Email this article   Print article 


Nearly 12 Million Apple UDIDs Potentially Stolen From FBI

By Ken Presti
September 04, 2012    7:48 PM ET

Page 1 of 2

A hacktivist group has released an archive of more than a million Apple-related Unique Device Identifiers (UDIDs) that were apparently stolen from an FBI computer. The same group also claims to possess at least 11 million more UDIDs taken from the same computer.

The group, known as "AntiSec," is believed to be related to the hacking group known as "Anonymous" and purportedly acquired the list of user names, devices names, cell phone numbers and addresses last spring by leveraging a Java vulnerability.

Java-based vulnerabilities have also been widely reported in the news lately. Two issues with Java 7 were disclosed more than a week ago. Oracle issued a patch aimed at alleviating the problem last week, and then flaws in that patch were discovered over the weekend.

A spokesperson for the FBI has declined comment. However, it has been widely reported that the FBI is in the midst of an ongoing investigation of Anonymous, and therefore, the exploit is seen as a likely attempt to discredit and embarrass the agency.

[Related: Despite Oracle's Patch, New Java 7 Vulnerabilities Emerge]

A post on the group's Facebook page reads, "Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was P0wn3d using the AtomicReferenceArray vulnerability on Java. R u mad?"

Some reports also suggest that Stangl also appeared on a special video in 2009, inviting the hacker community to turn white-hat and work in collaboration with the FBI to combat black-hat cyber operations. This might've made that specific agent a particularly inviting target, according to Rob Rachwald, director of security strategy at Imperva, a Redwood Shores, Calif.-based security company.

"This is very inconsistent with previous hacktivist attacks because it's very personal in nature, and this could be an indication of trends to come," he said. "They targeted a very specific individual, which is kind of unique, although not unheard of. The second thing that's different is that this attack was not pre-announced. They typically pre-announce who they are going to attack in order to better promote their efforts."

NEXT: How Data Could Be Leveraged

1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

10 Security Companies That Have Scored CIA Funding

CIA-funded venture firm invests millions in technology startups, mostly security firms. Find out which security companies won In-Q-Tel funding.

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

  More Slide Shows




Related Videos
Loading...