Berliner Boersenzeitung - Hackers got user data from Meta with forged request

EUR -
AED 4.326385
AFN 75.395071
ALL 95.674789
AMD 440.015872
ANG 2.108574
AOA 1080.272088
ARS 1609.209775
AUD 1.650497
AWG 2.1146
AZN 2.00376
BAM 1.95624
BBD 2.372615
BDT 144.867534
BGN 1.965108
BHD 0.444408
BIF 3502.407445
BMD 1.17805
BND 1.498688
BOB 8.140144
BRL 5.887543
BSD 1.178005
BTN 110.020973
BWP 15.806095
BYN 3.362143
BYR 23089.784375
BZD 2.369224
CAD 1.623253
CDF 2721.295698
CHF 0.92182
CLF 0.026572
CLP 1048.064802
CNY 8.031534
CNH 8.032303
COP 4232.946501
CRC 540.640075
CUC 1.17805
CUP 31.218331
CVE 110.291703
CZK 24.360786
DJF 209.775241
DKK 7.472861
DOP 70.198188
DZD 155.6347
EGP 61.25877
ERN 17.670753
ETB 183.936737
FJD 2.589767
FKP 0.868557
GBP 0.869372
GEL 3.163095
GGP 0.868557
GHS 13.005425
GIP 0.868557
GMD 86.583025
GNF 10334.326644
GTQ 9.006257
GYD 246.4549
HKD 9.229358
HNL 31.288106
HRK 7.534222
HTG 154.139936
HUF 364.864557
IDR 20208.273529
ILS 3.539323
IMP 0.868557
INR 110.049152
IQD 1543.199831
IRR 1550461.349731
ISK 143.756968
JEP 0.868557
JMD 185.891851
JOD 0.835232
JPY 187.408977
KES 152.207173
KGS 103.020741
KHR 4718.222453
KMF 492.425055
KPW 1060.247588
KRW 1740.074737
KWD 0.364029
KYD 0.981654
KZT 558.864797
LAK 25990.84433
LBP 105490.779538
LKR 371.653137
LRD 216.75708
LSL 19.328744
LTL 3.478476
LVL 0.712591
LYD 7.452678
MAD 10.894153
MDL 20.144219
MGA 4887.286999
MKD 61.655975
MMK 2474.176964
MNT 4213.159111
MOP 9.507304
MRU 47.036388
MUR 54.485091
MVR 18.212746
MWK 2042.6379
MXN 20.386218
MYR 4.65915
MZN 75.34219
NAD 19.328908
NGN 1586.33946
NIO 43.351232
NOK 11.121858
NPR 176.032609
NZD 1.997626
OMR 0.452964
PAB 1.17801
PEN 3.991634
PGK 5.105149
PHP 70.784305
PKR 328.513427
PLN 4.241641
PYG 7528.95069
QAR 4.295067
RON 5.090938
RSD 117.408
RUB 89.088201
RWF 1725.146972
SAR 4.41967
SBD 9.481549
SCR 16.474779
SDG 708.008114
SEK 10.848093
SGD 1.499016
SHP 0.879533
SLE 29.038993
SLL 24703.11964
SOS 673.27444
SRD 44.094179
STD 24383.261147
STN 24.506349
SVC 10.307321
SYP 130.273957
SZL 19.316005
THB 37.818905
TJS 11.132232
TMT 4.129066
TND 3.420257
TOP 2.836462
TRY 52.720504
TTD 7.996106
TWD 37.278237
TZS 3057.040551
UAH 51.30035
UGX 4353.12786
USD 1.17805
UYU 47.380667
UZS 14359.47664
VES 561.963944
VND 31018.062378
VUV 140.199803
WST 3.216909
XAF 656.126997
XAG 0.014936
XAU 0.000245
XCD 3.18374
XCG 2.123041
XDR 0.815091
XOF 656.104714
XPF 119.331742
YER 280.994416
ZAR 19.33131
ZMK 10603.871004
ZMW 22.587948
ZWL 379.331691
  • RIO

    -0.2900

    98.58

    -0.29%

  • BTI

    -0.3100

    57.2

    -0.54%

  • BP

    -0.2000

    45.97

    -0.44%

  • GSK

    -0.4750

    58.705

    -0.81%

  • AZN

    -2.3200

    202.06

    -1.15%

  • NGG

    -0.9600

    87.99

    -1.09%

  • RYCEF

    0.5900

    17.79

    +3.32%

  • VOD

    0.0500

    15.67

    +0.32%

  • BCE

    0.0600

    23.91

    +0.25%

  • BCC

    -1.7700

    79.95

    -2.21%

  • RELX

    0.7600

    35.47

    +2.14%

  • JRI

    0.0934

    12.8799

    +0.73%

  • CMSD

    0.0500

    22.88

    +0.22%

  • RBGPF

    -13.5000

    69

    -19.57%

  • CMSC

    0.1500

    22.79

    +0.66%

Hackers got user data from Meta with forged request
Hackers got user data from Meta with forged request

Hackers got user data from Meta with forged request

Facebook owner Meta gave user information to hackers who pretended to be law enforcement officials last year, a company source said Wednesday, highlighting the risks of a measure used in urgent cases.

Text size:

Imposters were able to get details like physical addresses or phone numbers in response to falsified "emergency data requests," which can slip past privacy barriers, said the source who requested anonymity due to the sensitivity of the matter.

Criminal hackers have been compromising email accounts or websites tied to police or government and claiming they can't wait for a judge's order for information because it's an "urgent matter of life and death," cyber expert Brian Krebs wrote Tuesday.

Bloomberg news agency, which originally reported Meta being targeted, also reported that Apple had provided customer data in response to forged data requests.

Apple and Meta did not officially confirm the incidents, but provided statements citing their policies in handling information demands.

When US law enforcement officials want data on a social media account's owner or an associated cell phone number, they must submit an official court-ordered warrant or subpoena, Krebs wrote.

But in urgent cases authorities can make an "emergency data request," which "largely bypasses any official review and does not require the requestor to supply any court-approved documents," he added.

Meta, in a statement, said the firm reviews every data request for "legal sufficiency" and uses "advanced systems and processes" to validate law enforcement requests and detect abuse.

"We block known compromised accounts from making requests and work with law enforcement to respond to incidents involving suspected fraudulent requests, as we have done in this case," the statement added.

Apple noted its guidelines, which say that in the case of an emergency application "a supervisor for the government or law enforcement agent who submitted the... request may be contacted and asked to confirm to Apple that the emergency request was legitimate."

Krebs noted that the lack of a unitary, national system for these type of requests is one of the key problems associated with them, as companies end up deciding how to deal with them.

"To make matters more complicated, there are tens of thousands of police jurisdictions around the world — including roughly 18,000 in the United States alone — and all it takes for hackers to succeed is illicit access to a single police email account," he wrote.

(G.Gruner--BBZ)