US spy agency hacked, claims no secrets leaked

Cybersecurity Breaches and Criminal Activities Highlight Ongoing Threats

A recent cybersecurity incident involving the U.S. spy satellite agency has raised concerns about data security, even though officials claim no classified information was compromised. The National Reconnaissance Office (NRO) confirmed that attackers gained limited access to its networks, but emphasized that no sensitive data was exposed. The breach involved the unclassified Acquisition Research Center (ARC) website, which serves as a portal for vendors to submit proposals and bid on contracts.

The NRO stated that it is working with federal law enforcement to investigate the incident but declined to comment on whether the attack was linked to the SharePoint vulnerability used in other government breaches. This lack of clarity has left many wondering about the full extent of the breach and the potential risks involved.

The ARC is not connected to classified networks, so contract details should remain secure. However, reports suggest that attackers may have accessed sensitive information related to the CIA’s technology acquisition efforts, including data tied to the Digital Hammer program. This initiative aims to fast-track innovative tools for surveillance and intelligence gathering. Despite these concerns, the CIA has remained silent on the matter, and the NRO has reportedly notified affected companies.

Data Breach in Dating App Exposes User Information

A popular dating app called Tea has suffered a major data breach, exposing 72,000 images, including 13,000 selfies and photo IDs, as well as 59,000 pictures from app posts and direct messages. The app, which allows users to share notes on specific men and comment on their dating experiences, had over 1.6 million users at the time of the breach.

Tea includes a feature called the Catfish Finder AI tool, which uses reverse image searches and public records to help flag suspicious identities. However, the breach revealed that user data was stored in an unsecured Firebase storage bucket, leading to the exposure of personal information. The app developers have since launched an investigation into the incident and claimed that the data was collected over two years ago, possibly before or around its 2023 launch.

This breach has sparked concerns among users, especially given the app’s primary purpose of helping women stay safe by sharing experiences. The company has yet to provide further details on the breach and its implications.

Ransomware Gang Site Taken Down, New Group Emerges

Visitors to the dark web site of the BlackSuit ransomware gang likely had their hopes dashed after a global law enforcement action seized the site. According to insiders, the site was taken down by Homeland Security as part of Operation Checkmate. The page now displays logos from various law enforcement agencies, indicating a coordinated effort to combat cybercrime.

However, this takedown may be short-lived, as Cisco has reported the emergence of a new ransomware-as-a-service group called Chaos. This group is believed to have originated from the BlackSuit gang, although there is already a known ransomware group with the same name. Cisco suspects that this is a deliberate attempt to mislead investigators and cover tracks.

This is not the first time a criminal group has faked a shutdown. Many groups announce they are shutting down when they become notorious, only to restart under a new brand. Even if they are legitimately shut down, they often return within weeks or months.

Criminal Sentenced for Phishing Kit Sales

In a case highlighting the dangers of cybercrime, a 21-year-old student named Ollie Holman received a seven-year prison sentence for selling over a thousand phishing kits online. Holman, who was studying electronic and computer engineering at the University of Kent, managed to net around £300,000 through his illegal activities, which he laundered through cryptocurrency exchanges.

Security firm WMC Global discovered the phishing kits and alerted the police, leading to a European law enforcement investigation. Holman was arrested in October 2023 and later released on bail, but he continued offering support for the phishing kits via Telegram, resulting in a second arrest in May 2024.

Holman’s actions caused significant financial and emotional harm to countless individuals and businesses. The Crown Prosecution Service plans to take him back to court to seize his assets, if possible.

Drug Dealer Caught Using EncroChat

In another case, a drug dealer named Thomas Hooton was jailed for using the encrypted EncroChat service to communicate. Police were able to identify Hooton after an associate sent him a picture of his father, who was semi-famous as the lead singer of the British band The Farm.

Hooton pleaded guilty to conspiring to supply drugs worth around £1.3 million and was sentenced to 10 years and 8 months in prison. The case highlights how even encrypted communications can be exploited by law enforcement, especially when criminals leave behind small details that can be traced back to them.

Police continue to comb through EncroChat data to catch more criminals, showing that even the most secure communication methods are not foolproof.

Leave a Comment