Pretty bad when the FBI has to step in and alert you that someone has brute forced their way into your servers.
Pretty bad when the FBI has to step in and alert you that someone has brute forced their way into your servers.
https://krebsonsecurity.com/2018/12/a-breach-or-just-a-force...
“This is not in response to a breach of Citrix products or services,” wrote spokesperson Jamie Buranich.
I want to know if they knew already in December, and if they lied to the public and their customers. Maybe they could argue that "yes a breach happened, but this password reset was completely unrelated" but thats a load of livestockwash, if thats the case.
Edit: maybe i should read the article. Looks like they were in back in October! Jamie is likely just a sacrificial lamb, who is there so they have a head to roll, but somebody on the executive team should be in trouble for that kind of lie, unless there were government gag orders.
>Citrix’s letter was prompted by laws in virtually all U.S. states that require companies to notify affected consumers of any incident that jeopardizes their personal and financial data.
Excuse my French, but thats fucking bullshit that they are just admitting to this a year and a half later.
> Resecurity also presented evidence that it notified Citrix of the breach as early as Dec. 28, 2018, a claim Citrix initially denied but later acknowledged.
Basically the FBI is the internet police for these infrastructure / science / tech / etc. firms. It's not hard to understand why this information isn't out on the street more.
Device or servers will then have evidence of the other things the hacker and thier associates have been doing.
Sometimes criminals brag about things.
Other times, the compromised infrastructure is used in other criminal activity that gets detected by the next victim, and the law enforcement agencies work thier way back.
If it was a nation state: The CIA might be inside their system (technically or personnel-wise) and saw evidence, and told the FBI.
I’m a little curious to know how the FBI comes across this information. Monitoring communications of criminals? Informants?
- criminal steals someone's SSN
- criminal uses that SSN to steal an identity
- the SSN owner notices their identity has been stolen and reports it to authorities
- the authorities investigate and are able to trace it back to where it was stolen from (and sometimes even who stole it)
- the authorities notify the company that was breached.
It's more common with larger breaches with more stolen SSNs (and thus more people reporting that their SSN was stolen) because that catches the FBI's attention more readily and makes it easier to trace it back.
Yes ..