A 17-Year-Old's Journey: Minecraft, SIM-Swapping Bitcoin Heists, Breaching Twitter (chicagotribune.com) 135
The New York Times tells the story of the 17-year-old "mastermind" arrested Friday for the takeover of dozens of high-profile Twitter accounts.
They report that Graham Ivan Clark "had a difficult family life" and "poured his energy into video games and cryptocurrency" after his parents divorced when he was 7, and he grew up in Tampa, Florida with his mother, "a Russian immigrant who holds certifications to work as a facialist and as a real estate broker." By the age of 10, he was playing the video game Minecraft, in part to escape what he told friends was an unhappy home life. In Minecraft, he became known as an adept scammer with an explosive temper who cheated people out of their money, several friends said.... In late 2016 and early 2017, other Minecraft players produced videos on YouTube describing how they had lost money or faced online attacks after brushes with Mr. Clark's alias "Open...."
Mr. Clark's interests soon expanded to the video game Fortnite and the lucrative world of cryptocurrencies. He joined an online forum for hackers, known as OGUsers, and used the screen name Graham$... Mr. Clark described himself on OGUsers as a "full time crypto trader dropout" and said he was "focused on just making money all around for everyone." Graham$ was later banned from the community, according to posts uncovered by the online forensics firm Echosec, after the moderators said he failed to pay Bitcoin to another user who had already sent him money to complete a transaction.
Still, Mr. Clark had already harnessed OGUsers to find his way into a hacker community known for taking over people's phone numbers to access all of the online accounts attached to the numbers, an attack known as SIM swapping. The main goal was to drain victims' cryptocurrency accounts. In 2019, hackers remotely seized control of the phone of Gregg Bennett, a tech investor in the Seattle area. Within a few minutes, they had secured Mr. Bennett's online accounts, including his Amazon and email accounts, as well as 164 Bitcoins that were worth $856,000 at the time and would be worth $1.8 million today... In April, the Secret Service seized 100 Bitcoins from Mr. Clark, according to government forfeiture documents... Mr. Bennett said in an interview that a Secret Service agent told him that the person with the stolen Bitcoins was not arrested because he was a minor... By then, Mr. Clark was living in his own apartment in a Tampa condo complex...
[L]ess than two weeks after the Secret Service seizure, prosecutors said Mr. Clark began working to get inside Twitter. According to a government affidavit, Mr. Clark convinced a "Twitter employee that he was a co-worker in the IT department and had the employee provide credentials to access the customer service portal."
The plan was to sell access to the breached Twitter accounts, but Clark apparently began cheating his customers again, the Times reports — "reminiscent of what Mr. Clark had done earlier on Minecraft..."
"Mr. Clark, who prosecutors said worked with at least two others to hack Twitter but was the leader, is being charged as an adult with 30 felonies."
They report that Graham Ivan Clark "had a difficult family life" and "poured his energy into video games and cryptocurrency" after his parents divorced when he was 7, and he grew up in Tampa, Florida with his mother, "a Russian immigrant who holds certifications to work as a facialist and as a real estate broker." By the age of 10, he was playing the video game Minecraft, in part to escape what he told friends was an unhappy home life. In Minecraft, he became known as an adept scammer with an explosive temper who cheated people out of their money, several friends said.... In late 2016 and early 2017, other Minecraft players produced videos on YouTube describing how they had lost money or faced online attacks after brushes with Mr. Clark's alias "Open...."
Mr. Clark's interests soon expanded to the video game Fortnite and the lucrative world of cryptocurrencies. He joined an online forum for hackers, known as OGUsers, and used the screen name Graham$... Mr. Clark described himself on OGUsers as a "full time crypto trader dropout" and said he was "focused on just making money all around for everyone." Graham$ was later banned from the community, according to posts uncovered by the online forensics firm Echosec, after the moderators said he failed to pay Bitcoin to another user who had already sent him money to complete a transaction.
