Bad OPSEC - How The Feds Traced a Monero User

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 ก.พ. 2024
  • In this video I discuss how the hacker responsible for the Vastaamo data breach incident was caught due to numerous OPSEC mistakes and not really any flaws with the Monero protocol.
    My merch is available at
    based.win/
    Subscribe to me on Odysee.com
    odysee.com/@AlphaNerd:8
    ₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
    Monero
    45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
    Bitcoin
    3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
    Ethereum
    0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
    Litecoin
    MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 1.6K

  • @rulu1828
    @rulu1828 3 หลายเดือนก่อน +4087

    Rule 1 of Crime: Don't talk about the crime

    • @spacecowboy511
      @spacecowboy511 3 หลายเดือนก่อน +256

      Rule 2 of crime: do not talk about crime

    • @Kenword69420
      @Kenword69420 3 หลายเดือนก่อน +93

      If only I knew rule number 3 😢

    • @ThatGuy-ky2yf
      @ThatGuy-ky2yf 3 หลายเดือนก่อน +49

      Self Snitching

    • @donnadie2068
      @donnadie2068 3 หลายเดือนก่อน +78

      >Uploads video to TikTok

    • @Abhishek.Rana.
      @Abhishek.Rana. 3 หลายเดือนก่อน

      don't upload to TH-cam​@@Kenword69420

  • @unseenxxx
    @unseenxxx 3 หลายเดือนก่อน +2214

    >tar contained his entire home directory
    This Finnished him

    • @brainwater
      @brainwater 3 หลายเดือนก่อน +146

      I was expecting something like he tarred it using the full path names giving the police his username, but no, it was 100x stupider than that.

    • @25566
      @25566 3 หลายเดือนก่อน +90

      Idiot was using his main pc instead of tails, terrible opsec

    • @sanguineel
      @sanguineel 3 หลายเดือนก่อน +11

      @@brainwater If you tar something with the full path name the tar file contains the full path name? Or do you mean the file name?

    • @Cube_Box
      @Cube_Box 3 หลายเดือนก่อน +1

      ​@@sanguineelyeah interested as well as i never heard of this before

    • @pogo55555
      @pogo55555 3 หลายเดือนก่อน +13

      🤣🤣🤣🤣. Pun fun. Thanks!

  • @lightfox11
    @lightfox11 3 หลายเดือนก่อน +1965

    the fact he would actually post his user folder to the internet really shows how sloppy this pos is

    • @Ulvis_B
      @Ulvis_B 3 หลายเดือนก่อน +39

      In the end Everyone making errors.

    • @AncientSlugThrower
      @AncientSlugThrower 3 หลายเดือนก่อน +223

      Imagine trying anything like this on your daily driver. Holy cow.

    • @rustymustard7798
      @rustymustard7798 3 หลายเดือนก่อน +182

      Before he even said it, i thought, "11GB?" and instantly started laughing out loud muttering "He tar'd his entire drive, didn't he?"

    • @severalwhitespaces
      @severalwhitespaces 3 หลายเดือนก่อน +8

      its wild - WILD - omg the mortification

    • @TheKeirsunishi
      @TheKeirsunishi 3 หลายเดือนก่อน +71

      @@AncientSlugThrower All the identifying information mentioned in the video could be from a machine dedicated to black hat activities. There is no mention of selfies or anything actually personal. They linked him through other crimes he was already suspected of committing

  • @bronysrule
    @bronysrule 3 หลายเดือนก่อน +2805

    “Only a fool learns from his own mistakes. The wise man learn from the mistakes of others”- Otto Von Bismark

    • @DxBlack
      @DxBlack 3 หลายเดือนก่อน +137

      ...of course this suggests that everyone is a fool.

    • @catdaddycoins
      @catdaddycoins 3 หลายเดือนก่อน +56

      or that you aren't in uncharted territories lol @@DxBlack

    • @Personalinfo404
      @Personalinfo404 3 หลายเดือนก่อน +100

      "a stupid man will make mistakes and never learn, a dumb man will make mistakes and learn from its experience, a smart man will live his life worrying about not making mistakes, and a wise man will learn lessons from the mistakes of other men"

    • @Knightmare-vc8qg
      @Knightmare-vc8qg 3 หลายเดือนก่อน +76

      I learn from the mistakes of people who take my advice

    • @brynna77
      @brynna77 3 หลายเดือนก่อน +20

      This man you quote is clearly not a scientist

  • @blackpolygon9306
    @blackpolygon9306 3 หลายเดือนก่อน +815

    The hacker accidentally uploading their home directory is a plot twist that would be called "unbelievable", "lazy wiriting" and similar if it would happen in a movie/show. Literally can't write that stuff.

    • @Sombre____
      @Sombre____ 3 หลายเดือนก่อน +21

      I don't understand why he didn't use a virtual machine in the first place ... Lazy ?

    • @PompaTG
      @PompaTG 3 หลายเดือนก่อน +35

      @@Sombre____ That's beyond lazy. Just having a pre-configured and clean image without any PII or login credentials to spin up a new VM for a new hack is not hard, doesn't take much effort or time...

    • @counterleo
      @counterleo 3 หลายเดือนก่อน +33

      If I was law enforcement I would probably go "hah nice lure, I'm not gonna fall for that" and not even bother with that lead

    • @aldrinmilespartosa1578
      @aldrinmilespartosa1578 3 หลายเดือนก่อน +34

      Reality is often bat shit crazy because fiction needs to make sense.
      We humans hated deus makima

    • @brahtrumpwonbigly7309
      @brahtrumpwonbigly7309 3 หลายเดือนก่อน

      And it would be all of those things lmao

  • @waryth4475
    @waryth4475 3 หลายเดือนก่อน +1843

    Poor Monero-chan getting her reputation damaged with this blunder.

    • @monke7566
      @monke7566 3 หลายเดือนก่อน

      ​@@SmolSpodermonero is battle tested by governments, and crypto cannot ever be made illegal because it's not regulated in the first place, "illegality" simply means places like binance wont be trading it anymore

    • @anonemoose102
      @anonemoose102 3 หลายเดือนก่อน +8

      ​@@SmolSpoderstriessand effect?

