Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

11/21/2017
03:34 PM
50%
50%

Iranian Nation-State Hacker Indicted for HBO Hack, Extortion

'Winter is coming,' DoJ official says of overseas hackers such as the alleged HBO hacker who steal intellectual property from the US.

The US Department of Justice today unsealed an indictment charging an Iranian national with a cyberattack earlier this year against HBO and using the stolen content for $6 million worth of Bitcoin in an extortion scheme.

Iranian resident Behzad Mesri, 29, aka "Skote Vahshat," has not been arrested by US authorities. According to the indictment says Mesri - who had previously performed hacking for the Iranian military - stole scripts, plot summaries, and other proprietary program information from HBO and leaked some of stolen HBO content online, including information on upcoming episodes of "Game of Thrones" and other programs. He also stole emails from at least one HBO employee, financial files, and online credentials for HBO social media accounts.

"Mesri now stands charged with federal crimes, and although not arrested today, he will forever have to look over his shoulder until he is made to face justice.  American ingenuity and creativity is to be cultivated and celebrated -- not hacked, stolen, and held for ransom.  For hackers who test our resolve in protecting our intellectual property -- even those hiding behind keyboards in countries far away -- eventually, winter will come," said Acting Manhatten US Attorney Joon H. Kim.

Among the charges Mesri faces are wire fraud, hacking, aggravated identity theft, and extortion-related activity. Read more on the indictment here.

 

 

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Gorilla Hunter
50%
50%
Gorilla Hunter,
User Rank: Strategist
11/28/2017 | 3:09:59 PM
Re: Why not arrested?
He is in Iran, and an issuing an arrest warrent will just be a waste of time. Iran does not have an extradition treaty with the US. There is nothing that can be done as long as he is in Iran.
Gorilla Hunter
100%
0%
Gorilla Hunter,
User Rank: Strategist
11/28/2017 | 3:08:00 PM
Re: Justice?
He hasn't been arrested becasue he is in Iran and they do not extradite to the US, aka the Great Satan. As long as he stays there, he will never face any legal action. 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
11/28/2017 | 2:21:22 PM
Re: Critical Data?
i REALLY have to agree here ---- any data breach IS serious and if HBO had financial data hacked, well there goes that one.,  THAT is the critical feature  of course --- $ always matter.  So if I appeared to be a bit off the mark here, apologies to one and all.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:09:00 AM
Re: Critical Data?
"if we are talking scripts and Hollywood content?"

I see, this is quite costly, also reputation, it is similar to Sony hack I would say.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:07:18 AM
Re: Critical Data?
"Yes it is sad to see a hack and there may be some financial data there"

True, this stolen episodes will cost HPO a lot I would say.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:05:51 AM
Re: Critical Data?
" I have real worries but HBO"

That makes sense, at the same time this shows hackers capabilities to cause damage, it may very well be other things next time.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:04:08 AM
Re: Justice?
"Forever looking over their should"

I see. They may not even care about it if there is no arrest warranted.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:03:02 AM
Why not arrested?
 

I am wondering why do not arrest him, they do not have enough evidence maybe?
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
11/27/2017 | 12:41:54 PM
Critical Data?
If we are talking national security, medical data, credit card info and such --- or WOPR for that sake - then I have real worries but HBO???  Yes it is sad to see a hack and there may be some financial data there but .... if we are talking scripts and Hollywood content?  Really - we have much larger worries in security than HBO. 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
11/22/2017 | 11:30:13 AM
Justice?
So if this individual has yet to be arrested by US authorities what is their current status? "Forever looking over their should", seems to me to be less of a victory of justice then what the article implies.
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.
CVE-2019-18197
PUBLISHED: 2019-10-18
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclo...
CVE-2019-4409
PUBLISHED: 2019-10-18
HCL Traveler versions 9.x and earlier are susceptible to cross-site scripting attacks. On the Problem Report page of the Traveler servlet pages, there is a field to specify a file attachment to provide additional problem details. An invalid file name returns an error message that includes the entere...