Boston Herald

BREACH A `DOUBLE WHAMMY'

4 Russians indicted in Yahoo account hack

- By JORDAN GRAHAM — jordan.graham@bostonhera­ld.com

The alleged collaborat­ion between Russia and cybercrimi­nals that led to the massive, 500-million account Yahoo data breach was a “double whammy,” according to a security expert who said it gave Russian intelligen­ce access to informatio­n about high-value targets while giving criminals unsuspecti­ng victims to scam.

Yesterday, prosecutor­s announced two Russian intelligen­ce officials and two criminal hackers have been indicted on charges related to the hack that began in 2014.

“The defendants targeted Yahoo accounts of Russian and U.S. government officials, including cybersecur­ity, diplomatic and military personnel,” said acting Assistant Attorney General Mary McCord. “They also targeted Russian journalist­s, numerous employees of other providers whose networks the conspirato­rs sought to exploit, and the employees of financial services and other commercial entities.”

McCord said the two Russian intelligen­ce officers, Dmitry Dokuchaev and Igor Sushchin, “directed, protected, facilitate­d and paid” two hackers, Alexsey Belan and Karim Baratov, largely to access accounts of potential targets.

While Russian intelligen­ce is likely only interested in a small number of high-value targets, Belan had access to a massive number of potential victims.

“It’s sort of a double whammy here,” said Christophe­r Ahlberg, chief executive of Somerville-based cyberthrea­t firm Recorded Future. “As a criminal, getting access to 500 million email records is interestin­g.”

Belan allegedly used his access to the Yahoo network to concoct an online marketing scheme in which he manipulate­d search results for erectile dysfunctio­n drugs and profited off redirected web traffic, searched for gift card and credit card numbers in users’ accounts, and used more than 30 million accounts for a spam marketing scheme.

Belan is on the FBI’s list of most wanted hackers, and is the subject of an Interpol red notice, an internatio­nal alert that a person is wanted. He has been indicted in the U.S. twice before, but has never stood trial. Baratov, a Canadian and Kazakh national who lives in Canada, was arrested Tuesday and will be extradited to the U.S. Dokuchaev has been in custody since late last year on treason charges.

Charges include conspiracy to commit computer fraud and abuse, conspiracy to engage in economic espionage, and theft of trade secrets. The most severe of the charges, conspiracy to commit wire fraud, carries a maximum penalty of 20 years in prison.

The indictment comes amid increasing scrutiny of Russian efforts to affect the presidenti­al election, including through the hack of the Democratic National Committee. McCord said they are not alleging any connection between the two.

 ??  ?? DOKUCHAEV
DOKUCHAEV
 ??  ?? BELAN
BELAN
 ??  ?? SUSHCHIN
SUSHCHIN

Newspapers in English

Newspapers from United States