Normal view

There are new articles available, click to refresh the page.
Today — 18 May 2024Main stream

Red flag? Samuel Alito scandal casts further doubt on supreme court’s impartiality

18 May 2024 at 07:00

The court will play a crucial role in November’s election. Alito’s pro-Trump flag adds fuel to an already raging ethics debate

With less than six months to go before America chooses its next president, the US supreme court finds itself in a profoundly unenviable position: not only has it been drawn into the thick of a volatile election, but swirling ethical scandals have cast doubt on its impartiality.

The US supreme court’s discomfort worsened dramatically on Thursday night when the New York Times published a photograph of an upside-down American flag being flown outside the Alexandria, Virginia, home of the hard-right justice Samuel Alito. The photo was taken on 17 January 2021, days after the insurrection at the US Capitol and days before Joe Biden’s inauguration.

Continue reading...

💾

© Photograph: Douglas Rissing/Getty Images

💾

© Photograph: Douglas Rissing/Getty Images

Will Michael Cohen’s testimony sway jurors in Trump’s hush-money trial?

18 May 2024 at 06:00

Trump’s former fixer gave damning testimony – and he’ll return to the stand on Monday as the trial moves towards a close

Donald Trump’s criminal trial is drawing to a close, with two looming questions: what will the jury decide, and how will America react?

After weeks of testimony from witnesses including the porn star Stormy Daniels, National Enquirer boss David Pecker and former senior Trump aide Hope Hicks, the trial came to an inflection point this week with its star witness. Michael Cohen, Trump’s former fixer and attorney who has since turned into a bellicose critic of his old boss, was on the stand all three days court was in session this week. He delivered damning testimony – then faced a tough if uneven grilling from Trump’s team.

Continue reading...

💾

© Photograph: Mike Segar/Reuters

💾

© Photograph: Mike Segar/Reuters

Yesterday — 17 May 2024Main stream

Trump aides plot deportation effort inspired by UK Rwanda plan – report

Wall Street Journal notes that British example may not be a good one, as ‘plan hasn’t gone into effect yet ‘amid legal challenges’

Aides to Donald Trump working to transform US immigration policy should he return to power are pursuing goals including “the largest mass deportation in US history” while “part-inspired” by the UK government’s deal to ship asylum seekers to Rwanda, the Wall Street Journal reported.

The Conservative UK government reached an agreement with the African country in 2022. Since then, however, the Rwanda policy has proved politically controversial, legally vulnerable, highly inefficient and vastly expensive.

Continue reading...

💾

© Photograph: Mark Wilson/Getty Images

💾

© Photograph: Mark Wilson/Getty Images

Biden and Trump are betting on debates to help magnify the other’s weaknesses

17 May 2024 at 10:31

Trump will look to again cast Biden as greatly diminished while Biden will aim to remind voters why they rejected Trump in 2020

It’s game on for a pair of presidential debates between two unpopular candidates most Americans wish weren’t running for the nation’s highest office.

In a ratatat social media exchange on Wednesday, Joe Biden and Donald Trump agreed to participate in two debates on 27 June, hosted by CNN, and on 10 September, hosted by ABC.

Continue reading...

💾

© Photograph: Jonathan Ernst/Reuters

💾

© Photograph: Jonathan Ernst/Reuters

Alito urged to recuse himself from Trump cases over reports of upside-down US flag outside his house – live

Senate judiciary committee chair says supreme court justice biased after report says flag linked to Trump’s baseless 2020 election fraud claim was flying outside his house

The Hawaii Democratic senator Brian Schatz also had strong words for Samuel Alito after the New York Times reported that a flag associated with Donald Trump’s election lies flew outside his house:

On X, Alicia Bannon, the director of the judiciary program at the non-partisan Brennan Center for Justice, warned that Samuel Alito’s display of a flag associated with Donald Trump’s election lies was “a five-alarm fire”:

Continue reading...

💾

© Photograph: Reuters

💾

© Photograph: Reuters

Trump-linked dark-money group spent $90m on racist and transphobic ads in 2022, records show

Revealed: Citizens for Sanity was one of top political spenders last election cycle and is back for 2024 with more extreme messaging

A dark money group with ties to Trump’s inner circle dropped more than $90m on ads described as vile, racist and transphobic in the second half of 2022 alone, new tax records obtained by Documented and the Guardian reveal. The staggering sum makes the newly created group, which is based out of the nerve center for the Maga movement, one of the top political spenders in the last election cycle, as it now appears to gear up to influence voters with violent, bigoted messaging in 2024.

The group, called Citizens for Sanity, formed in mid-2022, and quickly drew attention as it flooded the airwaves in battleground states and swing districts with deeply offensive and often misleading ads. Some ads targeted LGBTQ+ rights and attacked “Biden and his radical allies” for supporting “the woke left’s war on girls’ sports” and the “woke war on our children”. Others pictured Latino immigrants and characterized them as criminals “draining your paychecks, wrecking your schools, ruining your hospitals [and] threatening your family”, declaring that “Joe Biden and the Democrats have erased our southern border”.

Continue reading...

💾

© Photograph: Alex Wroblewski/AFP/Getty Images

💾

© Photograph: Alex Wroblewski/AFP/Getty Images

Trump to speak at NRA convention as US gun-safety groups sound alarm

17 May 2024 at 07:00

Fears grow that former president will follow through on threat to roll back gun-control regulations if he wins White House

When Donald Trump last addressed members of the National Rifle Association in February, he pitched himself as a paragon of inaction on gun violence, vowing to again march in lockstep with the gun rights group if he is reelected in November.

“During my four years, nothing happened. And there was great pressure on me having to do with guns. We did nothing. We didn’t yield,” Trump said at the NRA’s Great American Outdoor Show then. “When I’m re-elected, every single Biden attack on gun owners and manufacturers will be terminated.”

Continue reading...

💾

© Photograph: Leah Millis/Reuters

💾

© Photograph: Leah Millis/Reuters

Before yesterdayMain stream

Michael Cohen accused of lying over phone call at Trump hush-money trial

16 May 2024 at 17:30

Former lawyer and fixer for Donald Trump is under fierce attacks on his credibility by the ex-president’s legal team

Donald Trump’s lawyer on Thursday attacked the core charge against the former president as he sought to undercut Michael Cohen, the former attorney whose $130,000 hush-money payment to the adult film star Stormy Daniels is at the heart of the criminal trial in New York.

The defense, led by the Trump lawyer Todd Blanche, had Cohen admit that technically Daniels entered into a legal contract to sell the rights of her story about a sexual encounter with Trump, apparently in an attempt to justify labelling the repayments as legal expenses.

Continue reading...

💾

© Photograph: Andrés Kudacki/AP

💾

© Photograph: Andrés Kudacki/AP

Gaetz invokes Trump’s call to far-right Proud Boys at hush-money trial

Republican congressman travels to New York to support former president and says he is ‘standing back, and standing by’

Matt Gaetz echoed Donald Trump’s infamous remarks about the far-right Proud Boys on Thursday, as the Florida Republican congressman and other rightwing supporters of the former US presidentattended his criminal trial in Manhattan.

“Standing back, and standing by, Mr President,” Gaetz wrote on social media, with a photo of his group of supporters standing behind Trump outside the court where Trump is on trial on election subversion charges arising from hush-money payments to an adult film star during the 2016 campaign.

Continue reading...

💾

© Photograph: Drew Angerer/Getty Images

💾

© Photograph: Drew Angerer/Getty Images

Trump lawyer casts doubt on Cohen’s testimony about October 2016 call to Trump – live

Entire hush-money trial likely to succeed or fail on whether jurors believe Michael Cohen’s testimony

Judge Juan Merchan is on the bench and the court is in session.

