Calgary Herald

FBI charges 2 Iranian men in cyber extortion of U of C

- SAMMY HUDES

Two Iranian men were charged by the U.S. Federal Bureau of Investigat­ion on Wednesday in connection with an internatio­nal computer hacking and extortion scheme that led the University of Calgary to pay a $20,000 ransom after a devastatin­g malware attack more than two years ago.

The cyberattac­k crippled multiple U of C systems in May 2016 using sophistica­ted ransomware, which locks or encrypts computers and networks.

The university agreed at the time to pay the ransom using bitcoin, an untraceabl­e digital currency, to ensure critical systems could be restored.

The U of C was among more than 200 victims of the scheme, which spanned nearly three years. Other targets included hospitals, municipali­ties and public institutio­ns in the U.S., according to the FBI indictment.

Faramarz Shahi Savandi, 34, and Mohammad Mehdi Shah Mansouri, 27, both from Iran, were charged with offences including conspiracy to commit wire fraud, intentiona­l damage to a protected computer and transmitti­ng a demand in relation to damaging a protected computer.

Both are considered fugitives and are wanted by the FBI.

The six-count indictment alleges that while acting from inside Iran, they deployed malware known as “SamSam Ransomware,” capable of forcibly encrypting data on victims’ computers.

Beginning in December 2015, Savandi and Mansouri are accused of accessing the computers of victims through security vulnerabil­ities, and installing and executing the SamSam Ransomware on the computers.

Victims were then extorted with a demand for ransom paid in bitcoin in exchange for decryption keys for the affected systems. Ransom payments collected in the virtual currency would be exchanged into Iranian rial using Iran-based bitcoin exchangers.

The indictment alleges that Savandi and Mansouri collected more than US$6 million in ransom payments, causing more than US$30 million in losses to victims.

The U of C attack happened May 27, 2016, when it is alleged Savandi and Mansouri used virtual private servers to access the university’s computer network and deployed the “SamSam Ransomware,” according to their indictment unsealed Wednesday.

That same day, authoritie­s say, Savandi and Mansouri extorted the University of Calgary by demanding a ransom paid in bitcoin in exchange for decryption keys for the affected data.

More than 100 university computers were affected by the virus.

In a statement, U of C vice-president Linda Dalgetty thanked the FBI “for their diligence and perseveran­ce in investigat­ing this matter.”

“We are thankful that law enforcemen­t agencies take such criminal acts very seriously and were able to locate the perpetrato­rs and issue arrest warrants,” Dalgetty stated. “Students, faculty and staff showed tremendous patience and understand­ing as the university worked through this challengin­g issue, and we hope they can take satisfacti­on in knowing that the suspected perpetrato­rs are being charged.”

Other victims included the cities of Atlanta, Newark and San Diego, and the Colorado Department of Transporta­tion, according to the indictment.

It also says the hackers targeted six health care-related entities: the Hollywood Presbyteri­an Medical Center in Los Angeles; the Kansas Heart Hospital in Wichita; the Laboratory Corp. of America Holdings in Burlington, N.C.; MedStar Health in Columbia, Md.; the Nebraska Orthopedic Hospital in Omaha; and Allscripts Healthcare Solutions Inc., headquarte­red in Chicago.

“The defendants chose to focus their scheme on public entities, hospitals and municipali­ties. They knew that shutting down those computer systems could cause significan­t harm to innocent victims,” U.S. deputy attorney general Rod Rosenstein said at a news conference in Washington, D.C., on Wednesday.

“Every sector of our economy is a target of malicious cyber activity. But the events described in this indictment highlight the urgent need for municipali­ties, public utilities, health-care institutio­ns, universiti­es and other public organizati­ons to enhance their cybersecur­ity.”

In addition to using Iran-based bitcoin exchangers, the indictment alleges Savandi and Mansouri also used overseas computer infrastruc­ture to commit their attacks.

Newspapers in English

Newspapers from Canada