Attacks/Breaches

6/19/2018
02:26 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Arizona Man Sentenced to Prison for Distributed Denial of Service Attacks Against Emergency Communications System and Other Municipal Websites

An Arizona man was sentenced yesterday in Phoenix, Arizona, for directing distributed denial of service (DDoS) attacks at the computer networks of the City of Madison, Wisconsin, announced Acting Assistant Attorney General John P. Cronan of the Justice Department’s Criminal Division and First Assistant U.S. Attorney Elizabeth A. Strange for the District of Arizona.

Randall Charles Tucker, aka “Bitcoin Baron,” 23, of Apache Junction, Arizona, was sentenced to serve 20 months in prison by U.S. District Judge Douglas L. Rayes of the District of Arizona.  He was also ordered to pay restitution in the amount of  $69,331.56 to the victims of his computer attacks. Tucker pleaded guilty on April 17, 2017 to one count of intentional damage to a protected computer.

According to admissions made in connection with his plea, between March 9 and March 14, 2015, Tucker executed a series of DDoS attacks against various city websites, including Madison, Wisconsin. A DDoS attack is a malicious attack where illegitimate network traffic is used to slow down or altogether crash a computer server, thereby denying service to legitimate users of the server.  In addition to disabling the City of Madison’s website, the attack crippled the city’s Internet-connected emergency communication system, causing delays and outages in the ability of emergency responders to connect to the 911 center and degrading the system used to automatically dispatch the closest unit to a medical, fire, or other emergency. Tucker, referring to himself as the “Bitcoin Baron,” boasted about his attacks via social media.

This case was investigated by FBI’s Milwaukee and Phoenix Field Offices and Arizona’s Department of Public Safety.  Assistant U.S. Attorney James R. Knapp of the District of Arizona and Trial Attorney Laura-Kate Bernstein of the Criminal Division’s Computer Crime and Intellectual Property Section are prosecuting the case.  The U.S. Attorney’s Office for the Western District of Wisconsin also provided substantial assistance in this manner.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Mueller Probe Yields Hacking Indictments for 12 Russian Military Officers
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/13/2018
10 Ways to Protect Protocols That Aren't DNS
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/16/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10869
PUBLISHED: 2018-07-19
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.
CVE-2018-10870
PUBLISHED: 2018-07-19
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.
CVE-2018-12959
PUBLISHED: 2018-07-19
The approveAndCall function of a smart contract implementation for Aditus (ADI), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all contract balances into their account).
CVE-2018-14336
PUBLISHED: 2018-07-19
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.
CVE-2018-10620
PUBLISHED: 2018-07-19
AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code t...