    • @jsadecki1
      @jsadecki1 3 หลายเดือนก่อน

      More users in Monero enhance security by creating a larger and more decentralized network, making it difficult for malicious actors to gain control or manipulate the system@@SmolSpoder

    • @HypeXesk
      @HypeXesk 3 หลายเดือนก่อน +31

      ​@@SmolSpodertry Linux Mint out, one of the easiest things I used even easier than windows 11 (less repeated places for the same things like settings)

    • @Rock_Appreciator
      @Rock_Appreciator 3 หลายเดือนก่อน +16

      ​@@HypeXesk Mint is my personal favorite too. So much better than windows. I'd be 100% Linux nowadays if I didn't need Windows for work & a few games I play occasionally with relatives.
      Mint is so smooth and straightforward, I have nothing but respect for the developers

  • @Onni-
    @Onni- 3 หลายเดือนก่อน +1902

    I think the login for vastaamo was something like admin admin. No wonder they got extorted.

    • @jimbo-dev
      @jimbo-dev 3 หลายเดือนก่อน +321

      In some sources they mentioned root:root as the credentials

    • @ApocDevTeam
      @ApocDevTeam 3 หลายเดือนก่อน +198

      Don't think people would openly talk about their deepest secrets if they knew the dialog was stored on such a database..

    • @blackpaperbold
      @blackpaperbold 3 หลายเดือนก่อน +94

      I lock my door using toothpick, the most secure lock in the world.

    • @cowewu
      @cowewu 3 หลายเดือนก่อน +36

      root root

    • @stevengill1736
      @stevengill1736 3 หลายเดือนก่อน +74

      I think a great root login would be, "rootie toot toot, rootie toot toot, we're the boys from the institute"
      Whoops, probably gave it away....

  • @dontbestupid6664
    @dontbestupid6664 3 หลายเดือนก่อน +895

    Scamming sick people who are already spending money they dont have on saving their own lives? How low can you go?

    • @More_Row
      @More_Row 3 หลายเดือนก่อน +77

      I know right.

    • @michaelm1
      @michaelm1 3 หลายเดือนก่อน +51

      Exactly. Well put!

    • @Itsgone99
      @Itsgone99 3 หลายเดือนก่อน

      All that to keep the baby fat on his face he'd lose if he just got a job like the rest of us. 😁
      Starting to consider Snowden was wrong.

    • @onebacon_
      @onebacon_ 3 หลายเดือนก่อน +164

      Could've gone for a bank or insurances or any other scummy business, but no his "pressure point" were real people. And obviously the Company doesn't give a fuck about their patients privacy. This was a goner from the start.

    • @Nik-rx9rj
      @Nik-rx9rj 3 หลายเดือนก่อน +121

      Literally the worst crime you could commit. I remember hearing about a few ransomware worms hitting some hospital's networks. Once the attackers found out the hospital's were hit, they gave them the keys to decrypt their infected systems.

  • @cleoh3
    @cleoh3 3 หลายเดือนก่อน +770

    If this guy wasn't such a showman, and had just contacted vastaamo directly, they probably would have paid right up if it meant it stayed out of the news and the data didn't get released. As soon as the media picks it up, they can't pay because it would be a PR nightmare. Makes you wonder how many companies are extorted by hackers without egos and we never even hear about it.

    • @hanro50
      @hanro50 3 หลายเดือนก่อน +77

      Well, a fair amount of the time the hacker collects a bug bounty instead.
      The more damming the hack, the higher the bounty.

    • @tehonlynoobs5556
      @tehonlynoobs5556 3 หลายเดือนก่อน +74

      If im not wrong there a lot of hacker did contact the company first but they ignore it cuz authorities like cops always suggest to ignore or not to pay them
      This is why a lot of them goes to media social and post the threat

    • @SillyMonkeysLikeApples
      @SillyMonkeysLikeApples 3 หลายเดือนก่อน +6

      He did many noob mistakes... thats all,..

    • @maxbd2618
      @maxbd2618 3 หลายเดือนก่อน +35

      @@hanro50 a bug bounty payout is nothing compared to what u can get from a company off of ransomware so why would they do that

    • @oddspaghetti4287
      @oddspaghetti4287 3 หลายเดือนก่อน +30

      There's no quarantee that a ransomer doesn't continue asking for money even after you pay since there is no way to quarantee that he would delete the files. So paying them is completely useless.

  • @dshaf7
    @dshaf7 3 หลายเดือนก่อน +94

    Mf was finnish before he even started

  • @maiastniki
    @maiastniki 3 หลายเดือนก่อน +568

    why is it ALWAYS someone telling on themselves????

    • @MentalOutlaw
      @MentalOutlaw  3 หลายเดือนก่อน +392

      Self snitching has been the best aid to law enforcement since the beginning.

    • @konrad94886
      @konrad94886 3 หลายเดือนก่อน +59

      overconfidence I'd assume. The hacker just ran the command to zip the data and didn't bother to double check. After all, if you call yourself a true hacker, there's no way you could make a mistake, right?

    • @Splarkszter
      @Splarkszter 3 หลายเดือนก่อน

      ​@@konrad94886 That seems plausible.
      Quirks about working directories and not being organized

    • @FLAXMS
      @FLAXMS 3 หลายเดือนก่อน +31

      You only hear about the dumb hackers getting caught through their idiocy. WAY MORE fishing attacks happen every year than you think but it's all a bit hush-hush.

    • @Octaviu5
      @Octaviu5 3 หลายเดือนก่อน +18

      The finngolian is obviously a social engineer or a skid and not a hacker.

  • @pajeetsingh
    @pajeetsingh 3 หลายเดือนก่อน +370

    tarred his home folder? he was surely stoned to do that.

    • @cc-dtv
      @cc-dtv 3 หลายเดือนก่อน +59

      without a doubt, prob something stronger tbh

    • @RiwenX
      @RiwenX 3 หลายเดือนก่อน +30

      Vodka

    • @strongestgamer2501
      @strongestgamer2501 3 หลายเดือนก่อน +40

      Just the fact he doesn't notice he was uploading a several gigabyte file suggests he was smoking something

    • @tvm2209
      @tvm2209 3 หลายเดือนก่อน +4

      Adderal

    • @cleety4530
      @cleety4530 3 หลายเดือนก่อน +9

      probably was drunk.

