WORLD US charges Swiss 'hacktivist' for data theft and leaks

WORLD

US charges Swiss 'hacktivist' for data theft and leaks

AP

10:09, March 19, 2021

In this March 4, 2020 file photo, a security camera is shown on the second floor of a row of rooms at a motel in Kent, Wash. Hackers aiming to call attention to the dangers of mass surveillance said they were able to peer into hospitals, schools, factories, jails and corporate offices after they broke into the systems of a security-camera startup. Photo: AP

The US Justice Department has charged a Swiss hacker with computer intrusion and identity theft, just over a week after the hacker took credit for helping to break into the online systems of a U.S. security-camera startup.

An indictment against 21-year-old Till Kottmann was brought Thursday by a grand jury in the Western District of Washington.

Federal prosecutors said Thursday that Kottmann, of Lucerne, Switzerland, was initially charged in September on a range of allegations dating back to 2019 involving stealing credentials and data and publishing source code and proprietary information from more than 100 entities on the web.

Kottmann had described the most recent hack and leak of camera footage from customers of California security-camera provider Verkada as part of a “hacktivist" cause of exposing the dangers of mass surveillance.

Acting U.S. Attorney Tessa Gorman rejected those motives in a statement Thursday.

“These actions can increase vulnerabilities for everyone from large corporations to individual consumers," Gorman wrote. "Wrapping oneself in an allegedly altruistic motive does not remove the criminal stench from such intrusion, theft, and fraud.”

Kottmann didn't immediately return an online request for comment Thursday.

Swiss authorities said they had raided Kottmann's home in Lucerne late last week at the request of U.S. authorities.

The indictment ties a number of hacks to Kottmann over the past year, including one targeting an unnamed security device manufacturer based in the Seattle region and another affecting a maker of tactical equipment.

In several cases, prosecutors said Kottmann improperly used valid employee credentials to gain access to source code databases. The indictment says Kottmann also hacked the Washington state Department of Transportation, an automobile manufacturer and a financial investment company.

The indictment doesn't mention last week's high-profile hack of Verkada, which drew attention because it exposed live camera feeds and archived video footage from schools, jails, factories, gyms and corporate offices.

Kottmann, who uses they/them pronouns, told The Associated Press last week they belonged to a group nicknamed APT-69420 Arson Cats, a small collective of “primarily queer hackers, not backed by any nations or capital but instead backed by the desire for fun, being gay and a better world.”

Kottmann has previously attracted attention for leaking hacked material to expose security flaws, including from U.S. chipmaker Intel last year.


Related Stories

Terms of Service & Privacy Policy

We have updated our privacy policy to comply with the latest laws and regulations. The updated policy explains the mechanism of how we collect and treat your personal data. You can learn more about the rights you have by reading our terms of service. Please read them carefully. By clicking AGREE, you indicate that you have read and agreed to our privacy policies

Agree and continue