Attacks/Breaches
10/15/2012
11:57 AM
Connect Directly
RSS
E-Mail
50%
50%

LulzSec Attacker Pleads Guilty To Sony Pictures Hack

Defendant agrees to pay restitution toward Sony's $600,000 data breach cleanup costs.

Alleged LulzSec hacker Raynaldo Rivera, 20, has pleaded guilty to one charge against him relating to an attack against the website of Sony Pictures Entertainment. According to authorities, Rivera operated online using the monikers "neuron," "royal," and "wildicv," and was part of the hacktivist group known as Lulz Security, or LulzSec.

The FBI arrested Rivera in August 2012, after a federal grand jury handed down a two-count indictment against him the same month. The indictment charged Rivera with conspiracy and unauthorized impairment of a protected computer. Both charges carry a maximum penalty of 15 years in jail.

In a plea agreement that he signed October 4, 2012, Rivera agreed to plead guilty to the charge of conspiracy, "with the object of the conspiracy being to intentionally cause damage without authorization to a protected computer," which involved a SQL injection attack against the Sony Pictures website, as well as the public release of hundreds of thousands of Sony customers' usernames and passwords.

[ Learn more about How Cybercriminals Choose Their Targets. ]

As part of the plea agreement, the U.S. Attorneys' Office agreed to move to dismiss the unauthorized impairment of a protected computer charge against Rivera, provided he abides by the terms of the agreement. As part of the plea deal, Rivera also acknowledged that he "will be required to pay full restitution to the victim(s) of the offense to which [he] is pleading guilty." Rivera will also face a maximum of 5 years' imprisonment, a three-year supervised release, and a fine of $250,000 "or twice the gross gain or gross loss resulting from the offense, whichever is greatest," according to court documents. As part of the plea bargain, however, the U.S. Attorneys' Office agreed to argue for a shorter jail sentence, provided Rivera takes responsibility for the conspiracy offense.

The ultimate amount of money that Rivera must repay could be substantial. According to court documents, "Sony Pictures suffered losses of approximately $605,663.67 during the one-year period beginning on approximately May 27, 2011, including to hire (sic) computer forensic firms, to staff call centers, and to provide credit monitoring services for individuals whose personal identifying information was compromised."

How was the attack executed? According to court documents, Rivera registered for a proxy service on or about May 23, 2011, "to attempt to hide his true Internet Protocol or 'IP' address from law enforcement while defendant engaged in criminal activity as part of LulzSec."

Then, between about May 27, 2011, and June 2, 2011, according to court documents, Rivera "knowingly caused the transmission of programs, information, codes, and commands, specifically, commands to execute a SQL injection attack against the computer systems of Sony Pictures," which also involved him "stealing confidential data contained on such systems, including personal identifying information for thousands of individuals."

After the attack, Rivera then "provided to members of LulzSec confidential information he had stolen from Sony Pictures' computer systems via the SQL injection attack." The official LulzSec Twitter feed, as well as the lulzsecurity.com website, were also used to publicize the attack, and provide links to the stolen Sony data. According to court documents, "from approximately late May through early June 2011, [Rivera] knowingly combined, conspired, and agreed with other members of LulzSec, including 'sabu,' 'topiary,' 't- flow,' 'kayla,' 'recursion,' 'pwnsauce,' 'joepie,' 'trollpoll,' and 'm_nerva,' to knowingly cause the transmission of codes and commands to the computer systems of Sony Pictures."

According to a Pastebin post uploaded at the same time by LulzSec, in which the group claimed credit for the Sony Pictures website attack, its members claimed to have obtained one million Sony website users' passwords, which had been stored in unencrypted format. "From a single injection, we accessed everything," according to the LulzSec statement. But it said that there had only been time to post 150,000 of the stolen usernames and passwords to the LulzSec website.

Unbeknownst to the LulzSec participants, the group's leader, Sabu, was then busted by two FBI agents on June 7, 2011. Hector Xavier Monsegur, 28, a.k.a. Sabu, immediately turned informer, working with authorities to gather evidence against LulzSec and Anonymous participants, as well as to help identify and patch a number of vulnerabilities in businesses' systems.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
10/16/2012 | 2:43:47 PM
re: LulzSec Attacker Pleads Guilty To Sony Pictures Hack
So he gets a large fine and possible jail time with supervised released? How much money if any did Rivera make fro the information he gained buy attacking Sony pictures. If he did not profit at all from the attack then what exactly was the purpose of the attack? So I didn't catch it or not did Rivera turn informer also?

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-0334
Published: 2014-10-31
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

CVE-2014-2334
Published: 2014-10-31
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.

CVE-2014-2335
Published: 2014-10-31
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.

CVE-2014-2336
Published: 2014-10-31
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2334 and CVE-2014-2335.

CVE-2014-3366
Published: 2014-10-31
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.