  • @SongOfDeer
    @SongOfDeer 3 หลายเดือนก่อน +336

    8:24 - We went from "Alright, the guy got a bit cheeky and impatient" to "How was this man even smart enough to hack the database in the first place?" in an instant. Good lord, how does this even happen?

    • @hyde4004
      @hyde4004 3 หลายเดือนก่อน +99

      Well it wasn't even much of a hack, as the server the db was running on was even indexed by Google and had no firewall, and also had default passwords, like admin admin or something along those lines. So literally anybody who came across the servers adress and decided to try default logins had access to the entire db :D

    • @SongOfDeer
      @SongOfDeer 3 หลายเดือนก่อน +97

      @@hyde4004 So everybody involved was an absolute muppet; brilliant!

    • @Sombre____
      @Sombre____ 3 หลายเดือนก่อน +13

      There is always weak DB in the wild. Not everyone take safety seriously. Lazy admin make easy password. You just need to find on of those DB.

    • @hyde4004
      @hyde4004 3 หลายเดือนก่อน +39

      @@SongOfDeer Basically yes. It was some of the most grossly negligent handling of confidential data in Finnish history. Their security was basically: surely nobody will find the address for our publicly accessible server. Fucking brilliant.

    • @Tattootin
      @Tattootin 3 หลายเดือนก่อน

      @@hyde4004this careless out of sight out of mind type set up seems to be the internet as a whole? Like if the internet was physical, the bigger corporations would be in buildings made of cardboard and duct tape, while the small dudes and singular users are going to be having fortresses that go invisible with such crazy tech. It’s crazy how much more people neglect when certain circumstances change from physical to digital, I guess the doors that aren’t passed through much are left wide open?

  • @Hentai_Protag
    @Hentai_Protag 3 หลายเดือนก่อน +155

    "Even a fish wouldn't have gotten caught if it just kept its mouth closed."
    - some random guy on the internet

    • @WakandaDigitalGroup
      @WakandaDigitalGroup 3 หลายเดือนก่อน +1

      😂😂😂

    • @OGPimpin
      @OGPimpin 2 หลายเดือนก่อน

      Gonna need that on a tshirt

  • @More_Row
    @More_Row 3 หลายเดือนก่อน +293

    Deserved arrest. Don't fuck with peoples mental health records or private data like that.

    • @michaelm1
      @michaelm1 3 หลายเดือนก่อน +29

      Absolutely.

    • @ennui7778
      @ennui7778 3 หลายเดือนก่อน

      Yup lol. Can't say I'm surprised that a hacker that decided that this makes a great target, turned out to be dumb enough to essentially broadcast his name and identity in blinking neon letters to Finnish authorities.
      If he was hellbent on picking a morally disgusting target, though, he could've at least tried thinking for half a second when deciding how best to extort said target. but no. rather than contacting them privately first to give them the opportunity to "save face" this idiot went straight to image boards to boast about his leet hax. good job dumbass, now why are they going to care if stolen patient records are published or not? they're pretty much fucked facing a massive PR disaster either way now so they have no incentive to care. they already demonstrated they don't give a shit about their patients wellbeing or confidentiality. but they might've been willing to pay to avoid the public debacle...if he had bothered asking.
      but there really is no excuse for the type of target he chose and especially for extorting patients directly. potential targets are literally everywhere in almost every sector of the economy, because executives ALWAYS target IT/cybersecurity when cost cutting. they're viewed as "nonessential expenditures" and slashing them never harms whatever the business' core profit-making strategy is....... until, of course, it does.

    • @accelerationquanta5816
      @accelerationquanta5816 3 หลายเดือนก่อน +1

      Cringe

    • @More_Row
      @More_Row 3 หลายเดือนก่อน +45

      @@accelerationquanta5816 Your communism is cringe

    • @lv1543
      @lv1543 3 หลายเดือนก่อน +8

      Therapy is a meme

  • @BillyBob-kj4qq
    @BillyBob-kj4qq 3 หลายเดือนก่อน +292

    Hack snitches telling all their business, sitting in the court and be their own star witness.

    • @refficial
      @refficial 3 หลายเดือนก่อน +32

      do you see the perpetrator? yeah i’m right here

    • @Toresdale
      @Toresdale 3 หลายเดือนก่อน

      @@refficial Fuck around, get the whole server sent up for years, uh

    • @yis9259
      @yis9259 3 หลายเดือนก่อน

      ​@@refficialfuck around get the whole hacking group sent up for years

    • @placeholder4988
      @placeholder4988 3 หลายเดือนก่อน +11

      r.i.p mf doom

    • @parashkevdraganov2395
      @parashkevdraganov2395 3 หลายเดือนก่อน

      @@placeholder4988 ALL CAPS WHEN YOU SPELL THE MAN NAME

  • @ApocDevTeam
    @ApocDevTeam 3 หลายเดือนก่อน +170

    Their security policy was probably "it won't happen to us".

    • @ImNotPotus
      @ImNotPotus 3 หลายเดือนก่อน +15

      "We would be considered paranoid if we thought this could happen which would recuse us from conducting the therapy."

    • @killerkonnat
      @killerkonnat 3 หลายเดือนก่อน +11

      As someone from Finland following these news years ago, it basically was.

    • @PompaTG
      @PompaTG 3 หลายเดือนก่อน

      "Why would anyone want to target us? We're not that important, so no one will bother"

    • @brahtrumpwonbigly7309
      @brahtrumpwonbigly7309 3 หลายเดือนก่อน +1

      Normalcy bias

    • @robertgrays8790
      @robertgrays8790 3 หลายเดือนก่อน

      The probability of a double-ransomware attack is low, but never zero.

