The CyberWire · Alan Geason

The T-Mobile hacker speaks (we think). SparklingGoblin enters the cyberespionage ring. Is someone stealing data to train AI? Cellebrite’s av

August 27, 2021·24 min·2 clips
John Binns, a 21-year-old expatriate in Turkey, says he hacked T-Mobile because their security was awful and he wanted to make noise.
Host Dave Bittner opens the August 27, 2021 episode by previewing several major stories: a T-Mobile hacker speaking publicly, a new Chinese-linked espionage group, potential AI training via stolen data, and a ransomware gang claiming to shut down. John Binns, a 21-year-old American living in Turkey, told the Wall Street Journal he was responsible for the T-Mobile breach, and the Journal considers his claims credible because he demonstrated non-public knowledge of the operation. Binns said he entered T-Mobile's network through an unprotected router, used it as a gateway to a Washington state data center, and leveraged stolen credentials to access more than 100 servers. He described T-Mobile's security as 'awful' and said he hacked the company to 'make noise,' though his simultaneous offers to sell the stolen data under hacker aliases IRDev and Vortex complicate that stated motive. Binns, a McLean High School graduate, is largely self-taught and has a history of claiming government persecution. A Chinese intelligence-linked APT group called Sparkling Goblin, identified by ESET as an offshoot of Winnti, has been exploiting a modular backdoor called Sidewalk to target educational institutions in East and Southeast Asia, as well as a U.S. computer retailer and Canadian schools. Sparkling Goblin appears to have incorporated code stolen from the NSA-linked Equation Group alongside Winnti tools. The episode raises a third, less-discussed motive for China's Hafnium Microsoft Exchange exploitation: beyond direct espionage and agent recruitment, the indiscriminate data collection could serve China's ambition to build dominant AI systems that require large, unstructured datasets. Microsoft warned customers of a vulnerability in Azure Cosmos DB discovered by Wiz researchers involving exposed database keys, which has since been patched. Microsoft also issued guidance on ProxyShell vulnerabilities in Exchange Server. The Intercept reports that despite Cellebrite's claim to have exited the Chinese market, Chinese police continue to purchase the Israeli company's phone-cracking tools through brokers and resellers, with one reseller reportedly demonstrating the software to Tibetan border guards for searching WeChat accounts. Cellebrite issued a statement emphasizing its compliance framework and commitment to human rights. Guest Bill Wright of Splunk, a former Senate Homeland Security Committee staff director, argues ransomware evolved from a nuisance crime to a national security threat following Colonial Pipeline, JBS, and Kaseya. Wright outlines a three-part strategy: organizations must improve their own defenses, governments must attack the ransomware-as-a-service business model including cryptocurrency policy and payment reporting requirements, and the U.S. and allies must take more aggressive action against ransomware actors abroad. Kevin McGee, CSO at Microsoft Canada, argues the cybersecurity industry has over-focused on technical skills to the detriment of leadership development, proposing cross-pollination of security professionals into other business units and vice versa. McGee draws a parallel to how accountants eventually rose to CEO roles and warns against dismissing communication and people skills as 'soft.' In his hiring process, McGee prioritizes volunteer work and personal passions over certifications as indicators of character. The episode closes with news that the Ragnarok ransomware gang has announced it is shutting down and released a decryption key, though the host notes skepticism about whether this represents a genuine exit or a rebranding.

As heard by us

A brisk CyberWire brief connecting breach claims, cyberespionage, AI data worries, and ransomware's move into national security.

The CyberWire packs a busy Friday brief into a clear snapshot of late-summer security anxiety. The lead item is a young man claiming responsibility for the T-Mobile breach, followed by SparklingGoblin's apparent focus on educational institutions in Southeast and East Asia,…

Read the full review in PlayNext →

Why you'd press play

If you want a tightly packed security roundup, this one jumps from ransomware to espionage and back.

Read the full recommendation in PlayNext →
Listen to the show on