Donald Trump has arrived in the courtroom for day 18 of his criminal trial.

Matt Gaetz, a Florida Republican representative

Lauren Boebert, a Colorado Republican congresswoman

Eric Trump

Boris Epshteyn, a longtime Trump aide

Continue reading...

💾

© Photograph: Andrés Kudacki/AP

💾

© Photograph: Andrés Kudacki/AP

Jim Jordan claims transcripts of Biden’s special counsel interview cannot be trusted after president blocks release of tape – live

16 May 2024 at 13:47

Jordan accuses White House of altering transcripts after Biden asserts executive privilege to block Republicans from accessing

Once again, a group of House Republicans is making a pilgrimage to the New York courthouse where Donald Trump’s business fraud trial is taking place in a show of support for their party’s presumptive presidential nominee.

Among the group is Florida congressman Matt Gaetz, who on X shared a photo of himself outside the courtroom while echoing Trump’s instruction to the Proud Boys militia group in 2020 to “stand back and stand by”:

Continue reading...

💾

© Photograph: Jonathan Ernst/Reuters

💾

© Photograph: Jonathan Ernst/Reuters

The Trump hush-money trial reveals a seamy world shot through with moral rot | Robert Reich

16 May 2024 at 06:01

The former president’s orbit is a sell-or-tell, catch-and-kill society where money and power are the only true values

There is something important about Trump’s criminal trial in New York that’s not being openly talked about. I don’t mean we’re not getting the facts about what’s happening in Manhattan superior court. But something very big is being left out.

The trial has introduced us to a world of moral and ethical loathsomeness in which people use and abuse one another routinely. It’s Trump world.

Continue reading...

💾

© Photograph: Mark Peterson/AFP/Getty Images

💾

© Photograph: Mark Peterson/AFP/Getty Images

It’s not pivotal that if the Donald is convicted Michael Cohen can sell his ‘Trump in jail’ T-shirts – but it’s not nothing | Emma Brockes

16 May 2024 at 06:00

It has been fun watching the former president’s disreputable former lawyer coolly damn his one-time mentor in court

There’s no justifying it, but I have a sneaky soft spot for Michael Cohen, the former lawyer, fixer and – as Fox News is keen to remind us – “ex-con” testifying against Donald Trump in the Stormy Daniels hush-money trial. Coming hard on the heels of Daniels’ explosive appearance last week, Cohen’s testimony could have been anticlimactic. Not so!

The 57-year-old, navigating a tricky line between languid, affable and sheepish, met tough questioning by Trump’s lawyers with the calmness of a man with nothing to lose and a lot of unfinished business to get through. Cohen, you’ll remember, literally did time for those hush-money payments (among other things), so it’s fair to say he might have a few scores to settle.

Emma Brockes is a Guardian columnist

Continue reading...

💾

© Photograph: David Dee Delgado/Getty Images

💾

© Photograph: David Dee Delgado/Getty Images

Alleged ‘deal’ offer from Trump to big oil could save industry $110bn, study finds

Ex-president at Mar-a-Lago last month hosted more than 20 executives, including from Chevron, Exxon and Occidental

A “deal” allegedly offered by Donald Trump to big-oil executives as he sought $1bn in campaign donations could save the industry $110bn in tax breaks if he returns to the White House, an analysis suggests.

The fundraising dinner held last month at Mar-a-Lago with more than 20 executives, including from Chevron, Exxon and Occidental Petroleum, reportedly involved Trump asking for large campaign contributions and promising, if elected, to remove barriers to drilling, scrap a pause on gas exports, and reverse new rules aimed at cutting car pollution.

Continue reading...

💾

© Photograph: Jon Cherry/Getty Images

💾

© Photograph: Jon Cherry/Getty Images

Biden should have pardoned Trump on federal charges, Mitt Romney says

Republican senator tells MSNBC that ‘frankly, the country doesn’t want to have to go through prosecuting a former president’

Joe Biden should have pardoned Donald Trump on all federal criminal charges the moment they were announced, the Utah senator and former Republican presidential nominee Mitt Romney said.

“Had I been President Biden,” Romney said, “when the justice department brought out indictments, I would have immediately pardoned him. I’d have pardoned President Trump.”

Continue reading...

💾

© Photograph: Sipa US/Alamy

💾

© Photograph: Sipa US/Alamy

Donald Trump comes face to face with former fixer Michael Cohen – podcast

This week, it was Donald Trump’s former fixer Michael Cohen’s turn to take the stand in the hush-money trial in New York. Cohen walked the jury through the steps he says he took to make any potential story that would damage Trump’s image go away, in advance of the 2016 election.

The defence is trying to chip away at Cohen’s credibility, to sow seeds of doubt among the jury listening to his testimony. So how did he do? Jonathan Freedland asks former federal prosecutor Ankush Khardori what he makes of the prosecution’s star witness so far

Archive: Fox News 5, CBS News, CNN, Sky Australia

Continue reading...

💾

© Photograph: David Dee Delgado/Getty Images

💾

© Photograph: David Dee Delgado/Getty Images

Joe Biden and Donald Trump agree to two US presidential debates

15 May 2024 at 13:37

Both candidates agreed upon two dates for debates: 27 June and 10 September, and Trump also posted about a third date in October

Shortly after the Biden-Harris re-election campaign proposed two TV debates between Joe Biden and Donald Trump ahead of November’s presidential vote, both men have agreed upon two debate dates: 27 June and 10 September.

CNN confirmed that it would host the first debate of 2024 on that date at 9pm ET from the crucial battleground state of Georgia.

Continue reading...

💾

© Photograph: Reuters

💾

© Photograph: Reuters

We’re in a pivotal moment in American history. We cannot retreat | Bernie Sanders

15 May 2024 at 13:30

Clearly, our job is not just to re-elect Biden. It’s much more than that

In 1776, Americans, living in a British colony, put their lives on the line and fought for independence from the king of England. They wrote the strongest democratic constitution that had ever been written as they created a new nation. That was a pivotal moment in American history.

In 1861, civil war broke out in the United States and more than 600,000 Americans died in the war between the states. Slavery was abolished. Over the ensuing decades, racist forces regained power and established an apartheid form of government throughout the old confederacy. That was a pivotal moment in American history.

Continue reading...

💾

© Photograph: Getty Images

💾

© Photograph: Getty Images

‘Good chance’ we’ll leave US if Trump acquitted, Stormy Daniels husband says

15 May 2024 at 19:49

Barrett Blade says wife, who testified in hush-money trial, ‘wants to move past this’ but admits ‘I don’t see people fighting for her’

The husband of Stormy Daniels said there is a “good chance” that the couple will leave the US if Donald Trump is acquitted in his criminal trial over paying hush-money payments to the adult film star.

“I think if it’s not guilty, we got to decide what to do. Good chance we’ll probably vacate this country,” Barrett Blade told CNN host Erin Burnett on Tuesday.

Continue reading...

💾

© Photograph: Michael M Santiago/Getty Images

💾

© Photograph: Michael M Santiago/Getty Images

He only visited the Playboy Mansion to support their journalism

15 May 2024 at 10:09
Perhaps Donald John Trump will have only one criminal trial this year. The prosecution's case in his state trial for using hush money to pay off a porn star to illegally influence his election is finishing with ex-fixer Michael Cohen testifying.

Also: A history of Donald Trump and his associations with the Playboy empire including his soft-porn film. A photo of Donald Trump, his wife, his daughter, Karen McDougal, and three other Playboy bunnies at the Playboy Mansion. He only attended Epstein parties for the scintillating conversation with underaged women.

