Live data from Hacker News

RaidForums gets raided, alleged admin arrested

krebsonsecurity.com

11–20 of 197 posts

Re: RaidForums gets raided, alleged admin arrested

#11
post #3
post #2

"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…

Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…

I imagine a lot of people think that just because they've used a WHOIS anonymization service through their registrar, domain registration isn't traceable back to their account. On the contrary, registrars make this incredibly straightforward for law enforcement to do: for instance, see https://www.godaddy.com/legal/agreements/subpoena-policy. It's a remarkably silly way to get busted.

Re: RaidForums gets raided, alleged admin arrested

#13

I wish the DOJ had a better designer for their domain seizure graphics.

Idea for a HN contest: design a better DOJ domain seizure graphic. Bonus points for features like "enter personal identifying information here to be notified when your favorite illegal site is back online".

...although I guess they did that last part for a while before they changed the graphic.

Re: RaidForums gets raided, alleged admin arrested

#14
post #2

"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…

I think that's because these people are on the business side of exploits, not the technical side. So really the most important quality to have is a lack of scruples, not any kind of insane technical talent which might inform proper infosec.

Re: RaidForums gets raided, alleged admin arrested

#15
post #3
post #2

"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…

Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…

I'm not so sure about it. Did you listen to the interview of Lex Fridman with Brett Johnson? He seems like an intelligent person who could easily get an infosec job and be extremely good at it from UX/social engineering point of view, but he was socialized from being a kid to disregard authority and steal from other people in every possible way.

I'm sure he wouldn't let Coinbase get away with SMS 2nd factor authentication, something I can never forgive a company to do when there's big money on the line.

Re: RaidForums gets raided, alleged admin arrested

#18

Earlier quoted context omitted.

Sounds like he was already on their radar if they were able/desired to obtain a warrant to search his devices.

...or even just spent the time to do it. But, not too surprising that they don't want to divulge everything that led them to him.

According to another article they arrested / detained several other people during this bust. I am guessing an inside agent got them to meet up. Only Coelho was stupid enough to have his devices unlocked / easily scoured. Using his admin email didn't help. Who even does that? Even my 75 year old mom knew to use her trash email for signing up for crap.

Re: RaidForums gets raided, alleged admin arrested

#19
post #2

"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…

This guy was under the impression that what he was doing wasn’t illegal.

IANAL but the fact that he is being charged with access device fraud might suggest that DOJ had to engage in some mental gymnastics in order to charge this. E: I’ll take that back since I actually read the indictment now, besides the usual raidforums fare he was also selling credit card data which would very much tend to attract access device fraud charges.

Re: RaidForums gets raided, alleged admin arrested

#20

I wish the DOJ had a better designer for their domain seizure graphics.

It's meant to be as garish as possible. It's the modern day equivalent of a branding iron. You got pwned!

Actually, you're spot on. They started doing these style of splash pages a few years after hacking groups did.
Post reply on HN