TECHNOLOGY

Spies in the hot seat after Italian surveillance firm breach

Jul 16, 2015, 1:06 PM

LONDON (AP) — A dramatic breach at an Italian surveillance company has laid bare the details of government cyberattacks worldwide, putting intelligence chiefs in the hot seat from Cyprus to South Korea. The massive leak has already led to one spymaster’s resignation and pulled back the curtain on espionage in the iPhone age.

More than 1 million emails released online in the wake of the July 5 breach show that the Milan-based company Hacking Team sold its spy software to the FBI and to Russian intelligence. It also worked with authoritarian governments in the Middle East and pitched to police departments in the American suburbs. It even tried to sell to the Vatican — all while devising a malicious Bible app to infect religiously minded targets.

“It’s a mini-Snowden event,” said Israel-based security researcher Tal Be’ery, likening the impact of the leak to the publication of top secret NSA documents by former intelligence worker Edward Snowden. Be’ery said he, like others, had long suspected the world’s security agencies of hacking but was struck by “the ubiquity of it — used on all continents, by both democracies and dictatorships.”

Hacking Team’s spyware was used by a total of 97 intelligence or investigative agencies in 35 countries, according to South Korean National Intelligence Service chief Lee Byoung Ho, who briefed lawmakers Tuesday after it became clear his organization used the technology.

Eric Rabe, the Hacking Team spokesman, said Thursday the company had about 50 clients, but it’s not clear whether those include resellers. Rabe acknowledged doing business with Russia and Sudan but said its sales were “in accordance with regulations that were in effect at the time.”

Bills from Hacking Team to Sudan’s intelligence service and a Russian arms conglomerate have critics — including a European parliamentarian — asking whether the company flouted international sanctions. A client list that includes Uzbekistan, Egypt and Azerbaijan has reinforced worries from groups such as Privacy International that the spyware is being used to silence dissidents. And ‘we-love-your-stuff’ emails from sheriffs, police and prosecutors across the United States suggest local law enforcement is eager to give the program a test drive.

CEO David Vincenzetti told La Stampa newspaper that his spyware is used to fight terror and “root out lone wolves.”

Hacking Team’s spyware is called Remote Control System and is delivered to targets through a mix of malicious links, poisoned documents and pornography, the emails show. Booby-trapped programs could be tailored to targets of any persuasion. Some messages appear to show Hacking Team working on apps named “Quran” and “DailyBible.”

Once secretly installed, the spyware acts as a track-anything surveillance tool.

The emails show Kazakhstan’s spy agency trying to suck chat histories from a target’s Samsung smartphone and Saudi Arabia’s Interior Ministry using an infected handset as a tracking beacon. They also show Mongolia’s anti-corruption authority trying to steal a target’s Facebook password by logging his keystrokes and Czech police at work turning a BlackBerry’s microphone into an ad-hoc listening device.

Vincenzetti told La Stampa the spyware even had the ability to automatically take pictures of people’s faces as they picked up their phones.

Mexico is a particularly aggressive user of the technology, according to a leaked client list. In Ecuador, evidence that Hacking Team’s spyware was used by the country’s SENAIN spy agency has caused an uproar.

Senior police and intelligence figures have been quizzed about Hacking Team by lawmakers in Italy and the Czech Republic. Revelations that the Cyprus Intelligence Service has been secretly using the spyware prompted the resignation of the agency’s boss, Andreas Pentaras, over the weekend.

The targets of all this spying are rarely made explicit. But in one of the leaked emails, dated Dec. 15, 2014, Vincenzetti suggested he sometimes has a pretty good idea who is being hacked.

“I usually get a call from, say, the head of Italian Police’s Deputy and he tells me: ‘Congratulations, Mr. Vincenzetti!’ I tell him: ‘Thank you Sir, may I ask you what are you referring to?’ ‘I am talking to what you will read tomorrow morning on the front pages of all the newspapers!’ he laughs. And he hangs up. And the day after I read that a mafia boss has been finally arrested, that an apparently impossible investigation mystery on a savage assassination has been finally solved and the murderer arrested, etc.”

Authorities “never disclose how they did it because they want to protect our technology and they want to protect us,” Vincenzetti said.

Rabe, the Hacking Team spokesman, said it wasn’t unusual for investigators to guard their methods.

“This is very common police practice,” he said.

For researchers like Be’ery, the leak has provided unprecedented insight into how governments hack. For human rights workers, it has confirmed their fears about state surveillance. And for past victims of Hacking Team’s software — people like prominent Emirati blogger Ahmed Mansoor — the leak has provided a dose of schadenfreude.

“They can at least understand how it feels to encroach into somebody’s privacy,” he said.

___

Menelaos Hadjicostis in Nicosia, Cyprus; Karel Janicek in Prague, Czech Republic; and Gonzalo Solano in Quito, Ecuador contributed to this report.

___

Raphael Satter can be reached on: http://raphae.li

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

Technology

(AP Photo/Elise Amendola)...

Ken Colburn, Data Doctors

Arizona tech tips: What’s the difference between Zelle and Venmo

Mobile payment systems like Zelle and Venmo allow you to use your smartphone to transfer money and eliminates the need to write checks.

7 months ago

Windows and Mac tricks every computer user in Phoenix needs to know about...

Kim Komando

Windows and Mac tricks all Valley office workers should be using

Sick of wasting time on manual tasks? Use these nifty Windows and Mac tricks to save time at the computer and boost productivity.

9 months ago

New plane ticket scam robs people who want to take vacations...

Kim Komando

Escaping the Arizona heat? Beware of scammers when trying to book flights

Scammers love to target you when you're going on vacation. This nasty plane ticket scam can steal hundreds of bucks from your bank account.

9 months ago

how to clean sticky keys on your keyboard...

Ken Colburn, Data Doctors

Heatwave got your palms sweaty? Try these insider tech tricks to clean up your keyboard

If you're sick of sticky keys slowing you down, you need to know how to clean sticky keys and make your keyboard as good as new.

9 months ago

ASU research Park...

Brandon Gray

Arizona State University, Applied Materials partner to create $270M Materials-to-Fab Center

Arizona State University and Applied Materials, Inc. announced Tuesday they are partnering to create a shared research, development and prototyping facility.

9 months ago

EV plug in electric vehicle...

Brandon Gray

ADOT adds 7 state highway corridors to EV charging station network plan

The Arizona Department of Transportation is adding seven highway corridors to its planned network of electric vehicle charging stations.

9 months ago

Sponsored Articles

...

Condor Airlines

Condor Airlines can get you smoothly from Phoenix to Frankfurt on new A330-900neo airplane

Adventure Awaits! And there's no better way to experience the vacation of your dreams than traveling with Condor Airlines.

...

COLLINS COMFORT MASTERS

Here are 5 things Arizona residents need to know about their HVAC system

It's warming back up in the Valley, which means it's time to think about your air conditioning system's preparedness for summer.

...

Midwestern University

Midwestern University Clinics: transforming health care in the valley

Midwestern University, long a fixture of comprehensive health care education in the West Valley, is also a recognized leader in community health care.

Spies in the hot seat after Italian surveillance firm breach