  • @thestoryteller2514
    @thestoryteller2514 3 หลายเดือนก่อน +265

    When I'm in a shilling monero competition and my opponent is mental outlaw

    • @William0271
      @William0271 3 หลายเดือนก่อน +31

      Shilling is a strong word. He alone won't significantly change the price over the span of a few months

    • @itsawill9268
      @itsawill9268 3 หลายเดือนก่อน +32

      Fan of the project ≠ shill

    • @brahtrumpwonbigly7309
      @brahtrumpwonbigly7309 3 หลายเดือนก่อน +11

      Was the video true or not? It doesn't matter if he is defending monero if his defense is true.

    • @treemallow757
      @treemallow757 3 หลายเดือนก่อน +1

      He right tho

    • @MrCmon113
      @MrCmon113 3 หลายเดือนก่อน +2

      What's better than monero for conceilability?

  • @nou712
    @nou712 3 หลายเดือนก่อน +97

    4:16 yulilawlta, towrilawlty..... 🤣 damn, he really took the pronunciation to the next level. One of our great joys is foreigners trying to pronounce anything in Finnish.

    • @videosambo01
      @videosambo01 3 หลายเดือนก่อน +23

      Toi oli kyl niin teurastettu lausunta et toon tosta clipin soundboardiin :D

    • @Miifor
      @Miifor 3 หลายเดือนก่อน +3

      root:roottista :-DDD

    • @SirSogMuffins
      @SirSogMuffins 3 หลายเดือนก่อน

      you speak a fake elvish monstrosity of a language

    • @thomastheeternaltormentor287
      @thomastheeternaltormentor287 3 หลายเดือนก่อน +3

      because yall don't use ü and confuse everybody with your y, also since when is finland a federation?

    • @gxooo
      @gxooo 3 หลายเดือนก่อน +4

      huutista :DD

  • @iamfishmind
    @iamfishmind 3 หลายเดือนก่อน +64

    heard a hundred thousand facepalms when he said he uploaded his f'ing home folder

  • @dzuchun
    @dzuchun 3 หลายเดือนก่อน +338

    "archive contained his entire home folder"
    my live reaction:
    AAAAAAAAAWWWW!!!
    EEEEEEEEEEEWWWW!!!
    😂😂
    "tracing monero" never was easier

    • @billbuyers8683
      @billbuyers8683 3 หลายเดือนก่อน +2

      so traced now like never will it never not be traced. much tech they are

    • @_idiot
      @_idiot 3 หลายเดือนก่อน +56

      "hey guys i also included my ssh keys, IP addresses to all my servers, and cute pics of me in my programming socks"

    • @counterleo
      @counterleo 3 หลายเดือนก่อน +16

      I was expecting "text doesn't take much space, the archive was 11GB because it contained imagery like CT scans", I really did NOT expect "it contained his entire home folder" hahah brilliant plot twist
      Why would he not double check the contents, and if you are gonna make a database of mostly text-based records available on Tor why on earth would you not gzip your tar, has this guy ever used a Unix-like OS before or what 😂

    • @Moonstone-Redux
      @Moonstone-Redux 3 หลายเดือนก่อน +11

      @@counterleo Uploading his entire home folder. At this point he might as well have ripped the hard drive out of his computer and mailed it to YLE (the local news network).

    • @starblaiz1986
      @starblaiz1986 3 หลายเดือนก่อน +3

      My live reaction was more like "HUUUUUH?!?! WHY THOUGH?!?!" 😂

  • @hellbilly8747
    @hellbilly8747 3 หลายเดือนก่อน +31

    "Uploaded his home folder in the tar file" im deceased ☠️

    • @fartful
      @fartful 3 หลายเดือนก่อน +2

      💀💀💀

  • @top0657
    @top0657 3 หลายเดือนก่อน +81

    One of the biggest mistakes he made (along with the tar fuck up) was that he talked to the police. I read the interrigation documents and were baffeled to see that there were pages after pages on him just casually talking and smart-assing with the police, leading him to straight up admit many of the links in the picture shown in the video. As Finland has a robust western justice system where you need to have proven then suspicion beyond a reasonable doubt I think it might even have been very unlikely to get him convicted without him talking so much.

    • @B1gLupu
      @B1gLupu 3 หลายเดือนก่อน +17

      The biggest mistake his mother made was seeing that pregnancy into term. He ruined so many lives.

    • @andre_santos2181
      @andre_santos2181 หลายเดือนก่อน +2

      Indeed. On some legal systems, the confession to Police is already proof. On others, only the confession to a judge is a proof, however, spelling the beans to the police make they go after more proof easily

  • @Rob-operator
    @Rob-operator 3 หลายเดือนก่อน +49

    Vastaamo wasn't an online therapy service, they were a therapist center with multiple locations in alot of major cities in Finland.

    • @seneca983
      @seneca983 2 หลายเดือนก่อน +2

      They did offer online therapy too.

  • @hamster3171
    @hamster3171 3 หลายเดือนก่อน +81

    the weakest link of cybersecurity is the human

  • @that_is_not_me
    @that_is_not_me 3 หลายเดือนก่อน +241

    How do you accidentally tar your whole home folder, upload it, and not notice that it's way bigger than expected?

    • @DonVigaDeFierro
      @DonVigaDeFierro 3 หลายเดือนก่อน +121

      Being too drunk and straight out of the sauna.

    • @mr.cauliflower3536
      @mr.cauliflower3536 3 หลายเดือนก่อน +4

      Right?

    • @warhawk_yt
      @warhawk_yt 3 หลายเดือนก่อน +29

      At least double check the archive before publicly uploading it. I am assuming he just accidentally forgot to add the right folder at the end of the path when archiving. I would of noticed when just a bunch of document files were taking a lot longer to archive than it should.
      Edit: Also, you should always double check commands you are running before doing them especially when it comes to modifying/managing files. You never know if a command you think you are running is safe but a typo accidently makes it dangerous.

    • @Mak_0007
      @Mak_0007 3 หลายเดือนก่อน +5

      He didn't use a separate pc for his hacking stuff it seems

    • @bbedlock1869
      @bbedlock1869 3 หลายเดือนก่อน +17

      Unless you use a specific GUI application to do it, TAR files are generally created from the command line. TAR files are created from the 'current working directory', so you have to tell Terminal/Command Prompt to go to a particular folder before telling it to archive. If you don't do this, you will get everything from the root onwards. Then at the end you'd just have one giant file which is too much of a pain to try to extract in order to check. Kind of an easy mistake to make.

