Apple and Meta handed over data to hackers pretending to be police
Hackers got into law enforcement emails and requested user data use Emergency Data Requests (EDR).
This new report comes not 24 hours after KrebsOnSecurity reported that hackers, like LAPSUS$ who recently hacked Nvidia, Microsoft, and others, are pretending to be law enforcement for the purposes of data gathering.
First, they hack into an email account owned by law enforcement. Then they start using that account to ask for specific data, in accordance with existing legal pathways.
The normal process for law enforcement officers is to get a warrant or subpoena for specific data. This requires a judge to sign off on.
The hackers circumvent this by using Emergency Data Requests (EDR), which don’t need warrants. Often the requests come with warnings of implicit threats of violence by the users.
The companies handed over user data to the hackers in 2021
It looks like both Apple and Meta complied with fraudulent EDRs in mid-2021. The user data handed over had home addresses, phone numbers, and IP addresses. The data was probably then used for financial fraud.
Snap Inc, Snapchat’s parent company, was also given falsified EDRs. But it’s not clear if they complied and sent user data to the hackers.
READ MORE: Hackers reportedly hacked the DEA
Cybersecurity researchers are reasonably sure that the hackers are the same underage hackers behind the LAPSUS$ group, which recently breached Nvidia, Microsoft, Samsung, and more.
The real issue here is that law enforcement is still using email to request customer data. There needs to be a way of digitally signing those requests so that impersonators can’t get access.
The Digital Authenticity for Court Orders Act would require digital signing. But, it still needs to get passed.
- Apple says it will no longer repair stolen iPhones at Apple Stores
- Yandex, Russia’s Google, is secretly sending your data to Russia
- Hackers stole $34 million from Crypto.com
- Surprise! The CIA has a secret stash full of data on Americans