Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

AT&T Hackers Have Terrorism Ties, Police Say

FBI aids in arrests in Philippines of four men who allegedly hacked into AT&T customers' PBXs to generate revenue for Saudi-based militant group.

Four people were arrested in the Philippines last week on charges that they hacked into the trunk lines of multiple U.S. telecommunication companies, including AT&T.

According to the Philippine National Police's Criminal Investigation and Detection Group (CIDG), the hackers' activities led to losses of almost $2 million for AT&T alone. The director of the CIDG, Samuel D. Pagdilao Jr., said that the raids, conducted by both CIDG and FBI agents in the country's capital city of Manila, had led to the confiscation of computer and telecommunication equipment that authorities believe was used in the attacks.

The CIDG said it launched its investigation into the hackers after being contacted in March 2011 by the FBI, which had said it found evidence that hack attacks were being launched against AT&T from the Philippines. According to a statement from Gilbert Sosa, police senior superintendent for the CIDG's Anti-Transnational and Cyber Crime Division, the FBI had linked the local hacking group--via bank statements--to a "Saudi-based cell whose activities include financing terrorist activities." The hackers allegedly routed the money directly to the militant group, which then paid the hackers a commission via Philippine banks.

[ Industrial control systems are ripe for attack due to inherent security weaknesses. See: Next DIY Stuxnet Attack Should Worry Utilities. ]

Sosa said that the hackers appeared to be working for a group that was created by Muhammad Zamir, a member of Jemaah Islamiyah, a militant group based in Southeast Asia. While Zamir was arrested in 2007 in Italy by "FBI operatives," Sosa said that the FBI has evidence that Zamir's group--not named, but which it said is based in Saudi Arabia--went on to fund the Mumbai terrorist attacks that occurred Nov. 26, 2008, killing 166 people. (Pakistani authorities have said that the attacks were funded by Lashkar-e-Taiba militants operating from inside Pakistan.)

The FBI declined to describe how the hacks would have generated money. But FBI spokeswoman Jenny Shearer said via phone that the hackers didn't break into trunk lines, but rather targeted the PBXs used by AT&T customers. "I'm not sure if other telephone companies' customers were targeted," she said, noting that the FBI's investigation is ongoing.

According to the Guardian, an unnamed person "familiar with the situation" said that the attacks involved hacking into PBXs, then calling international premium-rate services to generate revenue. Interestingly, that scamming technique is also favored by malware developers.

One of the people who was arrested last week in Manila, Paul Michael Kwan, 29, had previously been arrested by Philippine authorities in 2007, on charges that he was helping to fund groups engaged in terrorist activities as part of what Sosa described as an international crackdown on funding for militant groups.

CIDG director Pagdilao said last week's arrests highlighted the need for the country to pass a Cyber Crime Prevention Bill--currently pending in its legislature--which he said would enable authorities to more proactively pursue cyber criminals operating from inside the country.

Read our report on how to guard your systems from a SQL attack. Download the report now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
progan01
50%
50%
progan01,
User Rank: Apprentice
12/1/2011 | 2:01:39 AM
re: AT&T Hackers Have Terrorism Ties, Police Say
This is sincerely bad news. At the very least it indicates a level of police involvement with AT&T not previously suspected -- and it raises the question of how hard AT&T and the FBI are looking for similar schemes, since this one apparently was caught by accident. Incidentally, this method of raising illicit cash has been used since at least the 1980s if not earlier. Romanian hackers were among the first I know of to use this method of charging international calls through an unrelated third nation. Thirty years is a long time for this tool to be in criminal hands.
AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4147
PUBLISHED: 2019-09-16
IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 158413.
CVE-2019-5481
PUBLISHED: 2019-09-16
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CVE-2019-5482
PUBLISHED: 2019-09-16
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-15741
PUBLISHED: 2019-09-16
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
CVE-2019-16370
PUBLISHED: 2019-09-16
The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an artifact with a different one that has the same SHA-1 message digest, a related issue to CVE-2005-4900.