Suck it, Lichtenstein!

By: ambrosen
13 May 2024 at 16:19
I cannot tell you how or why, but at some point a few years back I discovered that Instagram Stories not only allows you unlimited emojis, it ALSO allows you to enlarge them to an apparently infinite degree. And so, may I present: FAMOUS PAINTINGS RECREATED USING ONLY EMOJIS! All on one page: Vermeer's Girl with a Pearl Earring, Goya's Saturn Devouring His Son. Klimt's The Kiss, Wood's American Gothic, Michaelangelo's The Creation of Adam and more, all moulded from shaded yellow spheres.

Although the artist's enthusiasm wanes towards the end, especially for writing the blurbs ("only to give up and slap a couple boat emojis on it because that shit's hard"), much of the history of art is here. All in emojis.

From the author-artist's substack.

Many thanks to Tehhund, curator and creator of the internet's most fascinating and bizarre phrases and things for drawing this to my attention.

Soundgarden's Reunion Tour 2012

By: hippybear
11 May 2024 at 22:29
I don't know why YouTube is serving me all these concerts right now, but I'm not complaining. Here's Soundgarden - Hyde Park - Hard Rock Calling 7-13-2012 - Pro Shot (HQ) Full Show [1h54m], arguably the band at the height of their career after taking a break and reforming. This concert is shortly before the release of their final album King Animal.

SETLIST: 01 Searching With My Good Eye Closed 02 Spoonman 03 Gun 04 Jesus Christ Pose 05 Black Hole Sun 06 Outshined 07 Hunted Down 08 Drawing Flies 09 Blow Up the Outside World 10 Fell on Black Days 11 Ugly Truth 12 My Wave 13 The Day I Tried to Live 14 Beyond the Wheel 15 Let Me Drown 16 Pretty Noose 17 Superunknown 18 4th of July Encore 19 Rusty Cage 20 Slaves & Bulldozers/(In My Time of Dying)

Fear, Cynicism, Nihilism, and Apathy

By: Rhaomi
9 May 2024 at 18:26
Even in a state where surveillance is almost total, the experience of tyranny and injustice can radicalize people. Anger at arbitrary power will always lead someone to start thinking about another system, a better way to run society. [...] If people are naturally drawn to the image of human rights, to the language of democracy, to the dream of freedom, then those concepts have to be poisoned. [...] Here is a difficult truth: A part of the American political spectrum is not merely a passive recipient of the combined authoritarian narratives that come from Russia, China, and their ilk, but an active participant in creating and spreading them. Like the leaders of those countries, the American MAGA right also wants Americans to believe that their democracy is degenerate, their elections illegitimate, their civilization dying. The MAGA movement's leaders also have an interest in pumping nihilism and cynicism into the brains of their fellow citizens, and in convincing them that nothing they see is true. Their goals are so similar that it is hard to distinguish between the online American alt-right and its foreign amplifiers, who have multiplied since the days when this was solely a Russian project. Tucker Carlson has even promoted the fear of a color revolution in America, lifting the phrase directly from Russian propaganda.
The New Propaganda War: Autocrats in China, Russia, and elsewhere are now making common cause with MAGA Republicans to discredit liberalism and freedom around the world. [SLAtlantic]

"It was that welcome feeling that every treehouse was your home."

9 May 2024 at 06:57
Set to the music of recent Hawaiian artists, The Edge of Paradise (SLYT) is a quiet, contemplative documentary on Taylor Camp, a treehouse community of war veterans and hippies that thrived on a jungle-backed beach on Kaua'i in the 1960s and 1970s (cw: black and white archival stills of unclothed community members, oral recollections of police actions against the community).

Biden Announces $3.3 Billion Microsoft AI Center at Trump’s Failed Foxconn Site

8 May 2024 at 16:27
The president’s visit to Wisconsin celebrated the investment by Microsoft in a center to be built on the site of a failed Foxconn project negotiated by his predecessor.

© Tom Brenner for The New York Times

President Biden at the Intel campus in Chandler, Ariz., in March. His “Investing in America” agenda has focused on bringing billions of private-sector dollars into manufacturing and industries such as clean energy and artificial intelligence.

A fateful exit interview

By: chavenet
7 May 2024 at 05:19
Wherever the blame lies, at the heart of the story are humans operating, ruptured, in an institutional machine. Many of the 42 are still 'deeply injured' by the incident, said Simon, who acts as their unofficial spokesperson. As the whole affair unravelled, the diocese was already under immense strain. The COVID lockdowns set clergy against their bishops, with many priests livid at having to close their churches. Others were angered by moves to invest millions in a new wave of informal congregations meeting in pubs, coffee shops and cinemas. And throughout it all there was division and tension over the church-wide culture war about gay blessings. 'There's so little trust at the moment,' Roger reflected. 'And in London, all the anger and the issues have a face: that face is Martin Sargeant.' from In the Shadow of St Paul's [The Fence; ungated] [CW: suicide, misogyny, homophobia.]

Send not to know for whom the bell tolls (but in this case.......)

5 May 2024 at 18:25
What happens if a US presidential candidate dies? Joe Biden and Donald Trump are the two oldest candidates in US history. If either needs to be replaced, what next? from the Guardian

'....knowingly and willfully mailing or otherwise making "any threat to take the life of, to kidnap, or to inflict great bodily harm upon the president of the United States" is a federal crime in the USA'. (Wiki). Needless to say, please keep this discussion legal.

How Pastor Chad Nedohin Helped Turn Trump Media Into a Meme Stock

Chad Nedohin, a part-time pastor, is among the fans of Donald J. Trump who helped turn Trump Media into a meme stock with volatile prices.

© Amber Bracken for The New York Times

Chad Nedohin, a podcaster and part-time pastor in Canada, has urged people to invest in Trump Media & Technology Group and hold on to the stock.

Truth Social Has an Edge as Rival Right-Wing Apps Falter

Donald Trump’s social media platform has outdistanced similar conservative sites such as Parler and Gettr, even as it lags far behind X and others.

© John Minchillo/Associated Press

Truth Social enjoys one crucial advantage over other right-wing apps: Donald J. Trump.

The CIA's Long and Dangerous History of Refusing to Answer Absurdly Obvious Questions

The CIA is so known for its unabashed secrecy that, when it joined Twitter in 2014, its first tweet was: “We can neither confirm nor deny that this is our first tweet.” This non-response response is known as a “Glomar,” and while the intelligence community likes to poke fun at how often they invoke it, this inane phrase has allowed the CIA to skirt meaningful transparency and accountability for decades.

In 1966, over the Johnson administration’s opposition, Congress enacted the Freedom of Information Act (FOIA), giving all of us the right to ask the government for documents and have the government respond, as it believed such access was a prerequisite to a functioning democracy. Soon after FOIA was passed, a Soviet nuclear submarine went missing somewhere in the Pacific Ocean, and the CIA took an early opportunity to undermine this new law.

The Soviet Union and the United States raced to locate the missing sub and extract the intelligence likely inside. But first, the U.S. needed to build a ship that could actually extract the sub once it was found — and the government wanted no one to know about it. The CIA contracted this mission out to Howard Hughes, a billionaire with little concern for government transparency, who told the media that the purpose of the ship (named the Hughes Glomar Explorer) was to extract manganese nodules from the ocean floor. Six years later, in 1974, the extraction began. Unfortunately for the U.S., the extracted sub broke into pieces and what the government most wanted was lost: the ship’s code machine and two nuclear missiles. Details of this secret, bungled extraction started to leak, inaccuracies and half-truths swirled, and people rushed to file FOIA requests hoping to answer the many outstanding questions.

