Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Mexican Businessman Pleads Guilty in U.S. to Brokering Hacking Tools

A Mexican businessman has admitted in a United States federal court to conspiring to sell and use interception devices and hacking services from companies in Italy, Israel, and elsewhere.

The man, Carlos Guerrero, of Chula Vista, California, and Tijuana, Mexico, owned and operated multiple companies in the U.S. and Mexico.

A Mexican businessman has admitted in a United States federal court to conspiring to sell and use interception devices and hacking services from companies in Italy, Israel, and elsewhere.

The man, Carlos Guerrero, of Chula Vista, California, and Tijuana, Mexico, owned and operated multiple companies in the U.S. and Mexico.

Documents presented in court allege that Guerrero brokered the same surveillance tools to Mexican government clients and commercial and private customers.

Between 2014 and 2015, he brokered hacking devices and geolocation tools from an Italian company, and later tools and services from Israeli and other companies.

While the spyware vendors have not been named, they are likely Italy’s now-defunct Hacking Team and Israel’s NSO Group.

“In 2016 and 2017, for example, Guerrero marketed signal jammers, Wi-Fi interception tools, IMSI catchers, and the ability to hack WhatsApp messages to prospective clients in the U.S. and Mexico,” the U.S. Department of Justice says.

[READ: Polish Leader Admits Country Bought Powerful Israeli Spyware]

Guerrero also admitted he was aware of the fact that, in some cases, his Mexican government clients planned to use the equipment for political purposes, not legitimate law enforcement purposes.

Advertisement. Scroll to continue reading.

He also arranged for a Mexican mayor to access without authorization the Twitter, Hotmail, and iCloud accounts of a political rival.

According to court documents, Guerrero used the brokered equipment himself, to intercept a U.S. rival’s phone calls, both in Southern California and Mexico. Additionally, his company helped a Mexican business intercept a Florida-based sales representative’s phone and email accounts, for a $25,000 fee.

Guerrero faces up to five years in prison and a $250,000 fine.

Related: Germany Admits Police Used Controversial Pegasus Spyware

Related: Cypriot National Admits in U.S. Court to Extorting Website Owners

Related: Russian Man Pleads Guilty to Role in Attempt to Plant Malware on Tesla Systems

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed the new CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.