The Borneo Post (Sabah)

Shockingly simple way nude photos of celebs were stolen

-

LOS ANGELES: Prosecutor­s have announced the first criminal conviction in connection with the 2014 hacking of Hollywood celebritie­s that resulted in the online release of hundreds of private nude photos.

Officials here said on Tuesday that 36-year-old Ryan Collins of Pennsylvan­ia agreed to enter a guilty plea on hacking charges as part of the “Celebgate” investigat­ion.

Authoritie­s said Collins admitted to a “phishing” scheme to obtain passwords of more than 100 people, many of them movie stars, and then using that to obtain nude pictures from their “cloud” storage accounts.

Collins used an email phishing scheme to access more than a hundred personal accounts.

Based on what we know from the plea agreement and prosecutor­s, it appears that one major part of Celebgate is much less elaborate than what some 4chan users claimed at the time: that many of the photos were stolen through a clever exploitati­on of a previously unknown iCloud security flaw — a claim that Apple had denied.

Instead, Collins used a method of gaining access to passwordpr­otected accounts that can victimise pretty much anyone. Phishing schemes come in a lot of different flavours, but all follow the same basic outline: Users are tricked into giving out sensitive informatio­n by malicious email accounts or websites that appear legitimate. Spear phishing, which appears to be what happened here, involves targeting specific users by impersonat­ing businesses or individual­s they might already know.

Constant threat

Although the informatio­n these emails request — usernames and passwords, personal data, financial informatio­n — are things that a legitimate company would never ask its users to provide in an email, the scammers are hoping that if their target believes they can trust the source of the request, they might be more likely to comply.

Phishing attempts like the one now connected to Celebgate are more or less a constant threat for anyone on the Internet. Even if you’ve never actually taken a nude selfie using a digital device, there’s probably something else stored in your digital life that you’d rather not share with the whole world — and there’s someone out there who would like to access it.

According to court filings, Collins stole photos, videos and sometimes entire iPhone backups from at least 50 iCloud accounts and 72 Gmail accounts, “mostly belonging to celebritie­s,” between November 2012 and September 2014, when the photos were posted online. The US attorney’s office in the Central District of California has confirmed that Collins was charged as a result of a federal investigat­ion into Celebgate, although court documents and statements pertaining to his plea deal do not name any of his famous victims.

Jennifer Lawrence, Kate Upton, Kirsten Dunst, Avril Lavigne, Lea Michele, McKayla Maroney and Ariana Grande were among the celebritie­s whose photos were said to be in the Celebgate dump. Some, like Lawrence, Upton and Dunst, confirmed that the photos were genuine.

Collins allegedly gained access by setting up emails designed to look like official accounts associated with the Google or Apple services used by his celebrity targets. Some of the emails he used included “email.protection­318@icloud.com,” “noreply_helpdesk01­1@ outlook.com,” and “secure. helpdesk00­19@ gmai l .com,” according to court documents. Then, it seems that whoever was managing the personal accounts of several of the targeted celebritie­s complied, replying to those messages with the requested access informatio­n: the usernames and passwords for their accounts.

Once he had that informatio­n, Collins also had access to everything stored within. He took photos and videos, and sometimes used “a software program to download the entire contents of the victims’ Apple iCloud backups,” the US attorney’s office said.

David Bowdich, assistant director in charge of the FBI’s Los Angeles Field Office, released a statement urging everyone to take precaution­s against schemes like the one linked to Collins. “We continue to see both celebritie­s and victims from all walks of life suffer the consequenc­es of this crime and strongly encourage users of Internet-connected devices to strengthen passwords and to be skeptical when replying to emails asking for personal informatio­n,” he said.

But there’s more you can do, particular­ly on the specific services named in this case: Both iCloud and Gmail allow users to turn on two-factor authentica­tion, which adds an additional step to logging on to an account. Instead of just a username and password (which, by the way, should be different for each account), an account with two-factor enabled also requires a unique code, sent to the user’s phone at the time of login. More and more services are starting to enable two-factor security measures. Turn it on if it’s available.

We still know very little about how the photos went from people like Collins to the whole Internet. At the time, 4Chan users were talking about a secret, very creepy-sounding undergroun­d ring that connected the people who hacked celebrity accounts with those who wanted to sell or collect them. The US attorney’s office said investigat­ors had “not uncovered any evidence linking Collins to the actual leaks or that Collins shared or uploaded the informatio­n he obtained.”

It seems unlikely that investigat­ors believe Collins is the sole source of the photos in the Celebgate cache. Gawker reported in January that two Chicago homes were raided in connection with the Celebgate investigat­ion. In both cases, according to court documents obtained by Gawker, investigat­ors believed that the individual­s in question had also used phishing schemes to target the iCloud accounts of celebritie­s connected to the stolen photo cache. The district attorney’s office told Gawker on Tuesday that the Chicago raids and the charge against Collins were “directly related.”

Collins is the first to be charged in connection with the FBI’s investigat­ion. As part of a plea deal, prosecutor­s will recommend an 18-month prison sentence. The charge against him carries a maximum of five years in prison. — WP-Bloomberg

 ??  ?? Actress Jennifer Lawrence arrives at the 88th Academy Awards nominees luncheon in Beverly Hills, California last month. — Reuters file photo
Actress Jennifer Lawrence arrives at the 88th Academy Awards nominees luncheon in Beverly Hills, California last month. — Reuters file photo

Newspapers in English

Newspapers from Malaysia