Worried about the geopolitical consequences, and obsessed with controlling information about its activities, the CIA came up with a novel way to keep the mission secret without telling an all-out lie. The agency decided it would refuse to confirm or deny whether records about the Glomar Explorer’s mission existed, despite the mounting public evidence that they did. And so the “Glomar response” was born. And, in the case of the Glomar Explorer, it worked: Historians claim many documents remain hidden to this day.

Unfortunately, in the decades since the submarine debacle, and especially in the post-9/11 era, we’ve repeatedly seen the CIA use the Glomar response to evade responsibility. They have used it to claim they could not say whether they had information about the government’s use of drones to carry out lethal strikes overseas, and when asked about legal justifications for the verified extrajudicial killing of three U.S. citizens. They’ve even used it to side-step questions about whether they’ve spied on Congress.

We’re even seeing state agencies attempt to use the CIA’s non-response to circumvent local public records requests. For example, in 2017, the New York Civil Liberties Union filed a public records request seeking documents regarding the NYPD’s monitoring of protesters’ social media activity and cell phones. The NYPD initially responded with a blanket statement that it could “neither confirm nor deny” whether such records existed, saying that even revealing the existence of records could harm national security. A New York court rejected this argument and ordered the NYPD to respond to the request in full.

And the CIA’s penchant for secrecy continues to expand, with the agency using Glomar to obstruct attempts to obtain records that would publicly shine a light on the agency’s failures and abuse, even when that abuse is well documented by the CIA itself and other sources.

Take, for instance, the CIA’s torture program. After the 9/11 attacks, the agency abducted dozens of Muslim men and boys, held them incommunicado, brutally tortured them, and denied the due process in sites around the globe. Once the program was exposed, 14 of the government’s “high-value detainees” were taken to the U.S. military prison at Guantánamo Bay, and detained at a notorious facility known as “Camp VII.” Attorney James G. Connell III, who represents Ammar al Baluchi, one of the men subjected to the CIA torture program and sent to Camp VII, filed a FOIA request with the CIA seeking information about the agency’s “operational control” over the facility. That “operational control” is hardly a secret: it was highlighted in the Senate Torture Report and in CIA and military commissions documents. But instead of processing Mr. Connell’s request, the agency issued what it called a “partial” Glomar response, producing three records, withholding a fourth in its entirety, and refusing to confirm or deny whether any other responsive records exist.

Given the extensive public record about the CIA’s connection to Camp VII, its refusal to acknowledge that it has responsive records both violates the law and defies common sense. That’s why we’re representing Mr. Connell in his appeal in federal court. To uphold its response, the CIA must demonstrate that it is logical or plausible that it has no responsive records in light of the entire record. That’s simply not possible here. We know this because there is an overwhelming amount of public evidence about Camp VII — from the Senate Torture Report, to court documents from the Guantánamo proceedings, to other documents the CIA itself released — that has left no doubt of CIA involvement. And yet, the CIA continues to avoid its legal obligations under FOIA through gaslighting and Glomar.

Connell v. CIA offers a real chance to not only break the CIA’s bad habit of using Glomar to evade transparency and accountability, but also issue a warning to other government agencies that hope to follow in the CIA’s footsteps by leaning into excessive secrecy.

BlackCat Ransomware Group Implodes After Apparent $22M Payment by Change Healthcare

5 March 2024 at 19:22

There are indications that U.S. healthcare giant Change Healthcare has made a $22 million extortion payment to the infamous BlackCat ransomware group (a.k.a. “ALPHV“) as the company struggles to bring services back online amid a cyberattack that has disrupted prescription drug services nationwide for weeks. However, the cybercriminal who claims to have given BlackCat access to Change’s network says the crime gang cheated them out of their share of the ransom, and that they still have the sensitive data Change reportedly paid the group to destroy. Meanwhile, the affiliate’s disclosure appears to have prompted BlackCat to cease operations entirely.

Image: Varonis.

In the third week of February, a cyber intrusion at Change Healthcare began shutting down important healthcare services as company systems were taken offline. It soon emerged that BlackCat was behind the attack, which has disrupted the delivery of prescription drugs for hospitals and pharmacies nationwide for nearly two weeks.

On March 1, a cryptocurrency address that security researchers had already mapped to BlackCat received a single transaction worth approximately $22 million. On March 3, a BlackCat affiliate posted a complaint to the exclusive Russian-language ransomware forum Ramp saying that Change Healthcare had paid a $22 million ransom for a decryption key, and to prevent four terabytes of stolen data from being published online.

The affiliate claimed BlackCat/ALPHV took the $22 million payment but never paid him his percentage of the ransom. BlackCat is known as a “ransomware-as-service” collective, meaning they rely on freelancers or affiliates to infect new networks with their ransomware. And those affiliates in turn earn commissions ranging from 60 to 90 percent of any ransom amount paid.

“But after receiving the payment ALPHV team decide to suspend our account and keep lying and delaying when we contacted ALPHV admin,” the affiliate “Notchy” wrote. “Sadly for Change Healthcare, their data [is] still with us.”

Change Healthcare has neither confirmed nor denied paying, and has responded to multiple media outlets with a similar non-denial statement — that the company is focused on its investigation and on restoring services.

Assuming Change Healthcare did pay to keep their data from being published, that strategy seems to have gone awry: Notchy said the list of affected Change Healthcare partners they’d stolen sensitive data from included Medicare and a host of other major insurance and pharmacy networks.

On the bright side, Notchy’s complaint seems to have been the final nail in the coffin for the BlackCat ransomware group, which was infiltrated by the FBI and foreign law enforcement partners in late December 2023. As part of that action, the government seized the BlackCat website and released a decryption tool to help victims recover their systems.

BlackCat responded by re-forming, and increasing affiliate commissions to as much as 90 percent. The ransomware group also declared it was formally removing any restrictions or discouragement against targeting hospitals and healthcare providers.

However, instead of responding that they would compensate and placate Notchy, a representative for BlackCat said today the group was shutting down and that it had already found a buyer for its ransomware source code.

The seizure notice now displayed on the BlackCat darknet website.

“There’s no sense in making excuses,” wrote the RAMP member “Ransom.” “Yes, we knew about the problem, and we were trying to solve it. We told the affiliate to wait. We could send you our private chat logs where we are shocked by everything that’s happening and are trying to solve the issue with the transactions by using a higher fee, but there’s no sense in doing that because we decided to fully close the project. We can officially state that we got screwed by the feds.”

BlackCat’s website now features a seizure notice from the FBI, but several researchers noted that this image seems to have been merely cut and pasted from the notice the FBI left in its December raid of BlackCat’s network. The FBI has not responded to requests for comment.

Fabian Wosar, head of ransomware research at the security firm Emsisoft, said it appears BlackCat leaders are trying to pull an “exit scam” on affiliates by withholding many ransomware payment commissions at once and shutting down the service.

“ALPHV/BlackCat did not get seized,” Wosar wrote on Twitter/X today. “They are exit scamming their affiliates. It is blatantly obvious when you check the source code of their new takedown notice.”

Dmitry Smilyanets, a researcher for the security firm Recorded Future, said BlackCat’s exit scam was especially dangerous because the affiliate still has all the stolen data, and could still demand additional payment or leak the information on his own.

“The affiliates still have this data, and they’re mad they didn’t receive this money, Smilyanets told Wired.com. “It’s a good lesson for everyone. You cannot trust criminals; their word is worth nothing.”

