Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

3 Former US Officials Charged in UAE Hacking Scheme

Three former U.S. intelligence and military officials have admitted providing sophisticated computer hacking technology to the United Arab Emirates and agreed to pay nearly $1.7 million to resolve criminal charges in an agreement that the Justice Department described Tuesday as the first of its kind.

Three former U.S. intelligence and military officials have admitted providing sophisticated computer hacking technology to the United Arab Emirates and agreed to pay nearly $1.7 million to resolve criminal charges in an agreement that the Justice Department described Tuesday as the first of its kind.

The defendants — Marc Baier, Ryan Adams and Daniel Gericke — are accused of working as senior managers at a UAE-based company that conducted hacking operations on behalf of the government. Prosecutors say the men provided hacking and intelligence-gathering systems that were used to break into computers in the United States and elsewhere in the world.

The Justice Department alleges that the men committed computer fraud and violated export control laws by providing defense services without the required license. The case also appears to be part of a growing trend highlighted earlier this year by the CIA of foreign governments hiring former U.S. intelligence operatives to bolster their own spycraft — a practice officials have said risks exposing U.S. secrets.

“This is a loud statement” that the Justice Department takes such cases seriously, said Bobby Chesney, a professor at the University of Texas School of Law who specializes in national security issues.

The charges were filed under a deferred prosecution agreement that, in addition to requiring a $1.68 million payment, will also force the men to cooperate with the Justice Department’s investigation, to sever any ties with any UAE intelligence or law enforcement agencies and to forego any security clearances. If they comply with those and other terms for three years, the Justice Department will abandon the prosecution.

As part of the agreement, the three men did not dispute any of the facts alleged by prosecutors.

The Justice Department described it as the “first-of-its-kind resolution of an investigation into two distinct types of criminal activity,” including providing unlicensed technology for the purposes of hacking.

“Hackers-for-hire and those who otherwise support such activities in violation of U.S. law should fully expect to be prosecuted for their criminal conduct,” Mark Lesko, acting assistant attorney general in charge of the Justice Department’s national security division, said in a statement.

Advertisement. Scroll to continue reading.

According to court documents, the trio left a U.S.-based company that was operating in the UAE to join an Emerati company that would give them “significant increases” in their salaries.

The companies aren’t named in charging documents, but Lori Stroud, a former National Security Agency employee, said she worked with the three men in the UAE at U.S.-based CyberPoint and then for UAE-based DarkMatter.

Stroud said she quit because she saw DarkMatter hacking U.S. citizens. She said she assisted the FBI in its investigation and was glad to see the case come to a resolution.

“This is progress,” Stroud said.

The Emirati government did not immediately respond to a request for comment early Wednesday. Questions sent by email to officials at Abu Dhabi-based DarkMatter could not be delivered.

Since details of DarkMatter’s hacking campaign became public, the company’s profile has dropped over the last few years, with some staff moving onto a new Abu Dhabi-based firm called G42. That firm has been linked to a mobile app suspected of being a spying tool as well as Chinese coronavirus tests that American officials warned against using over concerns about patient privacy, test accuracy and Chinese government involvement.

DarkMatter’s founder and CEO, Faisal al-Bannai, told The Associated Press in 2018 that the company takes part in no hacking, although he acknowledged the firm’s close business ties to the Emirati government, as well as its hiring of former CIA and NSA analysts.

Prosecutors said that between January 2016 and November 2019, the defendants increased operations being providing to the UAE government. They bought exploits to break into computers and mobile devices from companies around the world, including those based in the U.S., according to the Justice Department. That includes one so-called “zero-click” exploit — which can break into mobile devices without any user interaction — that Baier bought from an unnamed U.S. company in 2016.

Lawyers for Adams and Gericke did not immediately return messages seeking comment, and a lawyer for Baier declined to comment.

The Justice Department described each of them as former U.S. intelligence or military personnel. Baier previously worked at the NSA, according to a former colleague who spoke on condition of anonymity because of the sensitivity surrounding the matter.

The CIA warned in a letter earlier this year about “an uptick in the number of former officers who have disclosed sensitive information about CIA activities, personnel, and tradecraft.”

The letter sent to former CIA officials was signed by Sheetal Patel, the agency’s assistant director for counterintelligence. It described as a “detrimental trend” a practice of foreign governments hiring former intelligence officers “to build up their spying capabilities.” Some listed examples included using access to CIA information or contacts for business opportunities as well as “working for state-sponsored intelligence related companies in non-fraternization countries.”

“We ask that you protect yourself and the CIA by safeguarding the classified tradecraft that underpins your enterprise,” Patel wrote.

Related: UAE Denies Developing Popular Mideast App as Spy Tool

Related: Google Removes Mideast Android App ToTok

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.