregister.com/2024/05/13/europol_data_breach/

[8] https://www.theregister.com/2024/04/04/feds_data_dump/

[9] https://www.theregister.com/2024/04/08/home_depot_data_theft/

[10] https://www.theregister.com/2024/05/14/uk_ncsc_partners_with_insurance/

[11] https://www.theregister.com/2024/05/13/europol_data_breach/

[12] https://www.theregister.com/2024/04/04/feds_data_dump/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkWE4PRDlZcGfHvZCoucaAAAAAc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2024/04/08/home_depot_data_theft/

[15] https://whitepapers.theregister.com/



Why not Facebook?

Yorick Hunt

"... swiped from the defense company's CI/CD pipeline, Bitbucket, Github and Apache SVN repositories."

Politicians using Hotmail for official mail, military contractors using public services for ostensibly "top secret" material, where does it end?

They may as well have created a Facebook group and dumped all of their most valuable digital assets there.

If you want your program to be readable, consider supplying the argument.
-- Larry Wall in the perl man page