Pursuit of hackers who stole credit reports of US celebrities, politicians spans continents

Advertisement

Advertise with us

WASHINGTON - The pursuit of hackers who audaciously stole and published credit reports for Michelle Obama, the attorney general, FBI director and other U.S. politicians and celebrities crisscrossed continents and included a San Francisco-based Internet company, Cloudflare, The Associated Press has learned.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 13/03/2013 (4937 days ago), so information in it may no longer be current.

WASHINGTON – The pursuit of hackers who audaciously stole and published credit reports for Michelle Obama, the attorney general, FBI director and other U.S. politicians and celebrities crisscrossed continents and included a San Francisco-based Internet company, Cloudflare, The Associated Press has learned.

The sensational crime caught the attention of Congress and President Barack Obama, who said “we should not be surprised.”

Obama said he could not confirm that the first lady’s credit report was published earlier this week on a Russian website, along with what appeared to be the credit reports of nearly two dozen others, including Republican presidential candidate Mitt Romney, Donald Trump and celebrities Britney Spears, Jay Z, Beyonce and Tiger Woods.

First lady Michelle Obama speaks to the quarterly meeting of member Chief Executive Officers of the Business Roundtable in Washington, Wednesday, March 13, 2013. (AP Photo/Susan Walsh)
First lady Michelle Obama speaks to the quarterly meeting of member Chief Executive Officers of the Business Roundtable in Washington, Wednesday, March 13, 2013. (AP Photo/Susan Walsh)

Perhaps in a show of defiance as the FBI, Secret Service and the Los Angeles Police Department co-ordinated efforts to investigate the security breach, the website added late Wednesday what it said was the credit report of disgraced Pennsylvania football coach Jerry Sandusky.

If accurate as widely suspected, the leaked records put each victim at significant risk of identity theft. Included in the reports are Social Security numbers, dates of birth and a list of previous home addresses. The records also include such personal information as the first lady’s monthly payments on a student loan 10 years ago and that she once held a Banana Republic credit card.

The president said determined hackers are a persistent threat.

“We should not be surprised that if you’ve got hackers who want to dig in and devote a lot of resources, that they can access people’s private information,” Obama told ABC News in an interview aired Wednesday. “It is a big problem.”

Obama added: “It would not shock me if some information among people who presumably have pretty good safeguards against it, still gets out. That’s part of the reason why we’ve got to continually improve what we do and co-ordinate between public and private sectors to make sure that people’s information is safe.”

On Capitol Hill, the chairman of the House Judiciary Committee cited the breach Wednesday at a congressional hearing about the government prosecuting hackers. Rep. Bob Goodlatte, R-Va., said the leaks of financial information was “just the beginning of the problem” when it comes to the vulnerability of U.S. computer networks. Goodlatte said the U.S. has billions of dollars at stake, as foreign hackers try to steal sensitive information from businesses.

“The truth is that all citizens are vulnerable to these kinds of cyberattacks,” Goodlatte said.

A spokesman for one of the largest U.S. credit bureaus, Tim Klein of Equifax, said an initial investigation showed that the hackers accessed the credit bureau’s system by correctly entering personal details about their victims to impersonate them and generate the credit reports.

Representatives for Experian, Equifax and TransUnion have all said they were co-operating with the U.S. criminal investigation being conducted by the FBI and Secret Service.

A retired FBI executive assistant director, Shawn Henry, said he hopes the incident sheds light on the scope of the cybersecurity problem and identity theft in particular, which affects millions of Americans who aren’t famous enough to make headlines.

“There’s a lot of sensitive data available online,” said Henry, the president of CrowdStrike, a security technology company. “People aren’t keeping information in a safe locked behind closed doors. Information being breached and violated is happening every day.”

In San Francisco, Cloudflare operates the directory computers, known as name servers, used behind the scenes to send visitors to the Russian website where the stolen credit reports were being published, according to Internet registration records. Without that service, few Internet users would be able to visit the Russian website or view the stolen credit reports.

A company spokeswoman, Carol Carrubba, told the AP that Cloudflare, which she described as a performance and security company, doesn’t comment on its customers. But Carrubba said: “Even if we delete a customer’s account, the content remains in place, though the site may load more slowly.”

Internet directories on Wednesday continued to identify Cloudflare as directing traffic to the Russian website, although any technical changes could take hours or days to update across the Internet.

Last month, the chief executive at Cloudflare, Matthew Prince, said in a speech that he had been victimized last year by hackers associated with the group UGNazi. They tricked Google into giving them access to his Gmail account, Prince said, and left voicemails taunting him that they had bought his Social Security number from an underground Russian website. Prince said the break-in of his personal email account also allowed the hackers to take over Cloudflare’s corporate email systems.

In his speech, Prince said his company traced the attackers within 24 hours, and the hackers turned out to be among Cloudflare’s customers.

The FBI in San Francisco declined to tell AP whether investigators have contacted Cloudflare to review payments or communications that had been used to set up the service.

The website address uses an Internet suffix originally assigned to the former Soviet Union, and many of the pages feature unflattering pictures of the person featured and taunting messages to them. A counter on the website indicated that it had received more than 500,000 views as of late Wednesday afternoon.

Social Security numbers posted on Jay-Z, Mel Gibson and others matched records in public databases. Social Security numbers are not public records, although they are used to be included in some court filings. Many courts require the information be redacted from filings since the numbers can be used to steal a person’s identity and open credit accounts in their name.

___

Associated Press writers Jason Dearen in San Francisco, Raquel Maria Dillon in Los Angeles and White House Correspondent Julie Pace and writers Ted Bridis and Pete Yost in Washington contributed to this report.

