Apple and Meta reportedly tricked into sharing customer dataVish Gainon March 31, 2022 at 07:22 Silicon RepublicSilicon Republic

0

Apple and Facebook parent company Meta have provided user data to cybercriminals who requested the information after compromising law enforcement accounts last year, according to a Bloomberg report.

Three people familiar with the investigation told Bloomberg that the hackers, at least one whom is likely part of the Lapsus$ group, pretended to be law enforcement officials and requested sensitive user data such as address, phone number and IP address from Apple and Meta in mid-2021.

Such requests usually require documents signed by judges or search warrants, but Bloomberg reported that special “emergency data requests”, like the ones the hackers used, can be made when officials require speedy access to the data.

Snapchat owner Snap was also sent these forged requests, but it is not known whether the company provided them with user data.

Some of the hackers behind the emails are suspected to be teenagers based in the UK, including one who is believed to be the teenage boy from Oxford who is suspected to be the mastermind behind the recent Lapsus$ hacks.

Lapsus$ has targeted big tech companies such as Microsoft, Samsung, Nvidia and Otka in recent months. Seven people between the ages of 16 and 21 were arrested in the UK last week in relation to the cybercrime gang.

However, the string of forged emails from compromised law enforcement accounts last year were churned out by a different hacker group called Recursion Team, which, according to Bloomberg, is no longer active.

The group likely used the info obtained to harass the users through financial fraud schemes that bypassed account security.

Legal guidelines

Meta, Apple, Snap and other big tech companies have strict rules about who they hand out user data to. Usually, law enforcement officials with official accounts can make successful requests – although it isn’t always clear to the companies if the accounts are compromised.

“We review every data request for legal sufficiency and use advanced systems and processes to validate law enforcement requests and detect abuse,” Meta spokesman Andy Stone told Bloomberg.

“We block known compromised accounts from making requests and work with law enforcement to respond to incidents involving suspected fraudulent requests, as we have done in this case.”

According to Apple’s legal process guidelines, if a law enforcement agency wants customer data under an emergency request, “a supervisor for the government or law enforcement agent who submitted [the request] may be contacted and asked to confirm to Apple that the emergency request was legitimate”.

Earlier this week, Krebs on Security reported that social media company Discord was also targeted in a similar hack with emergency requests for customer data, at least one of which it had fulfilled.

10 things you need to know direct to your inbox every weekday. Sign up for the Daily Brief, Silicon Republic’s digest of essential sci-tech news.

The post Apple and Meta reportedly tricked into sharing customer data appeared first on Silicon Republic.

Leave a Comment