logo
4 Arrested Over Scattered Spider Hacking Spree

4 Arrested Over Scattered Spider Hacking Spree

WIRED2 days ago
Photo-Illustration:WIRED reported this week on public records that show the United States Department of Homeland Security urging local law enforcement around the country to interpret common protest activities and surrounding logistics—including riding a bike, livestreaming a police encounter, or skateboarding—as 'violent tactics.' The guidance could influence cops to use everyday behavior as a pretext for police action.
An AI hiring bot used on the McDonald's 'McHire' site exposed tens of millions of job applicants' personal data because of a group of web-based security vulnerabilities—including use of the classically guessable password '123456' on an administrator account. The site's chatbot, known as Olivia, was built by the artificial intelligence software firm Paradox.ai. Meanwhile, in the wake of last week's devastating floods in Texas that killed at least 120 people, conspiracy theories about the extreme weather event have gained enough traction among anti-government extremists, GOP influencers, and others with large platforms to produce real-world consequences like death threats.
Finally, the metadata of the 'full raw' surveillance footage captured near Jeffrey Epstein's cell the night before the disgraced financier was found hanged shows it's not 'raw' footage at all. Instead, according to a WIRED analysis and digital video forensics experts, the full video is made up of two clips, and it was likely processed using powerful editing software.
And there's more. Each week, we round up the security and privacy news we didn't cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there. 4 Young People Arrested Over Cyberattacks Against UK Retailers
Earlier this year, three retailers in the UK—Harrods, the Co-Op, and M&S—were disrupted by sprawling cyberattacks. Some shelves were left empty for weeks, and M&S executives expect the attacks will cost around £300 million ($407 million) in total. This week, law enforcement officials at the National Crime Agency (NCA), the country's equivalent of the FBI, announced the arrest of four people as part of investigations into the three attacks.
A 20-year-old female, two males aged 19, and another aged 17 were all arrested at their homes in the West Midlands and London on Thursday morning. One of the 19-year-old males is from Latvia, while the others are from the UK, the NCA says. They are suspected of potential Computer Misuse Act offenses, blackmail, money laundering, and 'participating in the activities of an organized crime group,' the NCA said in a statement. The law enforcement agency has not named the individuals arrested or released precise locations of where they are based; however, NCA's deputy director Paul Foster said the arrests were a 'significant step' in its investigations.
The attacks against the three British retailers have been broadly linked, including partially by the NCA, to the loose cybercriminal group Scattered Spider. The hacking group, which first emerged in 2022, is largely made up of young, English-speaking individuals, and has recently been seen targeting retailers, airlines, and the insurance industry across the UK and the US. 'Explosion' of AI-Generated Child Abuse Images Could Overwhelm the Web, Experts Warn
It didn't take criminals long to start using generative AI to create ultra-realistic child sexual abuse images. Now huge volumes of illegal, AI-created content are being found online, with criminals moving to use the technology to create videos as well as still images. During the first six months of this year, analysts at the Internet Watch Foundation, a UK-based organization that removes child sexual abuse material (CSAM) from the web, identified 1,286 AI-generated videos that show abuse—more than 1,000 of the videos showed the most serious type of abuse.
'There is an incredible risk of AI-generated CSAM leading to an absolute explosion that overwhelms the clear web,' said Derek Ray-Hill, the interim chief executive of the Internet Watch Foundation. Separate figures from the US-based National Center for Missing & Exploited Children (NCMEC) say it has received 485,000 reports of AI CSAM in the first half of this year—up from 67,000 for the entirety of last year. Around 35 tech companies have reported finding AI-generated CSAM on their platforms, NCMEC said. Italian Police Arrest an Alleged Member of China's Silk Typhoon Hacking Group
In a rare instance of Western law enforcement actually laying hands on an alleged Chinese state-sponsored hacker, Italian police arrested Xu Zewei, a 33-year-old from Shanghai, at an airport in Milan on July 3. The police were acting on a warrant issued by the US Department of Justice seeking Xu's arrest on hacking charges. Authorities allege he's a member of the espionage group known as Silk Typhoon or Hafnium, which has carried out widespread data theft from Western governments and private sector companies for years. US prosecutors are specifically accusing Xu of taking part in Silk Typhoon's hacking that targeted researchers working to develop a Covid-19 vaccine in 2020 and 2021. He's also alleged to have participated in a far less targeted hacking campaign in which the same group broke into tens of thousands of Microsoft exchange servers around the world, leaving behind backdoors for later reconnaissance. Xu's lawyer denied the charges, saying it's a case of mistaken identity, and Xu's wife also has reportedly said that Xu is an IT technician at the company GTA Semi Conductor. Russian Pro Basketball Player Arrested on Ransomware Charges
In more news of alleged hackers arrested in European airports—and a very unusual case of alleged cybercriminal moonlighting—French police this week detained Russian professional basketball player Daniil Kasatkin in the Charles de Gaulle airport in Paris, accusing him of being part of a ransomware group. Authorities haven't yet named the ransomware crew they claim Kasatkin was a part of, but say that from 2020 to 2022 it hit close to 900 organizations, including two American government agencies. Kasatkin's lawyer, Frédéric Bélot, denied the accusations, saying his client is 'useless with computers and can't even install an application.' Kasatkin, who played for the pro basketball team MBA Moscow, had traveled to France with his fiancée to propose to her. Bodyguards Using Strava Leaked the Detailed Locations of Sweden's Prime Minister
Here's your annual reminder, athletic oversharers of the world, to set your Strava account settings to private. This week, Sweden's Dagens Nyheter newspaper revealed that seven bodyguards for Swedish government officials left their Strava accounts public, revealing their locations as they carried out 1,400 exercise activities—and in many cases, the locations of the people they were protecting, including the Swedish prime minister, Ulf Kristersson. The leaked locations of the prime minister included hotels where he stayed, private addresses, a family vacation, trips abroad, and his private home, which was intended to be secret. Repeat after me, Strava enthusiasts with security clearances: Go to Settings, tap Privacy Controls, then Activities. Future scandal averted.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Protesters with pride signs confront Indy church after anti-LGBTQ sermon calls for violence
Protesters with pride signs confront Indy church after anti-LGBTQ sermon calls for violence

Yahoo

time2 hours ago

  • Yahoo

Protesters with pride signs confront Indy church after anti-LGBTQ sermon calls for violence

After a Sunday service on July 13, leaders at an Indianapolis church laughed while protesters in front of their building held rainbow colored signs. Sure Foundation Baptist Church located at a mall storefront near Lafayette Road and West 30th Street, had recently gained attention for its anti-LGBTQ+ messaging to congregants. In a sermon shared online, a lay preacher encouraged members to pray for the deaths of the LGBTQ+ community. Protesters had their own message for the church on July 13. "Existing in their presence," Cass Jackson, who helped organize the protest, told IndyStar. "Which is something they do not believe Christ would approve of." Jackson said the protest was a way for them to communicate to the church, as well as others, that church leaders could continue their hate, but they would continue to show up and be joyful in their presence. An original video of a sermon shared earlier this month online identified LGBTQ+ as "evil" and "disgusting." "There's nothing good to be proud about being a (slur)," Church member Stephen Falco said during a sermon posted on YouTube. "You ought to blow yourself in the back of the head. You're so disgusting." The video-sharing platform has since removed the video for violating its terms of service. The independent fundamentalist church doubled down on its message in a statement shared on Facebook on July 3, where it said it wasn't apologizing. Evangelist Justin Zhong with the church has since done a sermon discussing the recent coverage and attention the church has gotten. "Why do these (slur) want to burn us and bomb this church and kill us?" Zhong preached in a video posted on the church's Facebook page July11. "Because we testify that their works are evil. My question is, why does a small strip mall church make worldwide news? Because the Word of God has power." Protesters on Sunday said they didn't want to meet the church with violence. They don't intend to change the minds of the congregants about LGBTQ+ individuals, but they say they do want to make it clear that they will highlight the church's bigotry. "What I know to be true is that these people really hate when other people are joyful, because they are not," Jackson said. "And unfortunately have been indoctrinated into a backyard cult." Sure Foundation Baptist Church: Indianapolis church doubles down on Pride sermon advocating for harm to LGBTQ people Zhong told IndyStar he's not surprised at the protest, but the church continued service Sunday morning without issue. The church, which opened its doors in 2024, has about 35 people who attend church on average every week. Citing the Book of Acts, he compared the protest to people and cities outraged in the Bible when the Apostles preached the truth. Zhong said protesters are upset because the Word of God exposes that their deeds are evil. The Concerned Clergy of Indianapolis countered the church's message with a Bible verse, saying in its statement the Gospel is for everyone and should not be used as a tool of condemnation. The clergy group said the Black church, born in the crucible of oppression, must never mimic the very spirit of exclusion that once rejected its community. "We are called to be a sanctuary for the marginalized, not a platform for prejudice," the statement said. In standing for the dignity, inclusion and justice for all people, the group said it rejects the notion LGBTQ+ individuals are outside of God's reach, grace or redemption. G. David Caudill with Equality Indiana said he is encouraged to see other Indianapolis faith leaders condemn the church's sermon. "When you have that type of hateful and violent language, it could lead to someone taking those words and feeling protected to be able to go and commit violent acts against our community," Caudill said. Jade Jackson is a Public Safety Reporter for the Indianapolis Star. You can email her at and follow her on X, formerly Twitter @IAMJADEJACKSON. IndyStar investigative reporter Alexandria Burris' previous reported assisted with this article. This article originally appeared on Indianapolis Star: Pride protest erupts after church calls LGBTQ people 'disgusting'

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store