Automatically translated.View original post

The FBI used Windows Device ID to track hackers.

The FBI uses Windows Device ID to track hackers.

According to a report by the website The Hacker News, it mentioned a report of the alleged arrest of a suspect who was one of the members of a hacker group called Scattered Spider after it hacked into the system of a famous jewellery store in the United States. The arrested person was a 19-year-old American-Estonian dual-national male named Peter Stokes, or named online as Bouquet, having been extradited as an extraditor from Finland to the United States, and was investigated in a Chicago city court during June 30.

As for the hacking incident, it took place between May 12 and 15, 2025. In the past, a group of culprits used Google Voice to contact the IT Help Desk department of the store, claiming to be a Locked Out employee. Hackers asked the IT department to reset both the password and the mobile phone connected to the multi-way authentication system (MFA or Multi-Factors Authentication). After the IT department became infected with the hacker, within three hours, the hackers had access to three accounts in the company, two of which were accounts of the IT administrator ( IT Administrator, where hackers use these accounts, installs a ngrok and a second Tunnelling tool called Teleport, and then moves the data to a cloud storage on Amazon's service, where the data is up to 77 GB.

In the hacking, it was detected that the hackers tried to implant ransom malware or Ransomware on the system, but the cybersecurity team detected and prevented it from doing so. But the hackers also sent a threat of taking the data hostage. The email section was "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY [sic]," and a ransom of $8 million ($269,984,000), which the company did not pay in any way. Yet the system was hacked until the data was stolen, it was damaged by as much as $2 million ($67,496,000). However, analysts say that the incident did not occur due to a software Flaw fault, but due to a system defect that was not directed to the IT department, had to confirm the contact identity (Verify) and call the number of the employee on the file before resetting the password. There is no procedure for the manager to sign the reset. In addition, there is no video verification of the identity of the account with access to the system. This brings to such an exciting event.

The arrest began as a result of the police's investigation into the ngrok machine, which was found to have access to a Windows 11 operating system with a Windows Device ID: g: 6755467234350028, which was tied to a single installation of Windows 11. The machine had access to ngrok via a Proxy IP number. But what the hackers made the biggest mistake was that an IP number was used on the same computer to access many real-name social media, whether Snapchat and Facebook. Brought to the eventual arrest.

# Trending # lemon 8 diary # fbi # Windows # freedomhack

8/5 Edited to

... Read moreเหตุการณ์นี้สะท้อนให้เห็นความสำคัญของการบริหารจัดการระบบไอทีในองค์กรอย่างรัดกุม โดยเฉพาะการตรวจสอบและยืนยันตัวตนของบุคคลที่เข้ามาขอรีเซ็ตรหัสผ่านหรือเข้าถึงบัญชีสำคัญ การใช้ Windows Device ID เป็นหนึ่งในเครื่องมือที่ FBI สามารถติดตามความผิดปกติจากการใช้งานได้อย่างมีประสิทธิภาพ จากกรณีนี้ แฮกเกอร์ใช้ช่องโหว่ที่เกิดจากนโยบายองค์กรในการขาดมาตรการยืนยันตัวตนระหว่างการทำงานของแผนกไอที เช่น การไม่โทรกลับเบอร์ที่ตรวจสอบไว้หรือตรวจสอบผ่านวิดีโอ ทำให้ทีมโจมตีสามารถเข้าถึงข้อมูลสำคัญได้สะดวก คำแนะนำสำหรับองค์กรคือการตั้งนโยบายที่เข้มงวดขึ้น เช่น การบังคับใช้กระบวนการยืนยันตัวตนแบบหลายขั้นตอน เพิ่มการอนุมัติจากผู้มีอำนาจก่อนทำการรีเซ็ต และมีการบันทึกประวัติการดำเนินงานเพื่อป้องกันและสืบค้นเหตุการณ์ในอนาคต นอกจากนี้ การให้ความรู้แก่ทีมไอทีและพนักงานเกี่ยวกับวิธีระวังและรับมือกับการโจมตีแบบ Social Engineering ก็มีความสำคัญเช่นกัน สำหรับผู้ใช้งานทั่วไป เรื่องนี้ทำให้เห็นว่าการใช้ระบบยืนยันตัวตนหลายช่องทาง (MFA) แม้จะช่วยเพิ่มความปลอดภัย แต่หากระบบการจัดการภายในองค์กรไม่รัดกุมพอ ก็ยังเสี่ยงต่อการถูกหลอกลวงและโจมตีได้ แนะนำให้ทุกคนตระหนักถึงความสำคัญของการรักษาความปลอดภัยข้อมูลส่วนตัว และไม่เปิดเผยข้อมูลรับรองกับบุคคลที่ไม่น่าเชื่อถือ นอกจากนี้ การที่ FBI ใช้ Windows Device ID ในการสืบสวนยังแสดงให้เห็นว่าเทคโนโลยีที่ฝังอยู่ในระบบปฏิบัติการสามารถเป็นประโยชน์ในการติดตามตัวผู้กระทำผิดได้ แม้แฮกเกอร์จะพยายามซ่อนตัวด้วยการใช้ Proxy หรือ IP ตัวแทนก็ตาม เหตุการณ์นี้จึงเป็นบทเรียนสำคัญสำหรับองค์กรต่าง ๆ ในการเสริมสร้างความมั่นคงปลอดภัยไซเบอร์และการจัดการความเสี่ยงในโลกดิจิทัลที่มีการโจมตีซับซ้อนมากขึ้นทุกวัน