Data Breaches

Hacker Caught Stealing Personal Data of 132,000 Individuals Pleads Guilty

Idaho man pleads guilty to hacking charges over cyberattacks he conducted in 2017 and 2018, which involved data theft and extortion.

Idaho man pleads guilty to hacking charges over cyberattacks he conducted in 2017 and 2018, which involved data theft and extortion.

A man from Meridian, Idaho, has pleaded guilty to hacking-related charges after investigators found evidence that he had targeted more than a dozen entities in cyberattacks that involved data theft and extortion. 

According to the Justice Department, 44-year-old Robert Purbeck, aka Lifelock and Studmaster, conducted one attack in 2017, when he used credentials acquired from a dark web marketplace to access the systems of a medical clinic in Georgia. 

After gaining access to the company’s systems, he obtained medical records and other documents containing the personal information of roughly 43,000 people, including social security numbers.

A few months later, in 2018, he acquired compromised credentials that gave him access to a server used by the police department of the City of Newnan in Georgia. He used the access to steal police reports and documents containing the personal information of 14,000 individuals.

Investigators tracked him down and executed a search warrant at Purbeck’s home in August 2019. The search revealed that he had been in possession of 132,000 personal data records obtained from the City of Newnan, the medical clinic, and at least 17 other victims located in the United States. 

Purbeck, who has pleaded guilty to computer fraud and abuse charges, will be sentenced on June 18. As part of his plea agreement, he has agreed to pay over $1 million in restitution to the entities he targeted. 

Authorities mentioned that the man had attempted to extort some of his victims. 

Back in 2018, a hacker using the online moniker Lifelock had told DataBreaches.net that he had hacked into the systems of an eye surgery center in Michigan, which at the time told the Department of Health that the details of 42,200 patients had been compromised in a data breach.

Advertisement. Scroll to continue reading.

Lifelock said at the time that he had requested a $10,000 ‘security fee’ from the company for helping it secure patient data. He also claimed to have sold some of the stolen data on the dark web when the firm refused to pay up.

Related: US Announces IPStorm Botnet Takedown and Its Creator’s Guilty Plea

Related: Pentagon Leaker Jack Teixeira Pleads Guilty Under a Deal That Calls for at Least 11 Years in Prison

Related: Moldovan Operator of Credential Marketplace Sentenced to US Prison

Related Content

Data Breaches

The Ohio Lottery cyberattack conducted by the DragonForce ransomware group has impacted more than 500,000 individuals.

Cybercrime

Zscaler says its customer, production and corporate environments are not impacted after a notorious hacker offers to sell access.

Ransomware

Philadelphia-based real estate company Brandywine Realty Trust shuts down systems following a ransomware attack.

Data Breaches

University System of Georgia says Social Security numbers and bank account numbers were compromised in the May 2023 MOVEit hack.

Data Breaches

Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords. 

Data Breaches

Financial Business and Consumer Solutions (FBCS) says compromised information may include names, dates of birth, Social Security numbers, and account information.

Data Breaches

UnitedHealth confirms that personal and health information was stolen in a ransomware attack that could cost the company up to $1.6 billion.

Data Breaches

The LockBit ransomware gang leaks data allegedly stolen from government contractor Tyler Technologies.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version