Skip to main content

Hackers told the FBK how they choose targets and what they do with the data they obtain

Submitted by fbrk_news on
DATASUCKERS хакеры

FBRK continues to publish interviews with members of DATASUCKERS, who previously claimed attacks on Dodo Pizza and Tez Tour. In this part — about why they attack companies, how they choose targets, what happens to the obtained databases and what protection measures they advise users.

We are telling this exclusively for informational purposes and do not romanticise illegal activity. Obey the law.

WHY THEY HACK 

In the field of cybersecurity, a conventional distinction is made between White Hat and Black Hat. The former search for vulnerabilities with the permission of system owners and help to eliminate them. The latter gain access without permission and use the found vulnerabilities for their own purposes.

The members of the group themselves classify themselves as Black Hat and name money as their main motive.

«Obviously, in our case it is Black Hat. Our motive is financial gain above all, theft of databases and, accordingly, earning from the sale of these databases».

The interviewee also said that they had been offered cooperation with state structures, but such a format turned out to be financially uninteresting for them.

HOW THEY CHOOSE A TARGET 

According to the interviewee, they are primarily interested in large companies with large databases. The second factor is how easy, in their assessment, it is to work with a specific resource.

«The first criterion is a large company that has a good and large database in terms of content. The second point is optional, in our subjective opinion, it is the ease of working with this resource».

At the same time, a large service is not always harder to attack.

«Sometimes it is easier to hack a large site, because it has many different developments, technologies and so on, than a small one».

The members of the group do not set strict restrictions for themselves by sector. Small sites and small projects interest them less because of their low financial value.

WHAT TARGETS THEY HAVE NOW

Dodo Pizza and Tez Tour, as the interviewee claims, are only part of the companies the group has dealt with.

«Right now I will not disclose specifically which ones, since we have not yet finished work on them. There are several jobs both in the CIS and on foreign companies».

According to him, this concerns dozens of other targets.

In the DATASUCKERS Telegram channel there was also a hint at one of the large electronics stores. In the comments, users suggested that this could be DNS, but the hackers themselves did not confirm this.

WHAT HAPPENS TO THE DATABASES

The obtained data, as the members of the group claim, is not published openly, but sold.

According to the interviewee, among the buyers there may be services that search for information about people. After the sale, it is no longer possible to control the further distribution of the database.

FBRK asked how they feel about the fact that such data may end up with fraudsters. The interviewee replied that negatively.

At the same time, a contradiction arises: the group says that it does not support fraud, but at the same time sells the obtained databases to third parties, without controlling their further use.

WHAT THEY ADVISE USERS 

«The only thing I can advise is to use a unique password on each site and enable two-factor authentication».

According to the interviewee, companies and state organisations also need to look for weak points in advance and constantly monitor the state of IT systems, rather than react only after an attack.

CONTEXT 

Earlier, FBRK wrote about a cyberattack on Dodo Pizza. At first the company stated that user data from Kazakhstan had not been affected, and later admitted that for some clients the name, phone number, delivery address, date of birth and order history could have been affected.

We devoted a separate piece to the story with eGov. The interviewee said that in 2023, according to his information, data from the state database «Individuals» could be obtained using automated requests. He did not confirm a direct hack of eGov, however.

Наша редакция участвует в партнёрской сети «Все СМИ».