Live data from Hacker News

RaidForums gets raided, alleged admin arrested

krebsonsecurity.com

111–120 of 197 posts

Re: RaidForums gets raided, alleged admin arrested

#111
post #2

"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…

Sounds like he was already on their radar if they were able/desired to obtain a warrant to search his devices.

So they even need a warrant? I was under the impression that no US constitutional protections apply to foreigners, and when entering the country you need a visa or equivalent preauthorisation, and there you certainly agree they can do whatever they want with you.

Re: RaidForums gets raided, alleged admin arrested

#112
post #66

> an extremely popular English-language cybercrime forum that sold access to more than 10 billion consumer records stolen in some of the world’s largest data breaches since 2015. The DOJ also charged the alleged administrator of RaidForums — 21-year-old Diogo Santos Coelho, of Portugal — with six criminal counts, including conspiracy, access device fraud and aggravated identity theft. Some thing doesn’t add up

What doesn't add up?

This admin would have been 14 when this was started. Why now and why him?

Re: RaidForums gets raided, alleged admin arrested

#113
This is pretty funny, imo:

---

Not all of those undercover buys went as planned. One incident described in an affidavit by prosecutors (PDF) appears related to the sale of tens of millions of consumer records stolen last year from T-Mobile, although the government refers to the victim only as a major telecommunications company and wireless network operator in the United States.

[...]

The government says the victim firm hired a third-party to purchase the database and prevent it from being sold to cybercriminals. That third-party ultimately paid approximately $200,000 worth of bitcoin to the seller, with the agreement that the data would be destroyed after sale. “However, it appears the co-conspirators continued to attempt to sell the databases after the third-party’s purchase,” the affidavit alleges.

---

T-mobile paid 200k and got precisely nothing from it.

Re: RaidForums gets raided, alleged admin arrested

#114
post #105

Earlier quoted context omitted.

License plates, CCTV, purchase records, public transport etc. There are so many ways in which you could be tracked that the safe assumption is that you won't be able to avoid it.

Which brings you back to asking why half don't get solved, I suppose.

In most countries: priorities.

Re: RaidForums gets raided, alleged admin arrested

#115
post #113

This is pretty funny, imo: --- Not all of those undercover buys went as planned. One incident described in an affidavit by prosecutors (PDF) appears related to the sale of tens of millions of consumer records stolen last year from T-Mobile, although the government refers to the victim only as a major telecommunications company and wireless network operator in the United States. [...] The government says the victim fi…

With the added benefit of poisoning the well for the next hacker who tries to sell the data back to the company.

Re: RaidForums gets raided, alleged admin arrested

#116

Funny how there are so many logos on the seizure notice . they should have put a McDonald's logo too or maybe a service where a company can pay to have their logo put on there given how much traffic the sized domain probably got

including an anime girl in skimpy clothing

Re: RaidForums gets raided, alleged admin arrested

#118

Earlier quoted context omitted.

It's not easy: that's why he got caught. And he got caught primarily because he started a criminal enterprise, which makes him not the sharpest tool in the shed, if he would have been he would have turned his talents to something both more lucrative and legal.

in a poor country where the average person makes < 1000 EUR per month, how do you come up with 0.5M at 21?

You probably won't. But 0.5 M at 21 through illegal means is easy: just rob a money transport and call it a day, after all: who cares if you are going to be a criminal anyway.

How you are going to legally come up with money is the question and there are no real shortcuts there other than to get lucky. But with his skills properly applied he would have a much better chance at a nice life than he has today. Money doesn't really matter much if you're in a jail cell.

Re: RaidForums gets raided, alleged admin arrested

#119
post #100

Earlier quoted context omitted.

> might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords I suspect that you are wrong about this. https://en.wikipedia.org/wiki/Accessory_(legal_term) "Count 1: Conspiracy to Commit Access Device Fraud (18 U.S.C. §§ 1029(b)(2)and 3559(g)(1)) Count 2: Access Device Fraud — Using or Trafficking in an Unauthorized Access Device (1…

Also important to keep in mind he ( most likely ) wasn’t aware of US law. Not sure how Portugal classifies businesses such as these, but we know how e.g. Russia differs in this regard.

Yes, true, but that's exactly why if you aren't aware of something or unsure of something you play it safe. The number of people that got busted like this is large enough that I'm 100% sure that he was aware that this wasn't a legal operation, in fact he went to some length to hide his identity, which shows at least minimal awareness of this.

Re: RaidForums gets raided, alleged admin arrested

#120
post #68
post #3

Earlier quoted context omitted.

Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…

dude, opsec is really really hard, the slightest mistake and it's over.

It's only that hard if the person in question is dumb enough to be using a pseudonym instead of opting for anonymity, since having a name opens up your attack surface and chance to fail. Hosting a site or some kind of infrastructure that you have to actively interface with also counts towards this.
Post reply on HN