$10M Is Yours If You Can Get This Guy to Leave Russia
krebsonsecurity.com
krebsonsecurity.com
This, however, is far more interesting.
> Authorities were able to identify that Kulkov had an iCloud account tied to the address nordexin@icloud.com, and upon subpoenaing that found passport photos of Kulkov, and well as more photos of his family and pricey cars.
Isn’t iCloud data E2EE? Or did they subpoena it before E2EE became available for iCloud?And catching cybercriminals is nice and all, but why not shift a little bit of blame on banking and card systems? My bank phased out virtual credit card numbers, that were be restricted to one seller and limited in transaction amount. And I rarely encountered a US merchant using 3D secure transaction, while in Europe many did. Maybe it just my experience though. Somewhat unrelated, but my bank for two 2FA offers only SMS code, I still see cards with magnetic stripes, which should've been obsolete a decade ago, chase still has some weird password requirements that forces you to simplify it, instead of testing it for entropy and plaid still wants your password to connect your bank account to a service. The fin industry is not security minded, so that few man in russia can cause so much damage.
Unless you’ve turned on Advanced Data Protection then Photos and Backups are not e2ee. And that’s only been available recently.
The OP article mentions a subpoena was needed.
https://www.macrumors.com/2022/12/07/apple-advanced-data-pro...
Alas, the KGB (Комитет государственной безопасности → КГБ) is no more. But never fear, the FSB (Федеральная служба безопасности → ФСБ) now may heed your call.
> 79608229389 — is exactly like Anna’s, only minus the (mis?)leading “8”.
Ah, those falsehoods programmers believe about phone numbers
Add:
> One of those was Mark Sokolovsky, a 26-year-old Ukrainian man who operated the popular “Raccoon” malware-as-a-service offering; Sokolovsky was apprehended in March 2022 after fleeing Ukraine’s mandatory military service orders.
Read the article on him. So the guy operated with the impunity from Ukraine and only when he left he was apprehended. *shurg_emoji*
> Ah, those falsehoods programmers believe about phone numbers
This actually has a reasonable technical explanation that will come to mind of most people who lived in Russia for a prolonged period at some point.
So, when you call internationally, each phone number has a country country that starts with a plus (+) character. E.g., US is +1, Russia is +7.
However, when you call domestically, there is some light magic done by telcoms (in each country, i assume) in regards to country codes to make domestic calls a bit easier to input. In the US, the country code can be entirely omitted for domestic calls. E.g., +1-xxx-xxx-xxxx becomes xxx-xxx-xxxx.
In Russia, it cannot be omitted, but instead can be replaced by character 8 (one character vs. two, and no need to deal with the awkward entry of the plus character). So +7-xxx-xxx-xxxx becomes 8-xxx-xxx-xxxx. No idea why +7 gets replaced by 8 instead of 7, I assume some historical reasons.
With that out of the way, and back to the OP, it seems like one of the sources listed the phone number in the shorthand format used in Russia, while the other one listed in the full form including the country code (with the plus character getting eventually stripped along the way as a special character).
https://en.wikipedia.org/wiki/Trunk_prefix
> it seems like one of the sources
What is more important is what the person who is writing the article doesn't have an idea about what it's about. There could be a completely bogus numbers and it wouldn't matter because nobody checks anything. Just like "Anna Denis Vnrhoturkina Kulkov" and "Kommunistrecheskya St"
> Just like "Anna Denis Vnrhoturkina Kulkov" and "Kommunistrecheskya St"
Not trying to absolve Bryan of making those mistakes, but let's be real, he is a security professional, not a specialist on how telephony works all over the world, and neither he is a linguistics specialist.
As long as the factually relevant info is correct and the reasoning is sound (even with those mistakes), it is ok. I am totally fine with the author not knowing that in russian language, the woman's last name would be "Kulkova" and not "Kulkov". Doubly so, given that a lot of digital systems and pieces indeed would record her last name as "Kulkov". Despite those mistakes, the post still makes perfect sense in its chain of reasoning, and none of it changes the conclusion.
For a specific example - my mother and I (who have that same difference in last names, as I am a man, and she is a woman) occasionally receive emails from businesses that mess the last name up (i.e., i would get emails writing my last name with that women-specific "-a" suffix, and she would get emails without it). It doesn't happen often, but it has been happening occasionally over the years.
The award for information on Osama Bid Laden was $27 million.
The state department operates rewardsforjustice.net, but this guy isn't on it. He is on a page on their main website: https://www.state.gov/denis-gennadievich-kulkov/
The secret service is also offering a reward for him https://www.secretservice.gov/investigation/mostwanted/kulko... (The secret service has a dual mandate to protect the president and investigate financial crime)
I'm maybe naïve to this, because I don't know how the check is being performed.
This is illegal because of the fraud. It harms the merchant in all sorts of ways, and also the cardholders and issuers.
That's going to be in records of accounts that eventually report compromises, and get figured our pretty quick, I'd imagine.
I know nothing about carding, but how does it actually work? How is that website able to verify a card's validity, and why can't competitors easily build a similar service?
Maybe abusing services that have "free trial, requires credit card" ? I bet a lot of those do pre-auths.
I thought iCloud was e2e encrypted?