___

Follow Anne Flaherty at https://twitter.com/AnneKFlaherty

Report Error Submit a Tip

More Stories

Klein launches mayoral campaign with pledge to make Winnipeg safest city in Canada

Joyanne Pursaga 2 minute read Preview

Klein launches mayoral campaign with pledge to make Winnipeg safest city in Canada

Joyanne Pursaga 2 minute read 12:47 PM CDT

Mayoral candidate Kevin Klein says he would make Winnipeg the safest city in Canada by the end of his four-year term, if elected.

“Crime is happening all over the city and we have to take steps to address it,” Klein said at his first campaign announcement Friday morning.

He promised to hire 100 to 110 more police officers, which he believes would cost between $9 million and $11 million.

“Our (officer) numbers are way down. We need to fix that now,” he said, not offering a timeline to fulfil that goal.

Read
12:47 PM CDT

Pursuit of hackers who took credit reports expands

Anne Flaherty, The Associated Press 6 minute read Preview

Pursuit of hackers who took credit reports expands

Anne Flaherty, The Associated Press 6 minute read Thursday, Mar. 14, 2013

WASHINGTON - The pursuit of hackers who audaciously stole and published credit reports for Michelle Obama, the attorney general, FBI director and other U.S. politicians and celebrities crisscrossed continents and included a San Francisco-based Internet company, Cloudflare, The Associated Press has learned.

The sensational crime caught the attention of Congress and President Barack Obama, who said "we should not be surprised."

Obama said he could not confirm that the first lady's credit report was published earlier this week on a Russian website, along with what appeared to be the credit reports of nearly two dozen others, including Republican presidential candidate Mitt Romney, Donald Trump and celebrities Britney Spears, Jay Z, Beyonce and Tiger Woods.

Perhaps in a show of defiance as the FBI, Secret Service and the Los Angeles Police Department co-ordinated efforts to investigate the security breach, the website added late Wednesday what it said was the credit report of disgraced Pennsylvania football coach Jerry Sandusky.

Read
Thursday, Mar. 14, 2013

Police officer faces charges of domestic assault

Free Press staff 2 minute read Preview

Police officer faces charges of domestic assault

Free Press staff 2 minute read Yesterday at 4:26 PM CDT

A Winnipeg police officer has been charged after police said he broke into a woman’s home and attacked her.

Police were sent to a home on Wednesday shortly before 10:20 p.m., the Winnipeg Police Service said in a Thursday news release. When officers arrived, they found the man, 20-year member in his 40s, inside a home assaulting the woman, the release said.

The man was taken into custody and the woman was given medical aid.

She told officers the man broke into the home, threatened to kill her and then attacked her.

Read
Yesterday at 4:26 PM CDT

Snowbird replacements ‘extremely manoeuverable, powerful,’ RCAF commander says

Kyle Duggan, The Canadian Press 4 minute read Preview

Snowbird replacements ‘extremely manoeuverable, powerful,’ RCAF commander says

Kyle Duggan, The Canadian Press 4 minute read Updated: 2:00 PM CDT

GATINEAU - The Royal Canadian Air Force welcomed on Thursday the first two of its new trainer aircraft, the CT-157 Siskin II — the same planes that will replace the old Tutor jets flown by the Snowbirds aerial demonstration team.

The turboprop planes will soon be headed to 15 Wing Moose Jaw, where the air force eventually will station 19 of them to serve as its main training fleet.

Acquiring the Siskin II, also known as the Pilatus PC-21, is part of the RCAF's plan to modernize its fleets and overhaul its training.

RCAF Commander Lt.-Gen. Jamie Speiser-Blanchet said the modern aircraft are well suited both to aerial acrobatics and to preparing pilots for the more advanced aircraft the air force is bringing online.

Read
Updated: 2:00 PM CDT

Safety review calls for improved security at Siloam Mission

Scott Billeck 5 minute read Preview

Safety review calls for improved security at Siloam Mission

Scott Billeck 5 minute read Updated: 10:32 AM CDT

A safety review of Winnipeg’s largest homeless shelter is recommending improvements to security for staff, volunteers and community members after what its leadership acknowledged has been a challenging year.

The Siloam Mission report, which has not been made public, was discussed during a town hall Thursday night at the Millennium Centre on Main Street, where shelter leaders laid out what they described as a road forward for the organization.

Interim CEO Lisa Cefali, who was brought in at the end of May following the departure of Sonia Prevost-Derbecker after three tumultuous months in the job, said she could see the toll turmoil had taken when she arrived May 29.

Employees alleged Prevost-Derbecker made derogatory remarks about Indigenous people, people struggling with substance use and the downtown neighbourhood surrounding the mission’s Princess Street headquarters.

Read
Updated: 10:32 AM CDT

A quick look at where provinces and territories stand on time changes

The Canadian Press 2 minute read Preview

A quick look at where provinces and territories stand on time changes

The Canadian Press 2 minute read Updated: 6:28 AM CDT

WINNIPEG - Manitoba's government said Thursday the province will be sticking with daylight time year-round, making it the latest jurisdiction to move away from twice-annual time changes. Here's a look at where things stand across Canada:

British Columbia said in March that it was moving to permanent Pacific daylight time. The change also means that parts of northeastern B.C., which have been on mountain standard time year round, are now in alignment with the rest of the province.

Alberta also switched to permanent daylight time this year in what it calls Alberta time. The change means it now has the same time as Saskatchewan year round.

Saskatchewan has been on permanent central standard time since 1966.

Read
Updated: 6:28 AM CDT