Govt officials across 20 countries targeted of WhatsApp hacking: report

Agencies
November 1, 2019

Washington, Nov 1: Senior government officials in multiple US-allied countries were targeted earlier this year with hacking software that used Facebook Inc's WhatsApp to take over users' phones, according to people familiar with the messaging company's investigation.

Sources familiar with WhatsApp's internal investigation into the breach said a "significant" portion of the known victims are high-profile government and military officials spread across at least 20 countries on five continents. Many of the nations are US allies, they said.

The hacking of a wider group of top government officials' smartphones than previously reported suggests the WhatsApp cyber intrusion could have broad political and diplomatic consequences.

WhatsApp filed a lawsuit on Tuesday against Israeli hacking tool developer NSO Group. The Facebook-owned software giant alleges that NSO Group built and sold a hacking platform that exploited a flaw in WhatsApp-owned servers to help clients hack into the cellphones of at least 1,400 users between April 29, 2019, and May 10, 2019.

The total number of WhatsApp users hacked could be even higher. A London-based human rights lawyer, who was among the targets, sent Reuters photographs showing attempts to break into his phone dating back to April 1.

While it is not clear who used the software to hack officials' phones, NSO has said it sells its spyware exclusively to government customers.

Some victims are in the United States, United Arab Emirates, Bahrain, Mexico, Pakistan and India, said people familiar with the investigation. Reuters could not verify whether the government officials were from those countries or elsewhere.

Some Indian nationals have gone public with allegations they were among the targets over the past couple of days; they include journalists, academics, lawyers and defenders of India's Dalit community.

NSO said in a statement that it was "not able to disclose who is or is not a client or discuss specific uses of its technology." Previously it has denied any wrongdoing, saying its products are only meant to help governments catch terrorists and criminals.

Cybersecurity researchers have cast doubt on those claims over the years, saying NSO products were used against a wide range of targets, including protesters in countries under authoritarian rule.

Citizen Lab, an independent watchdog group that worked with WhatsApp to identify the hacking targets, said on Tuesday at least 100 of the victims were civil society figures such as journalists and dissidents, not criminals.

John Scott-Railton, a senior researcher at Citizen Lab, said it was not surprising that foreign officials would be targeted as well.

"It is an open secret that many technologies branded for law enforcement investigations are used for state-on-state and political espionage," Scott-Railton said.

Prior to notifying victims, WhatsApp checked the target list against existing law enforcement requests for information relating to criminal investigations, such as terrorism or child exploitation cases. But the company found no overlap, said a person familiar with the matter. Governments can submit such requests for information to WhatsApp through an online portal the company maintains.

WhatsApp has said it sent warning notifications to affected users earlier this week. The company has declined to comment on the identities of NSO Group's clients, who ultimately chose the targets.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 30,2020

Six months since the new coronavirus outbreak, the pandemic is still far from over, the World Health Organization said Monday, warning that "the worst is yet to come".

Reaching the half-year milestone just as the death toll surpassed 500,000 and the number of confirmed infections topped 10 million, the WHO said it was a moment to recommit to the fight to save lives.

"Six months ago, none of us could have imagined how our world -- and our lives -- would be thrown into turmoil by this new virus," WHO chief Tedros Adhanom Ghebreyesus told a virtual briefing.

"We all want this to be over. We all want to get on with our lives. But the hard reality is this is not even close to being over.

"Although many countries have made some progress, globally the pandemic is actually speeding up.

"We're all in this together, and we're all in this for the long haul.

"We will need even greater stores of resilience, patience, humility and generosity in the months ahead.

"We have already lost so much -- but we cannot lose hope."

Tedros also said that the pandemic had brought out the best and worst humanity, citing acts of kindness and solidarity, but also misinformation and the politicisation of the virus.

In an atmosphere of global political division and fractures on a national level, "the worst is yet to come. I'm sorry to say that," he said.

"With this kind of environment and condition, we fear the worst."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 10,2020

New Delhi, Mar 10: A military transport aircraft of the Indian Air Force (IAF) brought back 58 Indians from coronavirus-hit Iran on Tuesday, official said.

The aircraft, a C-17 Globemaster, was sent to Tehran on Monday evening.

About 2,000 Indians are living in Iran, a country that has witnessed increasing numbers of coronavirus cases in the last few days.

"The IAF aircraft has landed. Mission completed. On to the next," External Affairs Minister S Jaishankar tweeted.

In an earlier tweet, he said, "First batch of 58 Indian pilgrims being brought back from Iran. IAF C-17 taken off from Tehran and expected to land soon in Hindon."

"Thanks to the efforts of our Embassy @India_in_Iran and Indian medical team there, operating under challenging conditions. Thank you @IAF_MCC. Appreciate cooperation of Iranian authorities. We are working on the return of other Indians stranded there (sic)," Jaishankar added.

The aircraft landed at Hindon airbase in Ghaziabad, from where the passengers were take to a medical facility.

According to latest reports, 237 people have died of novel coronavirus in Iran while the number of positive cases stands at around 7,000.

It is the second such evacuation by the C-17 Globemaster in the last two weeks.

On February 27, 76 Indians and 36 foreign nationals were brought back from the Chinese city of Wuhan by the aircraft of the Indian Air Force.

The C-17 Globemaster is the largest military aircraft in the IAF's inventory. The plane can carry large combat equipment, troops and humanitarian aid across long distances in all weather conditions.

Four days ago, a Mahan airline plane brought swab samples of 300 Indians from Iran to India.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 3,2020

New Delhi, Jun 3: Over 1 lakh scanned copies of Indians' national IDs, including Aadhaar, PAN card and passport, have been put on dark web for sale, cyber intelligence firm Cyble said on Wednesday.

The leaked data seems to have originated from a third party and not from the government system, according to a report by Cyble.

"We came across a non-reputed actor who is currently selling over 1 lakh Indian National IDs on the dark net. With such a low reputation, ideally, we would have skipped this; however, the samples shared by the actor intrigued our interest -- and also the volume. The actor is alleged to have access to over 1 lakh IDs from different places in India," Cyble said.

The personal data leaked by cyber criminals leads to various nefarious activities such as identity thefts, scams, and corporate espionage. Many criminals use the personal details in the IDs to win trust of the people over a phone call for fraudulent activities.

Cyber criminals leak personal data of 2.9 cr job-seeking Indians on dark web for free

The Cyble researchers acquired around 1,000 IDs from the seller and confirmed that the scanned IDs belong to Indians.

"Preliminary analysis suggests that the data originated from a third party, and no indication or artefact is indicating that it came from a government system. At this point, Cyble researchers are still investigating this further -- we are hoping to share an update soon," Cyble said.

The scanned ID documents indicate that the data may have been leaked from a company's data base in the segment where they have to comply with 'Know Your Customer' (KYC) norms.

"Cyble researchers have also learned about a surge in KYC and banking scams -- leaks such as this are often used by scammers to target individuals, especially elderlies," Cyble said.

The cyber intelligence firm has recommended people to refrain from sharing personal information especially financial information over phone, e-mail or SMS.

"Regularly monitor your financial transaction, if you notice any suspicious transaction, contact your bank immediately," the company said.

In May, Cyble showed two instances where personal data of 7.65 crore Indians have been put on sale in the dark web. In one instance, the seller claimed to have sourced data of 4.75 crore Indians from online directory Truecaller and in other, the seller claimed to have sourced from job websites.

Truecaller, however, had denied the claim of breach in its database.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.