Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

11/21/2017
03:34 PM
50%
50%

Iranian Nation-State Hacker Indicted for HBO Hack, Extortion

'Winter is coming,' DoJ official says of overseas hackers such as the alleged HBO hacker who steal intellectual property from the US.

The US Department of Justice today unsealed an indictment charging an Iranian national with a cyberattack earlier this year against HBO and using the stolen content for $6 million worth of Bitcoin in an extortion scheme.

Iranian resident Behzad Mesri, 29, aka "Skote Vahshat," has not been arrested by US authorities. According to the indictment says Mesri - who had previously performed hacking for the Iranian military - stole scripts, plot summaries, and other proprietary program information from HBO and leaked some of stolen HBO content online, including information on upcoming episodes of "Game of Thrones" and other programs. He also stole emails from at least one HBO employee, financial files, and online credentials for HBO social media accounts.

"Mesri now stands charged with federal crimes, and although not arrested today, he will forever have to look over his shoulder until he is made to face justice.  American ingenuity and creativity is to be cultivated and celebrated -- not hacked, stolen, and held for ransom.  For hackers who test our resolve in protecting our intellectual property -- even those hiding behind keyboards in countries far away -- eventually, winter will come," said Acting Manhatten US Attorney Joon H. Kim.

Among the charges Mesri faces are wire fraud, hacking, aggravated identity theft, and extortion-related activity. Read more on the indictment here.

 

 

 

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Gorilla Hunter
50%
50%
Gorilla Hunter,
User Rank: Strategist
11/28/2017 | 3:09:59 PM
Re: Why not arrested?
He is in Iran, and an issuing an arrest warrent will just be a waste of time. Iran does not have an extradition treaty with the US. There is nothing that can be done as long as he is in Iran.
Gorilla Hunter
100%
0%
Gorilla Hunter,
User Rank: Strategist
11/28/2017 | 3:08:00 PM
Re: Justice?
He hasn't been arrested becasue he is in Iran and they do not extradite to the US, aka the Great Satan. As long as he stays there, he will never face any legal action. 
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
11/28/2017 | 2:21:22 PM
Re: Critical Data?
i REALLY have to agree here ---- any data breach IS serious and if HBO had financial data hacked, well there goes that one.,  THAT is the critical feature  of course --- $ always matter.  So if I appeared to be a bit off the mark here, apologies to one and all.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:09:00 AM
Re: Critical Data?
"if we are talking scripts and Hollywood content?"

I see, this is quite costly, also reputation, it is similar to Sony hack I would say.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:07:18 AM
Re: Critical Data?
"Yes it is sad to see a hack and there may be some financial data there"

True, this stolen episodes will cost HPO a lot I would say.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:05:51 AM
Re: Critical Data?
" I have real worries but HBO"

That makes sense, at the same time this shows hackers capabilities to cause damage, it may very well be other things next time.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:04:08 AM
Re: Justice?
"Forever looking over their should"

I see. They may not even care about it if there is no arrest warranted.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/28/2017 | 11:03:02 AM
Why not arrested?
 

I am wondering why do not arrest him, they do not have enough evidence maybe?
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
11/27/2017 | 12:41:54 PM
Critical Data?
If we are talking national security, medical data, credit card info and such --- or WOPR for that sake - then I have real worries but HBO???  Yes it is sad to see a hack and there may be some financial data there but .... if we are talking scripts and Hollywood content?  Really - we have much larger worries in security than HBO. 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
11/22/2017 | 11:30:13 AM
Justice?
So if this individual has yet to be arrested by US authorities what is their current status? "Forever looking over their should", seems to me to be less of a victory of justice then what the article implies.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19589
PUBLISHED: 2019-12-05
The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives.
CVE-2019-19597
PUBLISHED: 2019-12-05
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.
CVE-2019-19598
PUBLISHED: 2019-12-05
D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used to determine the time when the user sent the request. If this value is equal to t...
CVE-2019-19596
PUBLISHED: 2019-12-05
GitBook through 2.6.9 allows XSS via a local .md file.
CVE-2019-19590
PUBLISHED: 2019-12-05
In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free. This allows remote at...