Hacking Team hacked: Firm sold spying tools to repressive regimes


  • TECH
  • Tuesday, 07 Jul 2015

SPYING ON THE PEOPLE: Leaked documents suggest the Hacking Team's clients are governments and security services of Azerbaijan, Kazakhstan, Uzbekistan, Russia, Bahrain, Saudi Arabia and the UAE.

The cybersecurity firm Hacking Team appears to have itself been the victim of a hack, with documents that purport to show it sold software to repressive regimes being posted to the company’s own Twitter feed.

The Italy-based company offers security services to law enforcement and national security organisations. It offers legal offensive and defensive security services, using malware and vulnerabilities to gain access to target’s networks.

According to the documents, 400GB of which have been published, Hacking Team has also been working with numerous repressive governments - something it has previously explicitly denied doing. It has not been possible to independently verify the veracity of the documents.

The perpetrators of the apparent hack have not made themselves known, instead using the company’s own official Twitter feed (renamed to Hacked Team) to communicate. They have continued to post to the feed for hours after, highlighting specific documents they claim come from the hack, such as e-mails, invoices, and even screenshots of Hacking Team employee’s computers, until the company regained control on morning and removed the posts.

One such tweet, which has since been removed, purports to show Hacking Team negotiating with a third-party reseller to export its malware to Nigeria. If the sale took place, it may have bypassed Italian export controls. Another is claimed to show the company debating what to do after an independent investigation from the University of Toronto attacked it for selling hacking tools to Ethiopia, which then used it to target journalists in the US and elsewhere. The company has never publicly confirmed nor denied working with Ethopia, and in March this year a spokesman dismissed earlier reports as “based on some nicely presented suppositions”.

The company has repeatedly denied selling its technology to repressive regimes. In 2013, a Reporters Without Borders report which named Hacking Team as one of the “corporate enemies of the internet”for its position as a “digital mercenary”prompted a response from the firm. In a statement , it said that “Hacking Team goes to great lengths to assure that our software is not sold to governments that are blacklisted by the EU, the USA, Nato and similar international organisations or any ’repressive’ regime.“

But, if genuine, the leaked documents suggest that among Hacking Teams clients are the governments and security services of Azerbaijan, Kazakhstan, Uzbekistan, Russia, Bahrain, Saudi Arabia, and the UAE, many of whom have been criticised by international human rights organisations for their aggressive surveillance of citizens, activists and journalists both domestically and overseas.

Most notably, the documents include an invoice for 480,000 euros (RM2bil) which purports to be from the Sudanese national intelligence service, dated June 2012. Three years later, in January 2015, the company told the UN’s Italian representative that it had no current business relations with the country, prompting the follow-up question “as to whether there have any previous business arrangements” with Sudan, the answer to which is not recorded.

A separate document contained in the apparent file dump appears to show Sudan, along with Russia, listed as “not officially supported”, as opposed to the “active”or “expired” status held by most other nation states.

The company describes itself as in the business of “providing tools to police organisations and other government agencies that can prevent crimes or terrorism”, but if the documents are genuine they suggest it may be willing to sell to non-state actors as well. One invoice apparently reveals the company dealing with a private Brazilian firm, YasNiTech, to whom it sold three months access to its remote access tool, allowing the firm to hack in to Android and Blackberry phones, and Windows devices. We do not know if this sale was part of a wider contract with the Brazilian government.

Hacking Team is one of a number of security firms which sell surveillance technology and malware to national governments, enabling them to access the computers of their targets. Gamma International, another firm in the same space which was best known for its FinFisher surveillance software, suffered a similar hack in 2014 . In the 40GB of data on FinFisher leaked, the company’s clients, capabilities and pricing was revealed; according to the leaked documents, Hacking Team was celebrating the demise of “a wannabe competitor of ours”.

Hacking Team refused to give comment over the phone, directing the Guardian to an e-mail address. Multiple e-mails to that address and others given on the firm’s website were returned as undeliverable, and on a follow-up call, Hacking Team again declined to comment and directed the paper to the broken e-mail address. When the Guardian explained that the e-mail address was not working, Hacking Team declined to give an alternative address or any other form of contact.

Christian Pozzi, one of the firm’s employees, tweeted to say that the documents contained “false lies”about the services the company offers.

“A lot of what the attackers are claiming regarding our company is not true. Please stop spreading false lies about the services we offer,”Pozzi tweeted. “We are currently working closely with the police at the moment. I can’t comment about the recent breach.“

Pozzi’s feed was later itself hacked, and later still the entire account was deleted. — Guardian News Service



Limited time offer:
Just RM5 per month.

Monthly Plan

RM13.90/month
RM5/month

Billed as RM5/month for the 1st 6 months then RM13.90 thereafters.

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

EU court adviser backs data privacy activist Schrems in Meta fight
Spotify says Apple has rejected its app update with price information for EU users
Amazon to invest $11 billion in Indiana to build data centers
IBM falls as enterprise-spending constraints choke consulting demand
Net neutrality rules to be restored in US agency vote
India's Tech Mahindra misses Q4 revenue view on weak communications segment
Explainer-Where are Wall Street's analyst notes on Trump's Truth Social?
AI spending worries cast gloom over Alphabet, Microsoft
Electric cars and digital connectivity dominate at Beijing auto show
Most global tech leaders see their companies unprepared for AI

Others Also Read