  • @whatamievendoing
    @whatamievendoing 3 หลายเดือนก่อน +38

    Glad Monero isn't compromised and it was just an idiot criminal using BTC instead of XMR to begin with

  • @brimmed
    @brimmed 3 หลายเดือนก่อน +23

    It's kind of alarming knowing that there's companies that aren't securing our data properly. My buddy just got a job somewhere doing some IT work. He told me there's thousands of social security #s unencrypted stored as plain text, along with names and addresses on his company's server.

    • @DingoYabuki
      @DingoYabuki 3 หลายเดือนก่อน +4

      The place I work for does this too, it's so fucked...

    • @nicksjacku9750
      @nicksjacku9750 3 หลายเดือนก่อน

      doesn't surprise me

    • @modernbassheads5051
      @modernbassheads5051 2 หลายเดือนก่อน +1

      @@DingoYabukireport them to the FCC

    • @HelloKurse
      @HelloKurse 2 หลายเดือนก่อน

      Yeah I'm 99% sure that's been illegal for quite awhile now. Even storing passwords as plain text is fking BAD, let alone SS#.. easy payday.

    • @HelloKurse
      @HelloKurse 2 หลายเดือนก่อน

      Inefficent protection of valuable data is REALLY BAD

  • @Relkond
    @Relkond 3 หลายเดือนก่อน +13

    Very often, the weakest point in a system is with the interface between the keyboard and the chair.

  • @FlymanMS
    @FlymanMS 3 หลายเดือนก่อน +34

    “How did you catch me guys??? - You left your wallet with ID”

  • @AKK5I
    @AKK5I 3 หลายเดือนก่อน +136

    It's so over...

    • @VolkColopatrion
      @VolkColopatrion 3 หลายเดือนก่อน +1

      How do you mean?

    • @veryhuman7472
      @veryhuman7472 3 หลายเดือนก่อน +2

      what's over?

    • @OB.x
      @OB.x 3 หลายเดือนก่อน +23

      They know shut it down shut it all down!

    • @incinncity
      @incinncity 2 หลายเดือนก่อน +1

      Yea bud hope you didn't tell your therapist anything that ya should've took to the grave 💀

  • @itsawill9268
    @itsawill9268 3 หลายเดือนก่อน +20

    To hack a psychotherapy clinic… how evil thank god the hacker had bad opsec

  • @TheUnRemarkableGamer
    @TheUnRemarkableGamer 3 หลายเดือนก่อน +26

    I could give you a literal documentaries worth of information on this guy and used to know zeekill for years. We lost contact about the time he started to become somewhat known after his lizard squad antics. He used to hang out with the Team Avolition crowd quite often and was an absolute demon of chaos and laughter. Towards the end, he really started to push things a bit far, swatting his opps, and streaming it in the community teamspeak. During that era, he along with Aurora and a few others I believe had one of the largest botnets in existence at the time.
    Edit: Just to be clear, while I considered zeekill a close friend at one point the crimes he's up to now are beyond "the lulz" or mostly innocent trolling we did.

    • @virusneverdies
      @virusneverdies 3 หลายเดือนก่อน

      Shoutout to vinnie omari

    • @Peeking
      @Peeking 2 หลายเดือนก่อน +1

      Thought I was the only one who knew about him and the lizard squad thing,

    • @incinncity
      @incinncity 2 หลายเดือนก่อน +2

      I just have one question, the one everyone's asking. Was he a drinker? Cause how tf do you upload the home folder of the server to tor as a tar 😭

    • @TheUnRemarkableGamer
      @TheUnRemarkableGamer 2 หลายเดือนก่อน +1

      @@incinncityI didn't really know him as an addict, but I do remember him ordering multiple thousand dollar bottles of wine on a stolen credit card.

    • @luislongoria6621
      @luislongoria6621 หลายเดือนก่อน

      Things I learned from this video: the entire population of Finland is 500 and 5 people sitting in the same room have styled themselves as hackers so annoying your housemates can lead to an embarrassing whoopsie the second you walk away from the keyboard

  • @davida3283
    @davida3283 3 หลายเดือนก่อน +19

    sudo tar /home: I gonna end this man's while career

  • @Name-ot3xw
    @Name-ot3xw 3 หลายเดือนก่อน +24

    Finnish language has got to narrow it down to about 35 people + a particularly well read reindeer.

    • @sycration
      @sycration 3 หลายเดือนก่อน +9

      Up in the north, in Lappi region, the Sami people keep their IT infrastructure mounted to their reindeer herds so they can run away when the feds come looking

  • @Wiiownyou
    @Wiiownyou 3 หลายเดือนก่อน +18

    I knew you'd have a video on this the moment I saw how brightly the headlines were glowing

  • @incorrectbeans
    @incorrectbeans 3 หลายเดือนก่อน +12

    Now there's a guy who would have been way better off actually using the services of that company instead of hacking them.

  • @Gideonrex1
    @Gideonrex1 3 หลายเดือนก่อน +19

    Guy after posting entire home folder: “WAIT WAIT WAIT WAIT!!! NO NO NO NO!!!”

    • @strongestgamer2501
      @strongestgamer2501 3 หลายเดือนก่อน +8

      "Whoopsie doodle"

    • @Pyovali
      @Pyovali 2 หลายเดือนก่อน +1

      More like "EI SAATANA, MITÄ MINÄ OLEN TEHNYT?"

  • @amarodsv
    @amarodsv 3 หลายเดือนก่อน +15

    6:13 ..."which makes things much easier for... authorities" while showing the Coffeezilla background set, nice touch

  • @hahhuli
    @hahhuli 3 หลายเดือนก่อน +7

    This thing was so bad, that the Government allowed the "injured party" (i.e people who were customers of Vastaamo) to change their social security number free of charge.

