Attacks/Breaches

6/19/2018
02:26 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Arizona Man Sentenced to Prison for Distributed Denial of Service Attacks Against Emergency Communications System and Other Municipal Websites

An Arizona man was sentenced yesterday in Phoenix, Arizona, for directing distributed denial of service (DDoS) attacks at the computer networks of the City of Madison, Wisconsin, announced Acting Assistant Attorney General John P. Cronan of the Justice Department’s Criminal Division and First Assistant U.S. Attorney Elizabeth A. Strange for the District of Arizona.

Randall Charles Tucker, aka “Bitcoin Baron,” 23, of Apache Junction, Arizona, was sentenced to serve 20 months in prison by U.S. District Judge Douglas L. Rayes of the District of Arizona.  He was also ordered to pay restitution in the amount of  $69,331.56 to the victims of his computer attacks. Tucker pleaded guilty on April 17, 2017 to one count of intentional damage to a protected computer.

According to admissions made in connection with his plea, between March 9 and March 14, 2015, Tucker executed a series of DDoS attacks against various city websites, including Madison, Wisconsin. A DDoS attack is a malicious attack where illegitimate network traffic is used to slow down or altogether crash a computer server, thereby denying service to legitimate users of the server.  In addition to disabling the City of Madison’s website, the attack crippled the city’s Internet-connected emergency communication system, causing delays and outages in the ability of emergency responders to connect to the 911 center and degrading the system used to automatically dispatch the closest unit to a medical, fire, or other emergency. Tucker, referring to himself as the “Bitcoin Baron,” boasted about his attacks via social media.

This case was investigated by FBI’s Milwaukee and Phoenix Field Offices and Arizona’s Department of Public Safety.  Assistant U.S. Attorney James R. Knapp of the District of Arizona and Trial Attorney Laura-Kate Bernstein of the Criminal Division’s Computer Crime and Intellectual Property Section are prosecuting the case.  The U.S. Attorney’s Office for the Western District of Wisconsin also provided substantial assistance in this manner.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Microsoft President: Governments Must Cooperate on Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/8/2018
To Click or Not to Click: The Answer Is Easy
Kowsik Guruswamy, Chief Technology Officer at Menlo Security,  11/14/2018
Veterans Find New Roles in Enterprise Cybersecurity
Kelly Sheridan, Staff Editor, Dark Reading,  11/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Online Malware and Threats: A Profile of Today's Security Posture
Online Malware and Threats: A Profile of Today's Security Posture
This report offers insight on how security professionals plan to invest in cybersecurity, and how they are prioritizing their resources. Find out what your peers have planned today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19279
PUBLISHED: 2018-11-14
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is limited to a 5-second window and file sizes less than 600 bytes. The effect on SSD devices may be greater.
CVE-2018-19280
PUBLISHED: 2018-11-14
Centreon 3.4.x has XSS via the resource name or macro expression of a poller macro.
CVE-2018-19281
PUBLISHED: 2018-11-14
Centreon 3.4.x allows SNMP trap SQL Injection.
CVE-2018-17960
PUBLISHED: 2018-11-14
CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.
CVE-2018-19278
PUBLISHED: 2018-11-14
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed lengt...