Hackers target US security think-tank
LONDON, Dec 25: Hackers on Sunday claimed to have stolen a raft of e-mails and credit card data from US-based security think-tank Stratfor, promising it was just the start of a weeklong Christmas-inspired assault on a long list of targets.
One alleged hacker said the goal was to use the credit data to steal a million dollars and give it away as Christmas donations.
Members of the loose-knit hacking movement known as “Anonymous” posted a link on Twitter to what they said was Stratfor’s tightly-guarded, confidential client list. Among the list: The US Army, the US Air Force and the Miami Police Department.
The rest of the list, which Anonymous said was a small slice of its 200 gigabytes worth of plunder, included banks, law enforcement agencies, defence contractors and technology firms such as Apple and Microsoft. “Not so private and secret anymore?” the group taunted in a message on the microblogging site.
Anonymous said it was able to get the credit details in part because Stratfor didn’t bother encrypting them — an easy-to-avoid blunder which, if true, would be a major embarrassment for any security-related company.
Stratfor said in an email to members that it had suspended its servers and email after learning that its website had been hacked.
“We have reason to believe that the names of our corporate subscribers have been posted on other web sites,” said the email, passed on to The Associated Press by subscribers. “We are diligently investigating the extent to which subscriber information may have been obtained.”
The email, signed by Stratfor Chief Executive George Friedman, said the company is “working closely with law enforcement to identify who is behind the breach.”
“Stratfor’s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me,” Friedman wrote.
Stratfor’s website was down midday Sunday, with a banner saying “site is currently undergoing maintenance.”
Wishing everyone a “Merry LulzXMas” — a nod to its spinoff hacking group Lulz Security — Anonymous also posted a link on Twitter to a site containing the email, phone number and credit number of a US Homeland Security employee.—AP