BlackCat’s apparent demise comes closely on the heels of the implosion of another major ransomware group — LockBit, a ransomware gang estimated to have extorted over $120 million in payments from more than 2,000 victims worldwide. On Feb. 20, LockBit’s website was seized by the FBI and the U.K.’s National Crime Agency (NCA) following a months-long infiltration of the group.

LockBit also tried to restore its reputation on the cybercrime forums by resurrecting itself at a new darknet website, and by threatening to release data from a number of major companies that were hacked by the group in the weeks and days prior to the FBI takedown.

But LockBit appears to have since lost any credibility the group may have once had. After a much-promoted attack on the government of Fulton County, Ga., for example, LockBit threatened to release Fulton County’s data unless paid a ransom by Feb. 29. But when Feb. 29 rolled around, LockBit simply deleted the entry for Fulton County from its site, along with those of several financial organizations that had previously been extorted by the group.

Fulton County held a press conference to say that it had not paid a ransom to LockBit, nor had anyone done so on their behalf, and that they were just as mystified as everyone else as to why LockBit never followed through on its threat to publish the county’s data. Experts told KrebsOnSecurity LockBit likely balked because it was bluffing, and that the FBI likely relieved them of that data in their raid.

Smilyanets’ comments are driven home in revelations first published last month by Recorded Future, which quoted an NCA official as saying LockBit never deleted the data after being paid a ransom, even though that is the only reason many of its victims paid.

“If we do not give you decrypters, or we do not delete your data after payment, then nobody will pay us in the future,” LockBit’s extortion notes typically read.

Hopefully, more companies are starting to get the memo that paying cybercrooks to delete stolen data is a losing proposition all around.

FBI’s LockBit Takedown Postponed a Ticking Time Bomb in Fulton County, Ga.

25 February 2024 at 21:17

The FBI’s takedown of the LockBit ransomware group last week came as LockBit was preparing to release sensitive data stolen from government computer systems in Fulton County, Ga. But LockBit is now regrouping, and the gang says it will publish the stolen Fulton County data on March 2 unless paid a ransom. LockBit claims the cache includes documents tied to the county’s ongoing criminal prosecution of former President Trump, but court watchers say teaser documents published by the crime gang suggest a total leak of the Fulton County data could put lives at risk and jeopardize a number of other criminal trials.

A new LockBit website listing a countdown timer until the promised release of data stolen from Fulton County, Ga.

In early February, Fulton County leaders acknowledged they were responding to an intrusion that caused disruptions for its phone, email and billing systems, as well as a range of county services, including court systems.

On Feb. 13, the LockBit ransomware group posted on its victim shaming blog a new entry for Fulton County, featuring a countdown timer saying the group would publish the data on Feb. 16 unless county leaders agreed to negotiate a ransom.

“We will demonstrate how local structures negligently handled information protection,” LockBit warned. “We will reveal lists of individuals responsible for confidentiality. Documents marked as confidential will be made publicly available. We will show documents related to access to the state citizens’ personal data. We aim to give maximum publicity to this situation; the documents will be of interest to many. Conscientious residents will bring order.”

Yet on Feb. 16, the entry for Fulton County was removed from LockBit’s site without explanation. This usually only happens after the victim in question agrees to pay a ransom demand and/or enters into negotiations with their extortionists.

However, Fulton County Commission Chairman Robb Pitts said the board decided it “could not in good conscience use Fulton County taxpayer funds to make a payment.”

“We did not pay nor did anyone pay on our behalf,” Pitts said at an incident briefing on Feb. 20.

Just hours before that press conference, LockBit’s various websites were seized by the FBI and the U.K.’s National Crime Agency (NCA), which replaced the ransomware group’s homepage with a seizure notice and used the existing design of LockBit’s victim shaming blog to publish press releases about the law enforcement action.

The feds used the existing design on LockBit’s victim shaming website to feature press releases and free decryption tools.

Dubbed “Operation Cronos,” the effort involved the seizure of nearly three-dozen servers; the arrest of two alleged LockBit members; the release of a free LockBit decryption tool; and the freezing of more than 200 cryptocurrency accounts thought to be tied to the gang’s activities. The government says LockBit has claimed more than 2,000 victims worldwide and extorted over $120 million in payments.

UNFOLDING DISASTER

In a lengthy, rambling letter published on Feb. 24 and addressed to the FBI, the ransomware group’s leader LockBitSupp announced that their victim shaming websites were once again operational on the dark web, with fresh countdown timers for Fulton County and a half-dozen other recent victims.

“The FBI decided to hack now for one reason only, because they didn’t want to leak information fultoncountyga.gov,” LockBitSupp wrote. “The stolen documents contain a lot of interesting things and Donald Trump’s court cases that could affect the upcoming US election.”

A screen shot released by LockBit showing various Fulton County file shares that were exposed.

LockBit has already released roughly two dozen files allegedly stolen from Fulton County government systems, although none of them involve Mr. Trump’s criminal trial. But the documents do appear to include court records that are sealed and shielded from public viewing.

George Chidi writes The Atlanta Objective, a Substack publication on crime in Georgia’s capital city. Chidi says the leaked data so far includes a sealed record related to a child abuse case, and a sealed motion in the murder trial of Juwuan Gaston demanding the state turn over confidential informant identities.

Chidi cites reports from a Fulton County employee who said the confidential material includes the identities of jurors serving on the trial of the rapper Jeffery “Young Thug” Williams, who is charged along with five other defendants in a racketeering and gang conspiracy.

“The screenshots suggest that hackers will be able to give any attorney defending a criminal case in the county a starting place to argue that evidence has been tainted or witnesses intimidated, and that the release of confidential information has compromised cases,” Chidi wrote. “Judge Ural Glanville has, I am told by staff, been working feverishly behind the scenes over the last two weeks to manage the unfolding disaster.”

LockBitSupp also denied assertions made by the U.K.’s NCA that LockBit did not delete stolen data as promised when victims agreed to pay a ransom. The accusation is an explosive one because nobody will pay a ransom if they don’t believe the ransomware group will hold up its end of the bargain.

The ransomware group leader also confirmed information first reported here last week, that federal investigators managed to hack LockBit by exploiting a known vulnerability in PHP, a scripting language that is widely used in Web development.

“Due to my personal negligence and irresponsibility I relaxed and did not update PHP in time,” LockBitSupp wrote. “As a result of which access was gained to the two main servers where this version of PHP was installed.”

LockBitSupp’s FBI letter said the group kept copies of its stolen victim data on servers that did not use PHP, and that consequently it was able to retain copies of files stolen from victims. The letter also listed links to multiple new instances of LockBit dark net websites, including the leak page listing Fulton County’s new countdown timer.

LockBit’s new data leak site promises to release stolen Fulton County data on March 2, 2024, unless paid a ransom demand.

“Even after the FBI hack, the stolen data will be published on the blog, there is no chance of destroying the stolen data without payment,” LockBitSupp wrote. “All FBI actions are aimed at destroying the reputation of my affiliate program, my demoralization, they want me to leave and quit my job, they want to scare me because they can not find and eliminate me, I can not be stopped, you can not even hope, as long as I am alive I will continue to do pentest with postpaid.”

DOX DODGING

In January 2024, LockBitSupp told XSS forum members he was disappointed the FBI hadn’t offered a reward for his doxing and/or arrest, and that in response he was placing a bounty on his own head — offering $10 million to anyone who could discover his real name.

After the NCA and FBI seized LockBit’s site, the group’s homepage was retrofitted with a blog entry titled, “Who is LockBitSupp? The $10M question.” The teaser made use of LockBit’s own countdown timer, and suggested the real identity of LockBitSupp would soon be revealed.