  • @spacecowboy511
    @spacecowboy511 3 หลายเดือนก่อน +19

    A real life vampire, I can’t believe it

  • @fabbritechnology
    @fabbritechnology 3 หลายเดือนก่อน +7

    Not hackers, but “script kiddies”. Dude didn’t even understand how folders and archive files work.

  • @ChrisHaefner
    @ChrisHaefner 3 หลายเดือนก่อน +1

    Thank you for covering this. I had a lot of questions about this case you answered

  • @warecamel
    @warecamel 3 หลายเดือนก่อน +5

    I ordered the PDFs involving this case from the national bureau of investigation here in Finland. There's some pretty interesting stuff in the documents. There were some American FBI agents working on the case and i found out that i had previously underestimated the feds' capability for cracking ciphers.

    • @fflecker
      @fflecker หลายเดือนก่อน

      Could you publish the PDF for the others ?

  • @YoanGonzalez-yr2rf
    @YoanGonzalez-yr2rf 3 หลายเดือนก่อน +3

    Yo your shirts have gotten a lot better in design. I would really consider buying one or two to support the channel. Keep up the great work.

  • @hexstaticloonatic4194
    @hexstaticloonatic4194 3 หลายเดือนก่อน +3

    Was watching a two year old video of yours regarding kax17 and the tor network. While I am good enough at self teaching that I can probably get it right with some research (and already have pretty decent understanding of how networks operate), I would love an in depth series on how tor works and how to participate with proper due diligence/OPSEC (both as a relay as well as an exit note, for the bravest out there). It would definitely help with getting more people to act as relays, which I feel is a great endeavor. Hell depending on how this year goes and how much time I can throw at learning the ins and outs of tor, I might even start a channel and do it myself, just for the cause

  • @abdou.the.heretic
    @abdou.the.heretic 3 หลายเดือนก่อน +253

    Well the glowies always win because evil is actually very motivated.

    • @brettlaw4346
      @brettlaw4346 3 หลายเดือนก่อน +25

      If you ever saw Wonder Woman, the first one, she kills the villain and they kept fighting and she didn't understand why. It is because of economics. They are paid and unless they individually suffer economic loss, they won't understand to stop because the authorities they choose to obey haven't told them to stop.

    • @boosiefade01
      @boosiefade01 3 หลายเดือนก่อน

      woww marvel cinematic universe is soo deep bro the only way i understand concepts is through a superhero lense.@@brettlaw4346

    • @jevvf3246
      @jevvf3246 3 หลายเดือนก่อน +1

      Sounds like a weird interpretation. Could also just be a cultural thing. Maybe in Wonder Woman's world, they will leave the world with dignity and surrender to the more powerful individual after they "lost." But she encounters someone who continues to fight even after they've been proven inferior. That would puzzle anyone.

    • @anonemoose102
      @anonemoose102 3 หลายเดือนก่อน +10

      But the glowies aren't 100% evil, just saying

    • @roguis3451
      @roguis3451 3 หลายเดือนก่อน +4

      @@jevvf3246 I think the point was that she thought all of the war was happening because of an evil god having his way, but the reality is that the war was happening because of human greed or whatever.

  • @guilhermepessoa3594
    @guilhermepessoa3594 3 หลายเดือนก่อน +12

    Some people are too proud to stay quiet.

  • @alexanderSydneyOz
    @alexanderSydneyOz 3 หลายเดือนก่อน +47

    "whoopsie" indeed!
    Dare I say, there are no doubt hackers who *don't* make these mistakes, and they are the ones who don't end up in court!

  • @_ipsissimus_
    @_ipsissimus_ 3 หลายเดือนก่อน +7

    I love the supposedly finnish b roll footage you have in the background

  • @happycakes1946
    @happycakes1946 3 หลายเดือนก่อน +58

    I had to pause to laugh for 10 seconds on that one! Lizard boy can hack but tar is hard.

  • @tfwmemedumpster
    @tfwmemedumpster 3 หลายเดือนก่อน +24

    How the hell do you not notice an archive being 11GB while uploading it through tor? The only way he could have missed it being that big if he uploaded it through clearnet with a very fast connection. Uploading through tor would have taken several hours if not days. He would definitely have noticed it was taking that long. So i have to conclude he uploaded it through a clearnet connection so they would have likely got him anyway even if it was just the records

    • @strongestgamer2501
      @strongestgamer2501 3 หลายเดือนก่อน +6

      Or he was on something.
      He looks like he would be most of the time

    • @A1ko_
      @A1ko_ 3 หลายเดือนก่อน +1

      tbh he could've gotten a bulletproof vps

    • @CupoChinoMusic
      @CupoChinoMusic 3 หลายเดือนก่อน

      he prolly either:
      - hosted the files locally in his home, and exposed an onion service
      - whatever you said

    • @A1ko_
      @A1ko_ 3 หลายเดือนก่อน

      my ass would rather get a vps I bought with xmr because tor is well, slow@@CupoChinoMusic

    • @fflecker
      @fflecker หลายเดือนก่อน

      I sent an 8 MB PDF file as my full application to an office and they just could find the motivation letter on top of it. People are as dumm as the last quarter of a pig.

  • @Garwinium
    @Garwinium 3 หลายเดือนก่อน +9

    You know it's gonna be a good cybersecurity video when it's got an anime waifu on the thumbnail

    • @yis9259
      @yis9259 3 หลายเดือนก่อน +2

      And/or wojak

  • @johnnyhellfire6
    @johnnyhellfire6 3 หลายเดือนก่อน +22

    I love how the feds like to act like they out smarted a master criminal, when they just got him from dumb luck lol
    Like "see!! See!! We are smarter !!!!"

    • @AKuTepion
      @AKuTepion 3 หลายเดือนก่อน +1

      They are smarter. The guy is dumb it hurts to watch.

    • @ArchOfficial
      @ArchOfficial 3 หลายเดือนก่อน +7

      Finland is a Republic, not a Federation.

    • @johnnyhellfire6
      @johnnyhellfire6 3 หลายเดือนก่อน +2

      @@ArchOfficial bet your fun at parties lol

    • @ArchOfficial
      @ArchOfficial 3 หลายเดือนก่อน +11

      @@johnnyhellfire6 I'm not, but at least I don't have Americanization brainrot.

