Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

10/3/2013
10:45 AM
50%
50%

Stratfor Hacker: FBI Entrapment Shaped My Case

Hacker Jeremy Hammond asks for leniency before sentencing, citing the role of FBI informant Sabu in his case. How far can the FBI go with suspected computer criminals?

Is the FBI allowed to entrap suspected computer criminals? That question is at the heart of a request for leniency by Jeremy Hammond, who's due to be sentenced on November 15 for hacking private intelligence contractor Stratfor, among other business and government sites.

Hammond, appearing in a Manhattan federal courtroom in May, pleaded guilty to one related count of computer fraud and abuse, as part of a plea agreement. "For each of these hacks, I knew what I was doing was wrong," Hammond told judge Loretta Preska, the Chicago Sun-Times reported. He now faces up to 10 years in jail, and the prospect of paying up to $2.5 million in restitution to Stratfor.

But in advance of his upcoming sentencing by Judge Preska, Hammond's supporters are asking for leniency, noting that Hammond hacked for ethical reasons, rather than to make a profit. They've also accused the FBI of entrapment, referring to tricking someone into committing a crime for the purpose of then arresting them. Hammond, notably, has accused former LulzSec leader turned FBI informant "Sabu" -- real name: Hector Xavier Monsegur -- of inciting participants of the Anonymous Operations (AnonOps) IRC channel, including himself, to hack into a number of systems, including Brazilian government servers for which Sabu reportedly distributed stolen access credentials.

[ Take heed of the security warnings that seem to pop up every day. Read WordPress Attacks: Time To Wake Up. ]

"Sabu was used to build cases against a number of hackers, including myself. What many do not know is that Sabu was also used by his handlers to facilitate the hacking of targets of the government's choosing -- including numerous websites belonging to foreign governments," Hammond said in an August statement.

What proof can Hammond offer? Attorney Margaret Ratner Kunstler, who's a member of Hammond's defense team, told me via email that "all but publicly filed documents are covered by [a] protective order," meaning related evidence has been sealed, at the request of prosecutors. Accordingly, "proof is only in the form of failure of government to deny" Hammond's allegations, she said.

An FBI spokeswoman, reached by phone, declined to comment on Hammond's allegations.

This wouldn't be the first time that the bureau's computer crime investigators have been accused of employing these types of tactics. "The FBI intended to entrap me via Sabu for as long as possible to incriminate my activities at the highest level," said former LulzSec participant Jake Davis last month, in an ongoing Q&A session on the Ask.fm website. Davis, who used the handle "topiary," handled the LulzSec's PR, but didn't take part in any of its actual hacking activities. He was arrested by British police in July 2011.

"One week I told Sabu that I had no intention of involving myself in any more crime -- organized by him -- and that I wanted to switch to helping the activist movement solely through art and writing," said Davis, who's now served related jail time in the United Kingdom and been released. "That same week my home was raided. It's nothing new, we were just another set of pawns in the FBI's strategy."

If that was the FBI's strategy, however, what may surprise is that the bureau wouldn't have broken any laws or investigation guidelines. "Unfortunately, there are numerous cases holding that this type of scenario -- very common in child pornography cases where agents pose as either children or brokers of child pornography -- does not constitute impermissible entrapment," sentencing expert Jeff Ifrah, an attorney who's previously chaired American Bar Association criminal justice and white collar crime committees, told me via email.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
majenkins
50%
50%
majenkins,
User Rank: Apprentice
10/4/2013 | 5:47:56 PM
re: Stratfor Hacker: FBI Entrapment Shaped My Case
Whether there was entrapment or not this time, these were not his first hacking crimes. Of course even if it was entrapment the fact that evidence doesn't exist to prosecute him for the other crimes of course doesn't make it right to falsely convict him in this case but it does seem to achieve a little justice.
Laurianne
50%
50%
Laurianne,
User Rank: Apprentice
10/4/2013 | 6:15:41 PM
re: Stratfor Hacker: FBI Entrapment Shaped My Case
Like John McAfee's recent exploits, Sabu's story still sounds like an unbelievable novel.
GAProgrammer
50%
50%
GAProgrammer,
User Rank: Guru
10/7/2013 | 5:34:12 PM
re: Stratfor Hacker: FBI Entrapment Shaped My Case
Based on his supporter's arguments, if you rob a bank to give money to the less fortunate, you should not be charged. Ludicrous.
OtherJimDonahue
50%
50%
OtherJimDonahue,
User Rank: Apprentice
10/8/2013 | 12:54:40 PM
re: Stratfor Hacker: FBI Entrapment Shaped My Case
While I agree with you ... yeesh, I really wish the government didn't align itself with people like Sabu.
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: George has not accepted that the technology age has come to an end.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-20001
PUBLISHED: 2021-03-07
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
CVE-2020-28466
PUBLISHED: 2021-03-07
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened r...
CVE-2021-27364
PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
CVE-2021-27365
PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length...
CVE-2021-27363
PUBLISHED: 2021-03-07
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system...