However, after the countdown timer expired the page was replaced with a taunting message from the feds, but it included no new information about LockBitSupp’s identity.

On Feb. 21, the U.S. Department of State announced rewards totaling up to $15 million for information leading to the arrest and/or conviction of anyone participating in LockBit ransomware attacks. The State Department said $10 million of that is for information on LockBit’s leaders, and up to $5 million is offered for information on affiliates.

In an interview with the malware-focused Twitter/X account Vx-Underground, LockBit staff asserted that authorities had arrested a couple of small-time players in their operation, and that investigators still do not know the real-life identities of the core LockBit members, or that of their leader.

“They assert the FBI / NCA UK / EUROPOL do not know their information,” Vx-Underground wrote. “They state they are willing to double the bounty of $10,000,000. They state they will place a $20,000,000 bounty of their own head if anyone can dox them.”

TROUBLE ON THE HOMEFRONT?

In the weeks leading up to the FBI/NCA takedown, LockBitSupp became embroiled in a number of high-profile personal and business disputes on the Russian cybercrime forums.

Earlier this year, someone used LockBit ransomware to infect the networks of AN-Security, a venerated 30-year-old security and technology company based in St. Petersburg, Russia. This violated the golden rule for cybercriminals based in Russia and former soviet nations that make up the Commonwealth of Independent States, which is that attacking your own citizens in those countries is the surest way to get arrested and prosecuted by local authorities.

LockBitSupp later claimed the attacker had used a publicly leaked, older version of LockBit to compromise systems at AN-Security, and said the attack was an attempt to smear their reputation by a rival ransomware group known as “Clop.” But the incident no doubt prompted closer inspection of LockBitSupp’s activities by Russian authorities.

Then in early February, the administrator of the Russian-language cybercrime forum XSS said LockBitSupp had threatened to have him killed after the ransomware group leader was banned by the community. LockBitSupp was excommunicated from XSS after he refused to pay an arbitration amount ordered by the forum administrator. That dispute related to a complaint from another forum member who said LockBitSupp recently stiffed him on his promised share of an unusually large ransomware payout.

A posted by the XSS administrator saying LockBitSupp wanted him dead.

INTERVIEW WITH LOCKBITSUPP

KrebsOnSecurity sought comment from LockBitSupp at the ToX instant messenger ID listed in his letter to the FBI. LockBitSupp declined to elaborate on the unreleased documents from Fulton County, saying the files will be available for everyone to see in a few days.

LockBitSupp said his team was still negotiating with Fulton County when the FBI seized their servers, which is why the county has been granted a time extension. He also denied threatening to kill the XSS administrator.

“I have not threatened to kill the XSS administrator, he is blatantly lying, this is to cause self-pity and damage my reputation,” LockBitSupp told KrebsOnSecurity. “It is not necessary to kill him to punish him, there are more humane methods and he knows what they are.”

Asked why he was so certain the FBI doesn’t know his real-life identity, LockBitSupp was more precise.

“I’m not sure the FBI doesn’t know who I am,” he said. “I just believe they will never find me.”

It seems unlikely that the FBI’s seizure of LockBit’s infrastructure was somehow an effort to stave off the disclosure of Fulton County’s data, as LockBitSupp maintains. For one thing, Europol said the takedown was the result of a months-long infiltration of the ransomware group.

Also, in reporting on the attack’s disruption to the office of Fulton County District Attorney Fani Willis on Feb. 14, CNN reported that by then the intrusion by LockBit had persisted for nearly two and a half weeks.

Finally, if the NCA and FBI really believed that LockBit never deleted victim data, they had to assume LockBit would still have at least one copy of all their stolen data hidden somewhere safe.

Fulton County is still trying to recover systems and restore services affected by the ransomware attack. “Fulton County continues to make substantial progress in restoring its systems following the recent ransomware incident resulting in service outages,” reads the latest statement from the county on Feb. 22. “Since the start of this incident, our team has been working tirelessly to bring services back up.”

Update, Feb. 29, 3:22 p.m. ET: Just hours after this story ran, LockBit changed its countdown timer for Fulton County saying they had until the morning of Feb. 29 (today) to pay a ransonm demand. When the official deadline neared today, Fulton County’s listing was removed from LockBit’s victim shaming website. Asked about the removal of the listing, LockBit’s leader “LockBitSupp” told KrebsOnSecurity that Fulton County paid a ransom demand. County officials have scheduled a press conference on the ransomware attack at 4:15 p.m. ET today.

Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider

30 January 2024 at 14:07

On Jan. 9, 2024, U.S. authorities arrested a 19-year-old Florida man charged with wire fraud, aggravated identity theft, and conspiring with others to use SIM-swapping to steal cryptocurrency. Sources close to the investigation tell KrebsOnSecurity the accused was a key member of a criminal hacking group blamed for a string of cyber intrusions at major U.S. technology companies during the summer of 2022.

A graphic depicting how 0ktapus leveraged one victim to attack another. Image credit: Amitai Cohen of Wiz.

Prosecutors say Noah Michael Urban of Palm Coast, Fla., stole at least $800,000 from at least five victims between August 2022 and March 2023. In each attack, the victims saw their email and financial accounts compromised after suffering an unauthorized SIM-swap, wherein attackers transferred each victim’s mobile phone number to a new device that they controlled.

The government says Urban went by the aliases “Sosa” and “King Bob,” among others. Multiple trusted sources told KrebsOnSecurity that Sosa/King Bob was a core member of a hacking group behind the 2022 breach at Twilio, a company that provides services for making and receiving text messages and phone calls. Twilio disclosed in Aug. 2022 that an intrusion had exposed a “limited number” of Twilio customer accounts through a sophisticated social engineering attack designed to steal employee credentials.

Shortly after that disclosure, the security firm Group-IB published a report linking the attackers behind the Twilio intrusion to separate breaches at more than 130 organizations, including LastPass, DoorDash, Mailchimp, and Plex. Multiple security firms soon assigned the hacking group the nickname “Scattered Spider.”

Group-IB dubbed the gang by a different name — 0ktapus — which was a nod to how the criminal group phished employees for credentials. The missives asked users to click a link and log in at a phishing page that mimicked their employer’s Okta authentication page. Those who submitted credentials were then prompted to provide the one-time password needed for multi-factor authentication.

A booking photo of Noah Michael Urban released by the Volusia County Sheriff.

0ktapus used newly-registered domains that often included the name of the targeted company, and sent text messages urging employees to click on links to these domains to view information about a pending change in their work schedule. The phishing sites used a Telegram instant message bot to forward any submitted credentials in real-time, allowing the attackers to use the phished username, password and one-time code to log in as that employee at the real employer website.

0ktapus often leveraged information or access gained in one breach to perpetrate another. As documented by Group-IB, the group pivoted from its access to Twilio to attack at least 163 of its customers. Among those was the encrypted messaging app Signal, which said the breach could have let attackers re-register the phone number on another device for about 1,900 users.

Also in August 2022, several employees at email delivery firm Mailchimp provided their remote access credentials to this phishing group. According to an Aug. 12 blog post, the attackers used their access to Mailchimp employee accounts to steal data from 214 customers involved in cryptocurrency and finance.

On August 25, 2022, the password manager service LastPass disclosed a breach in which attackers stole some source code and proprietary LastPass technical information, and weeks later LastPass said an investigation revealed no customer data or password vaults were accessed.

However, on November 30, 2022 LastPass disclosed a far more serious breach that the company said leveraged data stolen in the August breach. LastPass said criminal hackers had stolen encrypted copies of some password vaults, as well as other personal information.

