Newsletter Subject

[Krebs on Security] Here's Some Bitcoin: Oh, an d You've Been Served!

From

krebsonsecurity.com

Email Address

bk@krebsonsecurity.com

Sent On

Wed, Jan 10, 2024 01:51 PM

Email Preheader Text

Krebs on Security has posted a new item. A California man who lost $100,000 in a 2021 SIM-swapping a

Krebs on Security has posted a new item. A California man who lost $100,000 in a 2021 SIM-swapping attack is suing the unknown holder of a cryptocurrency wallet that harbors his stolen funds. The case is thought to be first in which a federal court has recognized the use of information included in a bitcoin transaction -- such as a link to a civil claim filed in federal court -- as reasonably likely to provide notice of the lawsuit to the defendant. Experts say the development could make it easier for victims of crypto heists to recover stolen funds through the courts without having to wait years for law enforcement to take notice or help. Ryan Dellone, a healthcare worker in Fresno, Calif., asserts that thieves stole his bitcoin on Dec. 14, 2021, by executing an unauthorized SIM-swap that involved an employee at his mobile phone provider who switched Dellone's phone number over to a new device the attackers controlled. Dellone says the crooks then used his phone number to break into his account at Coinbase and siphon roughly $100,000 worth of cryptocurrencies. Coinbase is also named as a defendant in the lawsuit, which alleges the company ignored multiple red flags, and that it should have detected and stopped the theft. Coinbase did not respond to requests for comment. Working with experts who track the flow of funds stolen in cryptocurrency heists, Dellone's lawyer Ethan Mora identified a bitcoin wallet that was the ultimate destination of his client's stolen crypto. Mora says his client has since been made aware that the bitcoin address in question is embroiled in an ongoing federal investigation into a cryptocurrency theft ring. Mora said it's unclear if the bitcoin address that holds his client's stolen money is being held by the government or by the anonymous hackers. Nevertheless, he is pursuing a novel legal strategy that allows his client to serve notice of the civil suit to that bitcoin address -- and potentially win a default judgment to seize his client's funds within -- without knowing the identity of his attackers or anything about the account holder. In a civil lawsuit seeking monetary damages, a default judgment is usually entered on behalf of the plaintiff if the defendant fails to respond to the complaint within a specified time. Assuming that the cybercriminals who stole the money don't dispute Dellone's claim, experts say the money could be seized by cryptocurrency exchanges if the thieves ever tried to move it or spend it. The U.S. courts have generally held that if you're going to sue someone, you have to provide some kind of meaningful and timely communication about that lawsuit to the defendant in a way that is reasonably likely to provide them notice. Not so long ago, you had track down your defendant and hire someone to physically serve them with a copy of the court papers. But legal experts say the courts have evolved their thinking in recent years about what constitutes meaningful service, and now allow notification via email. On Dec. 14, 2023, a federal judge in the Eastern District of California granted Dellone permission to serve notice of his lawsuit directly to the suspected hackers' bitcoin address -- using a short message that was attached to roughly $100 worth of bitcoin Mora sent to the address. Bitcoin transactions are public record, and each transaction can be sent along with an optional short message. The message uses what's known as an "OP RETURN," or an instruction of the Bitcoin scripting language that allows users to attach metadata to a transaction -- and thus save it on the blockchain. In the $100 bitcoin transaction Mora sent to the disputed bitcoin address, the OP RETURN message read: "OSERVICE - SUMMONS, COMPLAINT U.S. Dist. E.D. Cal. LINK: t.ly/123cv01408_service," which is a short link to a copy of the lawsuit hosted on Google Drive. "The courts are adapting to the new style of service of process," said Mark Rasch, a former federal prosecutor at the U.S. Department of Justice. "And that's helpful and useful and necessary." Please use the link above to continue reading this posting. * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * 100% of the companies that got breached in 2023 had cybersecurity. In fact they likely also had employee training, phishing simulations, GRC policies, EDR, and all the other InfoSec protections you have… so why do you feel safe? What are you doing better than MGM, T-Mobile, Activision, or MailChimp? The industry is evolving fast, hackers are getting smarter, and reactive cybersecurity is no longer sufficient. Top combat this, the world's top CISOs are now investing into External Data Privacy (EDP) as an effective way to proactively harden their defenses against breaches. The most successful method of cyber attack is currently PII infused social engineering, and a strong EDP defense posture shrinks your attack surface and makes it harder for hackers or AI to craft that hyper-targeted spear phishing message. Privacy Bee is the most trusted enterprise-grade EDP platform with over 1,500+ business clients. To learn more about how Privacy Bee can further decrease your risk against modern and emerging threats, schedule a no-risk consultation: * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * You received this e-mail because you asked to be notified when new updates are posted. Best regards, BrianKrebs P.S. You may manage your subscription here:

Marketing emails from krebsonsecurity.com

View More
Sent On

09/11/2024

Sent On

09/10/2024

Sent On

08/10/2024

Sent On

03/10/2024

Sent On

30/09/2024

Sent On

25/09/2024

Email Content Statistics

Subscribe Now

Subject Line Length

Data shows that subject lines with 6 to 10 words generated 21 percent higher open rate.

Subscribe Now

Average in this category

Subscribe Now

Number of Words

The more words in the content, the more time the user will need to spend reading. Get straight to the point with catchy short phrases and interesting photos and graphics.

Subscribe Now

Average in this category

Subscribe Now

Number of Images

More images or large images might cause the email to load slower. Aim for a balance of words and images.

Subscribe Now

Average in this category

Subscribe Now

Time to Read

Longer reading time requires more attention and patience from users. Aim for short phrases and catchy keywords.

Subscribe Now

Average in this category

Subscribe Now

Predicted open rate

Subscribe Now

Spam Score

Spam score is determined by a large number of checks performed on the content of the email. For the best delivery results, it is advised to lower your spam score as much as possible.

Subscribe Now

Flesch reading score

Flesch reading score measures how complex a text is. The lower the score, the more difficult the text is to read. The Flesch readability score uses the average length of your sentences (measured by the number of words) and the average number of syllables per word in an equation to calculate the reading ease. Text with a very high Flesch reading ease score (about 100) is straightforward and easy to read, with short sentences and no words of more than two syllables. Usually, a reading ease score of 60-70 is considered acceptable/normal for web copy.

Subscribe Now

Technologies

What powers this email? Every email we receive is parsed to determine the sending ESP and any additional email technologies used.

Subscribe Now

Email Size (not include images)

Font Used

No. Font Name
Subscribe Now

Copyright © 2019–2025 SimilarMail.