    • @johnnyhellfire6
      @johnnyhellfire6 3 หลายเดือนก่อน

      @@ArchOfficial and at least I get laid, so I guess we are even...

  • @Fircasice
    @Fircasice 3 หลายเดือนก่อน +4

    Are you seriously telling me that this dude managed to steal enough sensitive data from that multi million dollar company to make it ultimately go bankrupt but at the same time he was dumb enough to upload an archive containing his entire home folder? How is that even possible?

    • @Tn5421Me
      @Tn5421Me 2 หลายเดือนก่อน

      Zeekill was handed every success in a golden platter by his betters

  • @jonbikaku6133
    @jonbikaku6133 3 หลายเดือนก่อน +14

    This gotta be the craziest opsec oopsie ever..

  • @pompomaddons
    @pompomaddons 3 หลายเดือนก่อน +36

    oops sec

  • @zeeMuniStacksBundles
    @zeeMuniStacksBundles 3 หลายเดือนก่อน

    One of my new favorite sec ops videos. Excellent presentation.

  • @Splarkszter
    @Splarkszter 3 หลายเดือนก่อน +25

    How dumb(or drunk because finland) you have to be to upload your home folder.

    • @datajake1999
      @datajake1999 3 หลายเดือนก่อน +1

      My thoughts exactly.

  • @ashishpatel350
    @ashishpatel350 3 หลายเดือนก่อน +17

    if you uploaded your entire home directory you deserve to go to jail and toss salads

  • @ZingsVideos
    @ZingsVideos 3 หลายเดือนก่อน +7

    ""I always mess up some mundane detail" -- Michael Bolton, Office Space

    • @orange-os7nh
      @orange-os7nh 3 หลายเดือนก่อน

      This. IS A FUCK

  • @Zakru
    @Zakru 3 หลายเดือนก่อน +3

    Uncanny to see a cool channel cover a story from here, your subscriber count might as well be 10% of our population.

  • @galimantis190
    @galimantis190 3 หลายเดือนก่อน

    5:32
    I was thinking about that same 'green' text the other day, thanks for reminding me of the post.

  • @realmstupid-on8df
    @realmstupid-on8df 3 หลายเดือนก่อน +15

    This guy had more tar then a pack of Newport cigarettes

  • @avcat1209
    @avcat1209 3 หลายเดือนก่อน +11

    It was cool to see Tony Soprano again after all these years.

  • @jaimeortega4940
    @jaimeortega4940 3 หลายเดือนก่อน +61

    KRP is claiming a method to fully trace Monero. Of course they "won't disclose the tracing method" so I think it is probably BS for the most part. You're right bad opsec plus the reverse trace of Bitcoin in some manner.

    • @0x32_l3git
      @0x32_l3git 3 หลายเดือนก่อน +4

      krp?

    • @user-to9lk8ix6h
      @user-to9lk8ix6h 3 หลายเดือนก่อน

      @@0x32_l3gitKoach Red Pill (rip)

    • @junfour
      @junfour 3 หลายเดือนก่อน

      @@0x32_l3git Keskusrikospoliisi

    • @Huijaaja42
      @Huijaaja42 3 หลายเดือนก่อน +1

      @@0x32_l3git KRP = Keskusrikospoliisi (National Bureau of Investigation) They are/were in charge of this investigation

    • @killerkonnat
      @killerkonnat 3 หลายเดือนก่อน

      The Finnish tax authority also claims that they will know if you're hiding crypto profits from them.
      Which they absolutely don't because the country is way too small to pressure any exchanges to share their records, which is why there haven't been any data sharing agreements.. And if you aren't trading on any public exchanges, lmao good luck. Government is just trying to scare people. Situation might be changing in 2024 though with new EU regulations for public exchanges.

  • @NicholasHenkey
    @NicholasHenkey 3 หลายเดือนก่อน +20

    Used to know a guy that stole video games from BestBuy to resell them. Somehow he started spending money WAY outside his income range at the same store he was stealing from. Often criminals want to get caught

    • @DonVigaDeFierro
      @DonVigaDeFierro 3 หลายเดือนก่อน +8

      You can hide the hand that steals but not the hand that spends.

    • @mytech6779
      @mytech6779 3 หลายเดือนก่อน

      How do you get money way outside your range shoplifting video games? Hot items don't sell for full retail, nor is it a high volume market.

    • @Dzeividz
      @Dzeividz 3 หลายเดือนก่อน

      Did he really earn that much from just selling stolen games tho?

    • @NicholasHenkey
      @NicholasHenkey 3 หลายเดือนก่อน

      ​@@Dzeividz I think it was $30k over 6 months in 2009 money. Inflation adjusted that"s like $100k per year plus his hourly rate at BB​Y

    • @mytech6779
      @mytech6779 3 หลายเดือนก่อน +2

      @@NicholasHenkey So he worked at the store. That changes the story substantially.

  • @zane62135
    @zane62135 3 หลายเดือนก่อน +26

    It's amazing how someone can be so smart, yet so stupid.

    • @user-vn6jw4fc6h
      @user-vn6jw4fc6h 3 หลายเดือนก่อน +10

      That hacker has been arrested multiple times for hacking in the last decade. He isn’t that good.

    • @TheEsotericProgrammer
      @TheEsotericProgrammer 3 หลายเดือนก่อน +3

      You really don't need to be that smart for stuff like this probably just a script kiddie

    • @WalterClements.official
      @WalterClements.official 3 หลายเดือนก่อน +1

      ​@@TheEsotericProgrammerwoah, whats wrong?

  • @rproctor83
    @rproctor83 3 หลายเดือนก่อน +3

    Hacker: I have all your medical info!
    Me: Okay.
    Hacker: I am in your bank account!!
    Me: Have fun.
    Hacker: I have access to your WOW account!
    Me: I will hunt you down.

  • @liquidkameleon
    @liquidkameleon 2 หลายเดือนก่อน

    Now that's what I call a smooth segue into the merch store advert.