In February 2023, LastPass disclosed that the intrusion involved a highly complex, targeted attack against a DevOps engineer who was one of only four LastPass employees with access to the corporate vault. In that incident, the attackers exploited a security vulnerability in a Plex media server that the employee was running on his home network, and succeeded in installing malicious software that stole passwords and other authentication credentials. The vulnerability exploited by the intruders was patched back in 2020, but the employee never updated his Plex software.

As it happens, Plex announced its own data breach one day before LastPass disclosed its initial August intrusion. On August 24, 2022, Plex’s security team urged users to reset their passwords, saying an intruder had accessed customer emails, usernames and encrypted passwords.

KING BOB’S GRAILS

A review of thousands of messages that Sosa and King Bob posted to several public forums and Discord servers over the past two years shows that the person behind these identities was mainly focused on two things: Sim-swapping, and trading in stolen, unreleased rap music recordings from popular artists.

Indeed, those messages show Sosa/King Bob was obsessed with finding new “grails,” the slang term used in some cybercrime discussion channels to describe recordings from popular artists that have never been officially released. It stands to reason that King Bob was SIM-swapping important people in the music industry to obtain these files, although there is little to support this conclusion from the public chat records available.

“I got the most music in the com,” King Bob bragged in a Discord server in November 2022. “I got thousands of grails.”

King Bob’s chats show he was particularly enamored of stealing the unreleased works of his favorite artists — Lil Uzi Vert, Playboi Carti, and Juice Wrld. When another Discord user asked if he has Eminem grails, King Bob said he was unsure.

“I have two folders,” King Bob explained. “One with Uzi, Carti, Juicewrld. And then I have ‘every other artist.’ Every other artist is unorganized as fuck and has thousands of random shit.”

King Bob’s posts on Discord show he quickly became a celebrity on Leaked[.]cx, one of most active forums for trading, buying and selling unreleased music from popular artists. The more grails that users share with the Leaked[.]cx community, the more their status and access on the forum grows.

The last cache of Leaked dot cx indexed by the archive.org on Jan. 11, 2024.

And King Bob shared a large number of his purloined tunes with this community. Still others he tried to sell. It’s unclear how many of those sales were ever consummated, but it is not unusual for a prized grail to sell for anywhere from $5,000 to $20,000.

In mid-January 2024, several Leaked[.]cx regulars began complaining that they hadn’t seen King Bob in a while and were really missing his grails. On or around Jan. 11, the same day the Justice Department unsealed the indictment against Urban, Leaked[.]cx started blocking people who were trying to visit the site from the United States.

Days later, frustrated Leaked[.]cx users speculated about what could be the cause of the blockage.

“Probs blocked as part of king bob investigation i think?,” wrote the user “Plsdontarrest.” “Doubt he only hacked US artists/ppl which is why it’s happening in multiple countries.”

FORESHADOWING

On Sept. 21, 2022, KrebsOnSecurity told the story of a “Foreshadow,” the nickname chosen by a Florida teenager who was working for a SIM-swapping crew when he was abducted, beaten and held for a $200,000 ransom. A rival SIM-swapping group claimed that Foreshadow and his associates had robbed them of their fair share of the profits from a recent SIM-swap.

In a video released by his abductors on Telegram, a bloodied, battered Foreshadow was made to say they would kill him unless the ransom was paid.

As I wrote in that story, Foreshadow appears to have served as a “holder” — a term used to describe a low-level member of any SIM-swapping group who agrees to carry out the riskiest and least rewarding role of the crime: Physically keeping and managing the various mobile devices and SIM cards that are used in SIM-swapping scams.

KrebsOnSecurity has since learned that Foreshadow was a holder for a particularly active SIM-swapper who went by “Elijah,” which was another nickname that prosecutors say Urban used.

Shortly after Foreshadow’s hostage video began circulating on Telegram and Discord, multiple known actors in the SIM-swapping space told everyone in the channels to delete any previous messages with Foreshadow, claiming he was fully cooperating with the FBI.

This was not the first time Sosa and his crew were hit with violent attacks from rival SIM-swapping groups. In early 2022, a video surfaced on a popular cybercrime channel purporting to show attackers hurling a brick through a window at an address that matches the spacious and upscale home of Urban’s parents in Sanford, Fl.

“Brickings” are among the “violence-as-a-service” offerings broadly available on many cybercrime channels. SIM-swapping and adjacent cybercrime channels are replete with job offers for in-person assignments and tasks that can be found if one searches for posts titled, “If you live near,” or “IRL job” — short for “in real life” job.

A number of these classified ads are in service of performing brickings, where someone is hired to visit a specific address and toss a brick through the target’s window. Other typical IRL job offers involve tire slashings and even drive-by shootings.

THE COM

Sosa was known to be a top member of the broader cybercriminal community online known as “The Com,” wherein hackers boast loudly about high-profile exploits and hacks that almost invariably begin with social engineering — tricking people over the phone, email or SMS into giving away credentials that allow remote access to corporate internal networks.

Sosa also was active in a particularly destructive group of accomplished criminal SIM-swappers known as “Star Fraud.” Cyberscoop’s AJ Vicens reported last year that individuals within Star Fraud were likely involved in the high-profile Caesars Entertainment an MGM Resorts extortion attacks.

“ALPHV, an established ransomware-as-a-service operation thought to be based in Russia and linked to attacks on dozens of entities, claimed responsibility for Caesars and MGM attacks in a note posted to its website earlier this month,” Vicens wrote. “Experts had said the attacks were the work of a group tracked variously as UNC 3944 or Scattered Spider, which has been described as an affiliate working with ALPHV made up of people in the United States and Britain who excel at social engineering.”

In February 2023, KrebsOnSecurity published data taken from the Telegram channels for Star Fraud and two other SIM-swapping groups showing these crooks focused on SIM-swapping T-Mobile customers, and that they collectively claimed access to T-Mobile on 100 separate occasions over a 7-month period in 2022.

The SIM-swapping groups were able to switch targeted phone numbers to another device on demand because they constantly phished T-Mobile employees into giving up credentials to employee-only tools. In each of those cases the goal was the same: Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user’s text messages and phone calls to another device.

Allison Nixon, chief research officer at the New York cybersecurity consultancy Unit 221B, said the increasing brazenness of many Com members is a function of how long it has taken federal authorities to go after guys like Sosa.

“These incidents show what happens when it takes too long for cybercriminals to get arrested,” Nixon said. “If governments fail to prioritize this source of threat, violence originating from the Internet will affect regular people.”

NO FIXED ADDRESS

The Daytona Beach News-Journal reports that Urban was arrested Jan. 9 and his trial is scheduled to begin in the trial term starting March 4 in Jacksonville. The publication said the judge overseeing Urban’s case denied bail because the defendant was a strong flight risk.

At Urban’s arraignment, it emerged that he had no fixed address and had been using an alias to stay at an Airbnb. The judge reportedly said that when a search warrant was executed at Urban’s residence, the defendant was downloading programs to delete computer files.

What’s more, the judge explained, despite telling authorities in May that he would not have any more contact with his co-conspirators and would not engage in cryptocurrency transactions, he did so anyway.

Urban entered a plea of not guilty. Urban’s court-appointed attorney said her client would have no comment at this time.

Prosecutors charged Urban with eight counts of wire fraud, one count of conspiracy to commit wire fraud, and five counts of aggravated identity theft. According to the government, if convicted Urban faces up to 20 years in federal prison on each wire fraud charge. He also faces a minimum mandatory penalty of two years in prison for the aggravated identity offenses, which will run consecutive to any other prison sentence imposed.

