Attacks/Breaches

Feds Bust 'Farmer's Market' For Online Drugs

Eight people arrested on charges of running The Farmer's Market, an online bazaar offering a range of narcotics, including LSD and marijuana, to customers in 34 countries.

International law enforcement agencies Monday arrested eight people for allegedly operating an online marketplace for illegal narcotics. According to authorities, the online bazaar known as "The Farmer's Market" had sold a range of substances--including liquid LSD, MDMA (ecstasy), fentanyl, mescaline, ketamine, and "high-end marijuana"--to at least 3,000 customers in all 50 states, as well as 34 countries.

A 66-page federal indictment, unsealed Monday, alleged that the marketplace had processed more than 5,000 drug orders between January, 2007 and October, 2009, bringing in gross profits of $1 million. The money was allegedly collected using PayPal, Western Union, I-Golder, and Pecunix, as well as via cash. According to the indictment, the eight defendants "screened all sources of supply and guaranteed delivery of the illegal drugs," and handled all communications between buyers and sellers, in return receiving a commission based on the total value of each order.

The two accused ringleaders of the drug marketplace are Dutchman Marc Willems, 42, who was arrested at his home by police in the Netherlands, and American Michael Evron, 42, who was arrested by police in Columbia as he attempted to return to his home in Argentina. According to the indictment, both men functioned as "organizer, supervisor, and manager" for The Farmer's Market.

The other six defendants in the case--Jonathan Colbeck (51), Brian Colbeck (47), Ryan Rawls (31), Jonathan Dugan (27), George Matzek (20), and Charles Bigras (37)--were arrested at their respective homes in Iowa, Michigan, Georgia, New York, New Jersey, and Florida.

All of the defendants have been charged with money laundering, which carries a maximum prison sentence of 20 years, and conspiracy to distribute controlled substances, for which they could face life imprisonment. Alleged ringleaders Willems and Evron, meanwhile, were also charged with "participating in a continuing criminal enterprise," which carries a minimum sentence of 20 years, and a maximum of life imprisonment. The two men--as well as Rawls and the two Colbecks--were also charged with distributing LSD, which carries a maximum sentence of life imprisonment.

Although not named in the indictment, seven other people--two in the Netherlands, two in New Hampshire, and one each in Atlanta, New Jersey, and Pennsylvania--were also arrested Monday as part of the investigation. "During the course of the arrests made in this case, federal agents and local law enforcement officers also seized substances identified as hashish, LSD, and MDMA, as well as an indoor psychotropic mushroom grow, and three indoor marijuana grows," according to a statement released Monday by United States Attorney Andre Birotte Jr., whose office is handling the prosecution of the case.

As part of the investigation, dubbed Operation Adam Bomb--Adamflowers was the previous name of The Farmer's Market--investigators said they managed to infiltrate the marketplace, and an undercover agent successfully purchased 30 grams of LSD for $2,160. While authorities didn't detail how they'd infiltrated the market and traced related payment transactions, according to the indictment, "the operators initially used Hushmail for all communications and orders." Furthermore, the indictment cited an email sent to Willems from one of the defendants, which asserted that Canada-based Hushmail--an encrypted email service--would never share their communications with law enforcement authorities.

But as noted by Wired, such an assertion was false. Indeed, the indictment is filled with references to discussions made by defendants "using coded language in an email communication," suggesting that authorities obtained plaintext copies of the encrypted messages, presumably from Hushmail itself.

Perhaps mindful of the security downsides of Hushmail--or an email-based fulfillment model--around January 2010, the defendants allegedly moved Adamflowers off of Hushmail and onto the Tor anonymizing network. According to the indictment, emails from the defendants to Adamflowers users detailed how the new Tor-based site, rechristened as The Farmer's Market, would offer improved security, inventory management, menus for controlled substances for sale, and a consolidated payments system that would allow a customer to pay once for goods ordered from multiple vendors.

Based on the indictment, The Farmer's Market functioned in a similar manner to Silk Road, a Tor-based marketplace for such drugs as cocaine, heroin, and ecstasy, which drew Congressional attention last year after being profiled by Gawker, as well as for its acceptance of BitCoins as a payment method.

High-profile breaches against cloud-based services have forced tougher security and closer scrutiny of what to put in the cloud. In our Dark Side Of The Cloud report, we explain the risks. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15583
PUBLISHED: 2019-03-25
Cross-Site Scripting (XSS) vulnerability in point_list.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.
CVE-2017-7340
PUBLISHED: 2019-03-25
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.
CVE-2014-9187
PUBLISHED: 2019-03-25
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could lead to possible remote code execution or denial of service. Honeywell strongly encourages and recomme...
CVE-2014-9189
PUBLISHED: 2019-03-25
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that could lead to possible remote code execution, dynamic memory corruption, or denial of service. Honeywell...
CVE-2019-10044
PUBLISHED: 2019-03-25
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters e...