Still, Mr. Clark had already harnessed OGUsers to find his way into a hacker community known for taking over people's phone numbers to access all of the online accounts attached to the numbers, an attack known as SIM swapping. The main goal was to drain victims' cryptocurrency accounts. In 2019, hackers remotely seized control of the phone of Gregg Bennett, a tech investor in the Seattle area. Within a few minutes, they had secured Mr. Bennett's online accounts, including his Amazon and email accounts, as well as 164 Bitcoins that were worth $856,000 at the time and would be worth $1.8 million today... In April, the Secret Service seized 100 Bitcoins from Mr. Clark, according to government forfeiture documents... Mr. Bennett said in an interview that a Secret Service agent told him that the person with the stolen Bitcoins was not arrested because he was a minor... By then, Mr. Clark was living in his own apartment in a Tampa condo complex...
[L]ess than two weeks after the Secret Service seizure, prosecutors said Mr. Clark began working to get inside Twitter. According to a government affidavit, Mr. Clark convinced a "Twitter employee that he was a co-worker in the IT department and had the employee provide credentials to access the customer service portal."
The plan was to sell access to the breached Twitter accounts, but Clark apparently began cheating his customers again, the Times reports — "reminiscent of what Mr. Clark had done earlier on Minecraft..."
"Mr. Clark, who prosecutors said worked with at least two others to hack Twitter but was the leader, is being charged as an adult with 30 felonies."
State sponsored attackers? (Score:3, Interesting)
It seems all the rage to blame state sponsored groups these days, but in the end it turns out to be a 17yr old kid...
I guess for these companies it is less embarrassing to blame china than to admit they got owned by a 17yr old.
Re: (Score:1)
Re:State sponsored attackers? (Score:5, Funny)
On second thought, let's not go to Camelot. Tis a silly place.
Re: State sponsored attackers? (Score:2)
Kennedy kicked the bucket, as did most of his comfort women.
It's time to move on. All that there is left are morons swooning over the whole Camelot image, and they are ready to kick the bucket too.
I think you mean "insiders" (Score:5, Informative)
The initial report from Twitter was that it was probably i aiders, and they were looking into how to reduce the number of people who had access to the relevant internal tools.
Later, they said the insiders had actually been social engineered into giving up access, which is exactly what had happened.
You seem to be the first to mention "state sponsored attackers".
Within three days of the attack, Twitter posted pretty much the whole story:
--
"The attackers successfully manipulated a small number of employees and used their credentials to access Twitter's internal systems, including getting through our two-factor protections. As of now, we know that they accessed tools only available to our internal support teams to target 130 Twitter accounts. For 45 of those accounts, the attackers were able to initiate a password reset, login to the account, and send Tweets."
--
Re: (Score:2)
Re: (Score:2)
Yeah this incident is the exception, because they discovered the perpetrator and discovered he's a 17 year old.
What i'm talking about is all the incidents where they don't know who did it, and assign blame to state sponsored groups. For all we know, these could have been conducted by 17 years old too who just happen to be better at hiding their tracks.
Re: (Score:2)
I was getting A grades in college when I was 16.
I doesn't surprise me too much that a very interested 17yo chatted with someone who used to work customer service at Twitter.
Re: I think you mean "insiders" (Score:2)
There used to be a program named AOL4Free that people used to create fake AOL accounts back in the mid 1990s. I doubt the ones who wrote it were evil super geniuses or even good programers. They just had knowledge of AOL's flawed authentication system.
Re: (Score:3)
And the companies (mostly Uber and Apple and some bitcoin companies) didn't blame anyone. Damage to them was minimal.
Re: (Score:1)
Lesson #1 - never believe the official narrative
1. Whoever did this owned Twitter's database - and had access to everyone's DMs. So they, potentially, have a lot of very incriminating evidence.
2. There's a major US election coming up
3. Lots of major figures are a) perverts b) stupid enough to say incriminating things on Twitter (in DMs)
4. Leaks can do a lot of damage but you have to prove you had the access
Conclusion:
Whoever did the Twitter hack already had what they needed when the did the bitcoin posting
Re: (Score:2)
Also, am I the only one really uncomfortable with calling a 17 year old "Mr. Clark". I'm in my 30s and I still feel weird with such formal titles. But at least I'm undoubtedly an adult. I know that a 17 year old knows better and we infantilize teenagers and young adults too often... but it doesn't sit right with me for the NYT to do that.
Charged as an adult (Score:1)
Re:Charged as an adult (Score:5, Insightful)
Is there an appropriate amount of stolen money that you feel is punishable?
Re: (Score:3)
Re:Charged as an adult (Score:4, Informative)
The nature of the crime, reflected the nature of the individuals criminal capabilities, not consideration of the harm caused by the crime, just how readily they believed they could get away with it and how much they could make. People say, divorced parents, bad home life for child, bad child but ignore the other reality the parents got divorced because at least one of them was an arsehole, probably genetic and those bad genes passed onto the child.
Just to remind people, getting married, look at your spouse and remind yourself, that could be your child, the bad boy or girl might be a fun fling but do you want to be stuck with them for 18 years, would you be proud of them as you child, what kind of parent will they make, what kind of parent will their children be. Bad breeding choices will produce bad offspring with all the consequences and we are not talking class, simply the genetics behind the brain that does the thinking for them.
Re: (Score:3)
Assuming most divorces end because one or more of the partners is an "arsehole" seems like quite an assumption. It could just be that the people no longer love or get along with each other?
Also your faulty assumption that a person's personality is dictated by some genetic predisposition. Maybe some of it is, sure, but nurture is just as, if not more important. Go back far enough in anyone's family tree and you're sure to find criminals somewhere. Does that mean we are all genetically predisposed for crime?
Re: (Score:2)
So it's one of those things that you know it when you see it.
Re: (Score:1)
Was that a monologue? Have you been using the mirror again?
Re: (Score:2)
How do you determine when he is no longer a danger to the public? BTW, he hasn't been sentenced yet, it's a bit early to sound the alarms about a draconian sentence for his "harmless crime" of stealing $100K.
Re: (Score:3)
You missed him skipping prosecution entirely for stealing $860k.
Re: (Score:2)
And apparently being a complete dick to every community that accepted him.
Re: (Score:2)
How do we do it now?
Oh that's right, we don't. We release criminals whether they've reformed or not, simply because they've served their time. That's not much of an incentive for a criminal to reform, is it?
With such a low bar, we can easily do better. So how would you determine whether a criminal is no longer a danger to the public?
Re: Charged as an adult (Score:2)
With such a low bar, we can easily do better. So how would you determine whether a criminal is no longer a danger to the public?
Check their pulse.
Re: (Score:2)
Ok, so life sentences for everyone then. One problem with such harsh sentences is that we're often afraid to use them, such as when the criminal is a minor.
Re: (Score:3)
So crime in your mind can be redeemed if you get caught. There doesn’t seem to be much downside to any illicit activities. If you get caught the simply repent! The penalty should be zero if you are found guilty, but can return all of the funds.
This is similar to how drug runners work today. They know several shipments will be found and the runners busted. It is still profitable because some shipments do make it through. Thus, under your repenetence strategy it would still potentially be profitable as
Re: (Score:2)
Your reading comprehension needs some work. No, I said he should "stay locked up until he's no longer a danger to the public."
Re: Charged as an adult (Score:2)
He's only 17. This means he can either be charged as juvenile or charged as an adult. Juveniles serve their sentences in a juvenile detention facility and get out when they're 21 no matter what. Minors charged as adults serve in a juvenile detention facility until they're 18 and then finish it their sentence in regular prison. The more you know...
Re: (Score:3)
Re:Charged as an adult (Score:5, Funny)
Re: (Score:2)
I presume that the NSA uses social engineering just as much as any other attacker.
Re:Charged as an adult (Score:5, Insightful)
Sounds like a perfectly stable individual I'd trust around expensive equipment.
Re: (Score:1)
Re: (Score:2)
Don't throw him in jail. Give him a job at the NSA.
Sure, hire assholes who constantly put knives in other people’s backs. What could possibly go wrong ?
Re: (Score:2)
That might be what they are trying to do, plenty of hackers were threatened with decades of jail but were then given the opportunity to work at a government agency instead.
Re:Charged as an adult (Score:5, Informative)
Don't throw him in jail. Give him a job at the NSA.
So I guess that gives us an idea of the quality of the individuals working at the NSA then...
No, all it means is that some people on Slashdot have some very silly ideas about the type of people the NSA are actually looking to recruit. Absolutely no one is clamoring to hire an idiot like this.
Re: (Score:2)
Re: (Score:3)
Re: (Score:2)
Re:Charged as an adult (Score:5, Insightful)
Does he deserve some jail time? Sure, but this is overboard.
Charging him as an adult is what increases his likelihood of jail time. Charging him as a juvenile might only get him sent home with his mommie. Which, if you'd bothered to have read TFS, was exactly what had previously happened with the "lad":
In April, the Secret Service seized 100 Bitcoins from Mr. Clark, according to government forfeiture documents... Mr. Bennett said in an interview that a Secret Service agent told him that the person with the stolen Bitcoins was not arrested because he was a minor... By then, Mr. Clark was living in his own apartment in a Tampa condo complex...
Do an adult crime, get adult time.
Re: (Score:2)
Thank the lord he was treated as a child the first time, then he could go on and commit another crime before he turned 18.
Re: (Score:2)
Re: (Score:1)
Re: (Score:1)
Re: (Score:2)
The Catholic Church just swindled $3 billion out of coronations aid
What?
Re: (Score:1)
Re: (Score:2)
The guy is 17. He did the crime. It is in the interest of the state to insure that other kids do not think that engaging in a life of crime is the best path for them. That is the can claim Influenza and being a minor, they can do whatever they want.
It i
Re: (Score:2)
If punishment is an incentive for not being a criminal, the USA, with its death penalty for murder, would have no murders whatsoever, right?
Re: (Score:2)
Murderers are usually mentally aberrant in one way or another that makes it impossible to rehabilitate or deter them. Obviously it depends on the specific deviance but many are incapable of conceiving the consequences of their actions.
That's part of the reason why the death penalty makes sense in those cases. They are so far divorced from what a normal state of mind is you cannot "fix" them. And locking them up serves the same kind of punishment as locking up an animal, none.
So no, the death penalty isn't t
Re: (Score:2)
Murderers are usually mentally aberrant in one way or another that makes it impossible to rehabilitate or deter them. Obviously it depends on the specific deviance but many are incapable of conceiving the consequences of their actions.
In Germany, newspapers published a parole interview with a guy convicted for multiple murders. He stood up and said "You can't release me. I can't control myself. If you let me out, I will kill again. I fully understand that this is wrong and I'm sorry for it, but I will do it again". Didn't get parole. But he fully understood what he had done and what the consequences were.
Re: (Score:2)
Usually? Wrong. Actually very, very rarely. For many it is simly a job they have to do for the organised crime, little different from the mercenaries working for the US army.
And yet the death penalty is not a deterrent for them.
Generally prison is only as effective as locks - it merely keeps honest people honest. It is not a deterrent for criminals because they aren't planning to get caught. This is why being tough on crime is ineffective security theater.
Re: (Score:2)
However, murders, especially gun murders, do appear to respond to consequences. Vermont has an above average gun death rate, and an above average spouse-on-spouse death rate. Most of these are lightly prosecuted as Vermont also has an extraordinarily high accident rate for gun deaths. New York, where the
Re: (Score:2)
Yes, why can't we be more like, say, Norway, with their compassionate sentencing guidelines. Remember the guy who forgot he was in Norway, grabbed a couple guns, went for a boat ride to a summer camp on an island, and went child hunting, killing what was it, 85 campers and counselors [bbc.com] in a gun-free zone after blowing up a building in downtown Oslo with a fertilizer bomb?
And what was his sentence?
On 24 August 2012, Oslo District Court delivered its verdict, finding Breivik sane and guilty of murdering 77 people. He was sentenced to 21 years in prison, in a form of preventive detention that required a minimum of 10 years incarceration and the possibility of one or more extensions for as long as he is deemed a danger to society. This is the maximum penalty in Norway.
Source: https://www.nrk.no/ytring/en-m... [www.nrk.no] (Norwegian) https://en.wikipedia.org/wiki/... [wikipedia.org] (English)
Well, at least he
Re: (Score:3)
There is no difference in stealing $10 versus $100k, unless you are an idiot. The crime is the same!
And you misquote the Breivik case, he will be in "security retention" forever.
Re: (Score:2)
And boy, it seems he did everything in his power to earn himself a LOT of jail time. 30 felony counts. I assume he'll try for a plea, ratting out his accomplices, and his age may work to his advantage. But I'd be surprised if he's out in less than 10-
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: Charged as an adult (Score:1)
Re: (Score:1)
The main issue is he has already been found guilty in a court of law, repeat offenders don’t usually get light sentences.
Re: (Score:3)
Re: (Score:2)
He's been arrested, he hasn't been found guilty, unless the summary is wrong.
He was found guilty of previous crimes, so it's perfectly accurate to refer to him as both the suspect and the criminal.
Re: (Score:2)
Stealing 900k also gets you noticed too!
Re: (Score:2)
He stole electronic Monopoly money...
Re: (Score:1)
His name was Zero Cool (Score:2)
Die like the rest.
Big mistake to make so early in life (Score:2)
Kid's obviously just a scammer, not a clever hacker, and he was too young and dumb to realize he was out of his depth. He might have flown under the radar until he breached those high-profile accounts. At that point he was toast.
Re: (Score:2)
Exactly. The police and the feds only go into high gear when the rich and powerful are the victims.
Re: (Score:2)
How the fuck is the Secret Service confiscating 100 bitcoin from you flying under the radar?
Re: (Score:2)
How the fuck is the Secret Service confiscating 100 bitcoin from you flying under the radar?
How the fuck is the Secret Service confiscating 100 bitcoin from you flying under the radar?
True, he was already on the radar, but apparently not in jail yet. That's exactly the wrong time to pull a stunt like this.
What's up with the "Mr. Clark". (Score:2)
The Chicago Tribune article that is quoted in the summary does not address Graham Ivan Clark as "Mr. Clark". He's only 17.
Why did slashdot edit it to insert the "Mr."? It make no sense to do that, and it's kinda wrong.
Re: (Score:3)
Nice catch. From what I can tell, the Chicago Tribune reprinted the original NYT article and applied its own editorial standards to the text. The original article is here [nytimes.com] and seems to be verbatim what is quoted on /. I can only assume /, linked to the Chicago Tribune article because the original NYT article was behind a paywall.
Re: (Score:2)
Ah, that makes sense.
Thanks!
Re: (Score:1)
Re: (Score:2)
Shhh. He's virtue-signaling that the criminal is really the victim, and since he picked up on this first, he's morally superior to everyone else.
This kid, Mr. Clark, is only marginally smarter than his victims - why anyone would believe Bill Gates wants your BitCoins just so he can double the amount and give you an equal number of bitcoins along with your original bitcoins is beyond me.
Re: (Score:2)
Shhh. He's virtue-signaling that the criminal is really the victim, and since he picked up on this first, he's morally superior to everyone else.
lol, no and fuck you for calling me "virtue-signaling". That hurts, whimper.
What I am about to say is inconceivable to most people, but I read the linked article before posting.
Because the quoted text did not match the linked article, I thought that some slashdot editor had inserted the title "Mr" for no reason I could see, and I had to wonder why do all that work for some kid that clearly does not deserve one iota of respect.
BTW slashdot editors, quoting one source and giving credit to a different
How is "a difficult family life" an excuse? (Score:5, Insightful)
So if life treats me bad I get a free pass at being a crook? Wonder what the excuse for a lot of politicians is.
Millions of people live in a difficult situation, yet they pull through and manage to become honest, upstanding people. Many way, way more decent than any of those that are generally considered "pillars of society". Just imagine them all realizing that having a "difficult family life" is enough to gather sympathy when you want to rob, steal, emezzle and swindle.
Re: (Score:1, Offtopic)
Ever since women got to become members of a jury.
Re: (Score:1)
Right, I forgot, we're dealing with a justice system where pulling heartstrings actually has an effect.
Re: (Score:2)
So if life treats me bad I get a free pass at being a crook? Wonder what the excuse for a lot of politicians is.
They grew up too privileged. Like that teenager in Texas who got drunk (off stolen beer) and decided to drive, killed a couple people, and walked away with a slap on the wrist because he had been coddled and catered to his whole life.
Re: (Score:3)
Said the Anonymous Coward that wants to equate state-sanctioned human rights atrocities with inmates raping other inmates in federal prison...
Who said we were "OK" with it? And since when is being "pretty OK with that" the same thing as putting a million uhgers in concentration camps to provide cheap labor for making low-cost goods?
I assume you live in a country where prisoners are all perfect gentlemen and ladies to each other? Please, tell me where that is, and I'll move that we in the US start sending yo
Re:Looks like... (Score:5, Informative)
I assume you live in a country where prisoners are all perfect gentlemen and ladies to each other? Please, tell me where that is, and I'll move that we in the US start sending you our prisoners for a stay in your resort-like prisons.
Basically every western prison that is not in the US?
Re: (Score:1)
Kudos to the kid, its really sad it had to turn out that way, that's a hell of a lot of wasted talent
Re: (Score:2)
...regarding the rampant prison rape... ...I'm OK with it.
Don't want to get prison raped? Don't commit crimes. Simple as that.
Don't want to get prison raped? Don't get accused of crimes. Simple as that.
Sorry fixed that for you.
Re: (Score:2)
"Don't want to get prison raped? Don't commit crimes. Simple as that."
Do you believe EVERY person in prison is guilty from committing crimes? And do to believe that anyone who committed a crime should be subject to anal rape?
Re: (Score:2)
The really nasty criminals get to do the raping as a reward for being extra nasty.
Re: As an American Slashdotter... (Score:2)
"And do to believe that anyone who committed a crime should be subject to anal rape?"
It's not about what we on the outside think, but how the inmates run things on the inside.
Yeah this kid did his 'l33t hacking, and he thinks he is smarter than everyone, but is he smart enough NOT to take that Snickers bar and that bag of Doritos someone 'just happened' to leave on his bunk? Is he smart enough to know that if he did accept those items, he is now in debt with someone and if he does not pay back that debt soo
Re: (Score:3)
with a criminal justice system where every federal prisoner is apparently almost guaranteed to be constantly raped
Uh no, this is not true.
Re: Looks like... (Score:1)
Re: Looks like... (Score:2)
Fed prison is supposedly 'easier' than regular PMITA prison thar murderers, gangbangers, etc.. get sent to, but don't think for a second this kid would not get raped in there. Likely he will get himself into debt with the other inmates (the cocky savant that he is), and he will think he is smarter than them. Except it's THEIR game he is playing, not messing around with bloopie bleepie computers, and in general they are far more experienced and well versed on the game of prison life.
If he slips up to
Re: (Score:2)
Re: (Score:2)
Its a darn good deterrent if you ask me.
Sure, if you want to be a rapist by proxy, which is what you are if you willfully promote such schemes. Fucking rapist.
Re: (Score:2)
Don't you mean, want to rape men? Become a criminal.
Re: Looks like... (Score:2)
The people who are able to demonstrate physical strength and courage, and a willingness to fight where and whenever don't get raped. It's the people who are weak and cowardly in the prison enviroment that do.
This is why you never hear of gangbangers or stone cold killers getting raped. Instead it's those who were caught with some pot, or wrote a bad check, or lit a dumpster on fire.
Re: (Score:2)
Yes, but I was thinking of the other side of the coin. People make fun of those who get raped without considering that prisons are allowing rapists to rape. There's something really wrong with a society that promotes rape and rewarding rapists with more victims seems even worse.
Re: (Score:2)
I think they draw straws each day to see whose turn it is.
Re: (Score:3)
Those better be paper straws!
Re: (Score:3)