Canadian Man Stuck in Triangle of E-Commerce Fraud

19 January 2024 at 10:34

A Canadian man who says he’s been falsely charged with orchestrating a complex e-commerce scam is seeking to clear his name. His case appears to involve “triangulation fraud,” which occurs when a consumer purchases something online — from a seller on Amazon or eBay, for example — but the seller doesn’t actually own the item for sale. Instead, the seller purchases the item from an online retailer using stolen payment card data. In this scam, the unwitting buyer pays the scammer and receives what they ordered, and very often the only party left to dispute the transaction is the owner of the stolen payment card.

Triangulation fraud. Image: eBay Enterprise.

Timothy Barker, 56, was until recently a Band Manager at Duncan’s First Nation, a First Nation in northwestern Alberta, Canada. A Band Manager is responsible for overseeing the delivery of all Band programs, including community health services, education, housing, social assistance, and administration.

Barker told KrebsOnSecurity that during the week of March 31, 2023 he and the director of the Band’s daycare program discussed the need to purchase items for the community before the program’s budget expired for the year.

“There was a rush to purchase items on the Fiscal Year 2023 timeline as the year ended on March 31,” Barker recalled.

Barker said he bought seven “Step2 All Around Playtime Patio with Canopy” sets from a seller on Amazon.ca, using his payment card on file to pay nearly $2,000 for the items.

On the morning of April 7, Barker’s Facebook account received several nasty messages from an Ontario woman he’d never met. She demanded to know why he’d hacked her Walmart account and used it to buy things that were being shipped to his residence. Barker shared a follow-up message from the woman, who later apologized for losing her temper.

One of several messages from the Ontario woman whose Walmart account was used to purchase the goods that Barker ordered from Amazon.

“If this is not the person who did this to me, I’m sorry, I’m pissed,” the lady from Ontario said. “This order is being delivered April 14th to the address above. If not you, then someone who has the same name. Now I feel foolish.”

On April 12, 2023, before the Amazon purchases had even arrived at his home, Barker received a call from an investigator with the Royal Canadian Mounted Police (RCMP), who said Barker urgently needed to come down to the local RCMP office for an interview related to “an investigation.” Barker said the officer wouldn’t elaborate at the time on the nature of the investigation, and that he told the officer he was in Halifax for several days but could meet after his return home.

According to Barker, the investigator visited his home anyway the following day and began questioning his wife, asking about his whereabouts, his work, and when he might return home.

On April 14, six boxes arrived to partially fulfill his Amazon order; another box was delayed, and the Amazon.ca seller he’d purchased from said the remaining box was expected to ship the following week. Barker said he was confused because all six boxes came from Walmart instead of Amazon, and the shipping labels had his name and address on them but carried a contact phone number in Mexico.

Three days later, the investigator called again, demanding he submit to an interview.

“He then asked where my wife was and what her name is,” Barker said. “He wanted to know her itinerary for the day. I am now alarmed and frightened — this doesn’t feel right.”

Barker said he inquired with a local attorney about a consultation, but that the RCMP investigator showed up at his house before he could speak to the lawyer. The investigator began taking pictures of the boxes from his Amazon order.

“The [investigator] derisively asked why would anyone order so many play sets?” Barker said. “I started to give the very logical answer that we are helping families improve their children’s home life and learning for toddlers when he cut me off and gave the little speech about giving a statement after my arrest. He finally told me that he believes that I used someone’s credit card in Ontario to purchase the Walmart products.”

Eager to clear his name, Barker said he shared with the police copies of his credit card bills and purchase history at Amazon. But on April 21, the investigator called again to say he was coming to arrest Barker for theft.

“He said that if I was home at five o’clock then he would serve the papers at the house and it would go easy and I wouldn’t have to go to the station,” Barker recalled. “If I wasn’t home, then he would send a search team to locate me and drag me to the station. He said he would kick the door down if I didn’t answer my phone. He said he had every right to break our door down.”

Barker said he briefly conferred with an attorney about how to handle the arrest. Later that evening, the RCMP arrived with five squad cars and six officers.

“I asked if handcuffs were necessary – there is no danger of violence,” Barker said. “I was going to cooperate. His response was to turn me around and cuff me. He walked me outside and stood me beside the car for a full 4 or 5 minutes in full view of all the neighbors.”

Barker believes he and the Ontario woman are both victims of triangulation fraud, and that someone likely hacked the Ontario woman’s Walmart account and added his name and address as a recipient.

But he says he has since lost his job as a result of the arrest, and now he can’t find new employment because he has a criminal record. Barker’s former employer — Duncan’s First Nation — did not respond to requests for comment.

“In Canada, a criminal record is not a record of conviction, it’s a record of charges and that’s why I can’t work now,” Barker said. “Potential employers never find out what the nature of it is, they just find out that I have a criminal arrest record.”

Barker said that right after his arrest, the RCMP called the Ontario woman and told her they’d solved the crime and arrested the perpetrator.

“They even told her my employer had put me on administrative leave,” he said. “Surely, they’re not allowed to do that.”

Contacted by KrebsOnSecurity, the woman whose Walmart account was used to fraudulently purchase the child play sets said she’s not convinced this was a case of triangulation fraud. She declined to elaborate on why she believed this, other than to say the police told her Barker was a bad guy.

“I don’t think triangulation fraud was used in this case,” she said. “My actual Walmart.ca account was hacked and an order was placed on my account, using my credit card. The only thing Mr. Barker did was to order the item to be delivered to his address in Alberta.”

Barker shared with this author all of the documentation he gave to the RCMP, including screenshots of his Amazon.ca account showing that the items in dispute were sold by a seller named “Adavio,” and that the merchant behind this name was based in Turkey.

That Adavio account belongs to a young computer engineering student and “SEO expert” based in Adana, Turkey who did not respond to requests for comment.

Amazon.ca said it conducted an investigation and found that Mr. Barker never filed a complaint about the seller or transaction in question. The company noted that Adavio currently has a feedback rating of 4.5 stars out of 5.

“Amazon works hard to provide customers with a great experience and it’s our commitment to go above and beyond to make things right for customers,” Amazon.ca said in a written statement. “If a customer has an issue with an order, they may flag to Amazon through our Customer Service page.”

Barker said when he went to file a complaint with Amazon last year he could no longer find the Adavio account on the website, and that the site didn’t have a category for the type of complaint he wanted to file.

When he first approached KrebsOnSecurity about his plight last summer, Barker said he didn’t want any media attention to derail the chances of having his day in court, and confronting the RCMP investigator with evidence proving that he was being wrongfully prosecuted and maligned.

But a week before his court date arrived at the end of November 2023, prosecutors announced the charges against him would be stayed, meaning they had no immediate plans to prosecute the case further but that the investigation could still be reopened at some point in the future.

The RCMP declined to comment for this story, other than to confirm they had issued a stay of proceedings in the case.

Barker says the stay has left him in legal limbo — denying him the ability to clear his name, while giving the RCMP a free pass for a botched investigation. He says he has considered suing the investigating officer for defamation, but has been told by his attorney that the bar for success in such cases against the government is extremely high.

“I’m a 56-year-old law-abiding citizen, and I haven’t broken any laws,” Barker said, wondering aloud who would be stupid enough to use someone else’s credit card and have the stolen items shipped directly to their home.

“Their putting a stay on the proceedings without giving any evidence or explanation allows them to cover up bad police work,” he said. “It’s all so stupid.”

Triangulation fraud is hardly a new thing. KrebsOnSecurity first wrote about it from an e-commerce vendor’s perspective in 2015, but the scam predates that story by many years and is now a well-understood problem. The Canadian authorities should either let Mr. Barker have his day in court, or drop the charges altogether.

❌
❌