Los Angeles Times

Hacker gets 14 years in breach

Latvian programmer’s Scan4You tool was used by cybercrimi­nal who attacked Target.

- By Rachel Weiner Weiner writes for the Washington Post.

A Latvian computer programmer was sentenced to 14 years in prison for designing a program that helped hackers improve malware, including some used in the 2013 Target breach.

Ruslan Bondars, a 37year-old Latvian citizen, was found guilty at a May trial in federal court in Alexandria, Va., during which a co-conspirato­r revealed the pair had worked with Russian law enforcemen­t.

Hackers used their Scan4You program to see if antivirus programs would identify their software as malicious; it could be adapted into malware kits sold to cybercrimi­nals. Bondars argued that there are legal uses for the product and that he was not responsibl­e for when it was used illegally.

“Our position protects all online businesses; all online businesses have legitimate and illegitima­te users,” defense attorney Jessica Carmichael said Friday.

“It’s an interestin­g theory,” but not one that applies in criminal cases, Judge Liam O’Grady responded. He told Bondars, “There’s zero chance that you didn’t know the harm being done by the malware hackers used your service to perfect.”

Prosecutor­s said it is common and perfectly legal to hold software developers liable for creating products that could be used for good as well as ill.

“The defendant apparently thinks he is unique in being charged for creating and selling a computer product that had theoretica­l lawful uses. He is not. Malware often has theoretica­l lawful uses,” Assistant. U.S. Atty. Kellen Dwyer wrote in his sentencing argument.

Co-conspirato­r Taylor Huddleston made a similar argument in an interview with the Daily Beast last year, saying he was being prosecuted for designing software he never intended as malicious. Huddleston, 27, ultimately pleaded guilty to a hacking-related crime in Alexandria; one of his co-defendants testified against Bondars.

One Scan4You user was behind the 2013 theft of credit card informatio­n from about 40 million Target customers.

“I feel ashamed that some of the website users used it for such terrible things,” Bondars told the court in halting English on Friday.

Bondars argued in court filings that the service had little to do with the massive data breach, which cost Target hundreds of millions of dollars. He emphasized that the malware was also run through a mainstream virus-detection service and that Target’s own security system saw the breach but it was ignored. Bondars’ product was not actually used to help get into Target’s system or steal the informatio­n, according to court testimony. An expert from Verizon who helped investigat­e the hack said the files tested in Scan4You were probably used to figure out where payment informatio­n was stored.

Cybersecur­ity experts have said the hacker, identified in court as “Profile 958,” is probably a Ukrainian named Andrey Hodirevski.

Target is demanding restitutio­n from Bondars; an amount has yet to be decided. Although Bondars was never charged with direct involvemen­t in any hacking and made little money from Scan4You, court documents show he had used malware to rob people and to trick people into buying antivirus services they did not need.

Newspapers in English

Newspapers from United States