  • @elzabethtatcher9570
    @elzabethtatcher9570 3 หลายเดือนก่อน +6

    Note to self: when commiting criminal activities, do not send home folder to the victims.

  • @LAZYB00GiE
    @LAZYB00GiE 3 หลายเดือนก่อน +7

    This guy was part of the Christmas psn ddos attack back in the 2014

    • @70kg589
      @70kg589 5 วันที่ผ่านมา

      They need to put him under the prison for that lol I was trying to play cod zombies that day

  • @magneticshrimp7429
    @magneticshrimp7429 3 หลายเดือนก่อน +5

    Rule of thumb: if it is a significant hack and it points toward Finland, it's always Julius.
    At least he is the guy who always takes the fall haha

  • @antonberg1131
    @antonberg1131 3 หลายเดือนก่อน +1

    Thank you, great content! Just want to also comment that Finland does indeed exist.😊

  • @kRySt4LGaMeR
    @kRySt4LGaMeR 3 หลายเดือนก่อน

    holy shit, I couldn't hold laughter has the video went on. just keeps on giving

  • @def1nt
    @def1nt 3 หลายเดือนก่อน +8

    I work with Linux for almost ten years and still have to check man tar every time. I feel this guy so much...

  • @iCrimzon
    @iCrimzon 3 หลายเดือนก่อน +10

    So he wouldve gotten away with it but then self snitched, they never learn do they

  • @BeWhoYouWant2
    @BeWhoYouWant2 3 หลายเดือนก่อน

    I love these. It reminds me of watching Cops on tv as a kid. but with cyber crime instead of drug addicts.

  • @hummmingbear
    @hummmingbear 3 หลายเดือนก่อน +2

    What a dingus, serves him right releasing that kind of patient data.

  • @todpopo3
    @todpopo3 3 หลายเดือนก่อน +3

    bro just gave away his home folder 💀💀💀💀💀💀💀💀💀💀💀💀💀💀💀💀💀

  • @j.dunlop8295
    @j.dunlop8295 หลายเดือนก่อน +2

    The Dunning-Kruger effect is a cognitive bias in which people wrongly overestimate their knowledge or ability in a specific area. This tends to occur because a lack of self-awareness prevents them from accurately assessing their own skills.

  • @comedyman4896
    @comedyman4896 หลายเดือนก่อน +1

    Posting your user folder on the internet is kind of like if you robbed a bank and then ran straight to a police station

    • @j.dunlop8295
      @j.dunlop8295 หลายเดือนก่อน

      The Dunning-Kruger effect is a cognitive bias in which people wrongly overestimate their knowledge or ability in a specific area. This tends to occur because a lack of self-awareness prevents them from accurately assessing their own skills.

  • @Jmvars
    @Jmvars 3 หลายเดือนก่อน +11

    How stupid do you have to be to upload your entire home folder? I mean at some point he must have wondered why the compression is taking so long.

    • @meanmole3212
      @meanmole3212 3 หลายเดือนก่อน +8

      The hackerman doing hacker things and tarring his loot with command line like a pro. Unfortunately he did not understand how the command line tools work and instead ended up tarring his home folder.

  • @Kirmo13
    @Kirmo13 3 หลายเดือนก่อน +3

    doesn't surprise me this guy was also in the lizard squad thing

  • @OcteractSG
    @OcteractSG 3 หลายเดือนก่อน +1

    Well that was little thing by little thing until we got to the home folder. What a blunder! It would not have even been that bad had the hacker used a clean Kali VM.

  • @pfeilspitze
    @pfeilspitze 3 หลายเดือนก่อน +2

    Zips usually only depend on about 32K of history. A partial download of a zip will also be mostly readable, for the downloaded part.

  • @goldbitcoin
    @goldbitcoin 3 หลายเดือนก่อน +12

    Holy moly

  • @AylienYu
    @AylienYu 3 หลายเดือนก่อน +3

    it's so strange to see finnish in your video

  • @EdSmed20
    @EdSmed20 2 หลายเดือนก่อน +1

    posting ur own home folder is hilarious. he had to be geeked on drugs

  • @anotherinternetlurker6248
    @anotherinternetlurker6248 3 หลายเดือนก่อน +2

    The perils of not knowing how to use the zip command.

  • @berk-._.-
    @berk-._.- 3 หลายเดือนก่อน +3

    It's like so bad it doesn't feel like a failure it feels like he made it on purpose

  • @distantfirst1723
    @distantfirst1723 3 หลายเดือนก่อน +2

    Damn...here i was waiting to see how a team of crack specialists tracked down the hacker in a deeply technical way....and the dude publicly uploads his home folder....?

  • @7eis
    @7eis 3 หลายเดือนก่อน +2

    Ancient Finnish proverb: Never speak of your crimes, not even in the sauna

  • @qzozp
    @qzozp 3 หลายเดือนก่อน +4

    To save you 13 mins: The hacker uploaded his entire home directory as an archive by mistake.

    • @magog6852
      @magog6852 3 หลายเดือนก่อน

      thx see you next time

  • @WelcomeToDERPLAND
    @WelcomeToDERPLAND 3 หลายเดือนก่อน +18

    Welp, expect this case to be used against monero's privacy from now until were' all dead now.

  • @DigitalNomadOnFIRE
    @DigitalNomadOnFIRE 3 หลายเดือนก่อน +2

    This is a problem with doing stuff on the command line all the time, it's very easy to accidentally .tar up your entire home folder by forgetting a parameter or whatever. You'd never do this with a GUI.

  • @alperkaya8919
    @alperkaya8919 หลายเดือนก่อน

    Imagine being this much skilled but sending your whole home folder to feds

  • @beskamir5977
    @beskamir5977 3 หลายเดือนก่อน +9

    As usual. It's never the hardware or software but the wetware.

    • @elvisgregor8403
      @elvisgregor8403 3 หลายเดือนก่อน

      , 😂😂😂😂😂

  • @roderickflint1330
    @roderickflint1330 2 หลายเดือนก่อน +1

    By the way your info was so useful that I disabled adblock to support you :)

  • @Vexcenot
    @Vexcenot หลายเดือนก่อน

    we'll never find the villain's layer!
    the layer in question: