April 24, 2024

The Public Prosecution Service within the Netherlands [Dutch: Openbaar Ministerie] has simply launched details about an unnamed suspect arrested again in December 2022 for allegedly stealing and selling private information about tens of hundreds of thousands of individuals.

The victims are mentioned to dwell in nations as far aside as Austria, China, Columbia, the Netherlands itself, Thailand and the UK.

Apparently, the courts have taken a strict method to this case, successfully preserving the arrest secret from late 2022 till now, and never permitting the suspect out on bail.

In response to the Ministry’s report, a courtroom order about custody was made in early December 2022, when the authorities got permission to maintain the suspect locked up for an additional 90 days, that means that they will maintain him till no less than March 2023 as work on his case continues.

The suspect is being investigated for a number of offences: possessing or publishing “private” information, possessing phishing software program and hacking instruments, pc hacking, and cash laundering.

The prosecutors declare that he laundered near half-a-million Euros’ value of cryptocurrency throughout 2022, so we’re assuming that the courtroom thought of him a flight threat, determined that if launched he may be capable to destroy proof and, presumably, thought that he may attempt to warn others within the cybercrime boards the place he’d been energetic to begin overlaying their tracks, too.

Governmental breach?

Intriguingly, the investigation was triggered by the looks on a cybercrime discussion board of a multi-million report stash of non-public information referring to Austrian residents.

These information information, it appears, turned out to have a standard supply: the corporate accountable for gathering radio and TV licence charges in Austria.

Austrian cops apparently went undercover to purchase up a duplicate of the stolen information for themselves, and within the strategy of doing so (their investigative strategies, unsurprisingly, weren’t revealed) recognized an IP quantity that was in some way related to the username they’d handled on the darkish net.

That IP quantity led to Amsterdam within the Netherlands, the place the Dutch police took the investigation additional.

Because the Dutch Ministry writes:

The staff has sturdy indications that the suspect was working below that consumer title and that he had, for a very long time, been providing private private information – together with affected person information from medical information – on the discussion board for fee below that title. […]

With the theft of enormous quantities of digital information, combining totally different databases and buying and selling entry to this information, increasingly more criminals know the place an individual lives, performs financial institution transactions, what automotive they’ve, what their password is, what cellphone numbers they’ve, the place they work, go to highschool and so forth. The place it was essential to watch folks for weeks to establish the appropriate sufferer, now a push of a button suffices.

What subsequent?

We’ll let you already know if and once we be taught extra about this case.

We all know for certain that the Dutch police and prosecutors aren’t going to lose curiosity, as a result of the Ministry concludes its annoucement with these phrases:

This type of prison exercise not solely grossly violates the privateness of hundreds of thousands of individuals but additionally causes monetary harm to people and companies. Police and prosecutors are dedicated to preventing this advanced type of crime by detecting and prosecuting cybercriminals.

However we will’t assist questioning whether or not the Austrian radio and TV licence payment assortment firm may entice the curiosity of investigators of various kind, this time from the Austrian information safety regulators reasonably than the police.

Though firms that endure breaches are undeniably cybercrime victims themselves, they generally find yourself in authorized bother of their very own if the regulator types the opinion that they might and may have executed extra to guard their prospects.

In spite of everything, because the Dutch prosecutors level out, it’s the people whose information truly will get stolen who’re the first victims right here.