Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Feds Bust 'Farmer's Market' For Online Drugs

Eight people arrested on charges of running The Farmer's Market, an online bazaar offering a range of narcotics, including LSD and marijuana, to customers in 34 countries.

International law enforcement agencies Monday arrested eight people for allegedly operating an online marketplace for illegal narcotics. According to authorities, the online bazaar known as "The Farmer's Market" had sold a range of substances--including liquid LSD, MDMA (ecstasy), fentanyl, mescaline, ketamine, and "high-end marijuana"--to at least 3,000 customers in all 50 states, as well as 34 countries.

A 66-page federal indictment, unsealed Monday, alleged that the marketplace had processed more than 5,000 drug orders between January, 2007 and October, 2009, bringing in gross profits of $1 million. The money was allegedly collected using PayPal, Western Union, I-Golder, and Pecunix, as well as via cash. According to the indictment, the eight defendants "screened all sources of supply and guaranteed delivery of the illegal drugs," and handled all communications between buyers and sellers, in return receiving a commission based on the total value of each order.

The two accused ringleaders of the drug marketplace are Dutchman Marc Willems, 42, who was arrested at his home by police in the Netherlands, and American Michael Evron, 42, who was arrested by police in Columbia as he attempted to return to his home in Argentina. According to the indictment, both men functioned as "organizer, supervisor, and manager" for The Farmer's Market.

The other six defendants in the case--Jonathan Colbeck (51), Brian Colbeck (47), Ryan Rawls (31), Jonathan Dugan (27), George Matzek (20), and Charles Bigras (37)--were arrested at their respective homes in Iowa, Michigan, Georgia, New York, New Jersey, and Florida.

All of the defendants have been charged with money laundering, which carries a maximum prison sentence of 20 years, and conspiracy to distribute controlled substances, for which they could face life imprisonment. Alleged ringleaders Willems and Evron, meanwhile, were also charged with "participating in a continuing criminal enterprise," which carries a minimum sentence of 20 years, and a maximum of life imprisonment. The two men--as well as Rawls and the two Colbecks--were also charged with distributing LSD, which carries a maximum sentence of life imprisonment.

Although not named in the indictment, seven other people--two in the Netherlands, two in New Hampshire, and one each in Atlanta, New Jersey, and Pennsylvania--were also arrested Monday as part of the investigation. "During the course of the arrests made in this case, federal agents and local law enforcement officers also seized substances identified as hashish, LSD, and MDMA, as well as an indoor psychotropic mushroom grow, and three indoor marijuana grows," according to a statement released Monday by United States Attorney Andre Birotte Jr., whose office is handling the prosecution of the case.

As part of the investigation, dubbed Operation Adam Bomb--Adamflowers was the previous name of The Farmer's Market--investigators said they managed to infiltrate the marketplace, and an undercover agent successfully purchased 30 grams of LSD for $2,160. While authorities didn't detail how they'd infiltrated the market and traced related payment transactions, according to the indictment, "the operators initially used Hushmail for all communications and orders." Furthermore, the indictment cited an email sent to Willems from one of the defendants, which asserted that Canada-based Hushmail--an encrypted email service--would never share their communications with law enforcement authorities.

But as noted by Wired, such an assertion was false. Indeed, the indictment is filled with references to discussions made by defendants "using coded language in an email communication," suggesting that authorities obtained plaintext copies of the encrypted messages, presumably from Hushmail itself.

Perhaps mindful of the security downsides of Hushmail--or an email-based fulfillment model--around January 2010, the defendants allegedly moved Adamflowers off of Hushmail and onto the Tor anonymizing network. According to the indictment, emails from the defendants to Adamflowers users detailed how the new Tor-based site, rechristened as The Farmer's Market, would offer improved security, inventory management, menus for controlled substances for sale, and a consolidated payments system that would allow a customer to pay once for goods ordered from multiple vendors.

Based on the indictment, The Farmer's Market functioned in a similar manner to Silk Road, a Tor-based marketplace for such drugs as cocaine, heroin, and ecstasy, which drew Congressional attention last year after being profiled by Gawker, as well as for its acceptance of BitCoins as a payment method.

High-profile breaches against cloud-based services have forced tougher security and closer scrutiny of what to put in the cloud. In our Dark Side Of The Cloud report, we explain the risks. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32615
PUBLISHED: 2021-05-13
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CVE-2021-33026
PUBLISHED: 2021-05-13
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the ca...
CVE-2021-31876
PUBLISHED: 2021-05-13
Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with ...
CVE-2019-10062
PUBLISHED: 2021-05-13
The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attri...
CVE-2020-23995
PUBLISHED: 2021-05-13
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.