The Public Prosecution Service within the Netherlands [Dutch: Openbaar Ministerie] has simply launched details about an unnamed suspect arrested again in December 2022 for allegedly stealing and promoting private knowledge about tens of hundreds of thousands of individuals.
The victims are mentioned to reside in international locations as far aside as Austria, China, Columbia, the Netherlands itself, Thailand and the UK.
Apparently, the courts have taken a strict strategy to this case, successfully protecting the arrest secret from late 2022 till now, and never permitting the suspect out on bail.
In accordance with the Ministry’s report, a court docket order about custody was made in early December 2022, when the authorities got permission to maintain the suspect locked up for an extra 90 days, which means that they will maintain him till at the very least March 2023 as work on his case continues.
The suspect is being investigated for a number of offences: possessing or publishing “private” knowledge, possessing phishing software program and hacking instruments, pc hacking, and cash laundering.
The prosecutors declare that he laundered near half-a-million Euros’ value of cryptocurrency throughout 2022, so we’re assuming that the court docket thought of him a flight danger, determined that if launched he would possibly have the ability to destroy proof and, presumably, thought that he would possibly attempt to warn others within the cybercrime boards the place he’d been lively to start out overlaying their tracks, too.
Governmental breach?
Intriguingly, the investigation was triggered by the looks on a cybercrime discussion board of a multi-million report stash of non-public knowledge regarding Austrian residents.
These knowledge information, it appears, turned out to have a standard supply: the corporate liable for amassing radio and TV licence charges in Austria.
Austrian cops apparently went undercover to purchase up a duplicate of the stolen knowledge for themselves, and within the means of doing so (their investigative strategies, unsurprisingly, weren’t revealed) recognized an IP quantity that was by some means related to the username they’d handled on the darkish net.
That IP quantity led to Amsterdam within the Netherlands, the place the Dutch police took the investigation additional.
Because the Dutch Ministry writes:
The workforce has sturdy indications that the suspect was working below that person title and that he had, for a very long time, been providing private private knowledge – together with affected person knowledge from medical information – on the discussion board for cost below that title. […]
With the theft of huge quantities of digital knowledge, combining totally different databases and buying and selling entry to this knowledge, increasingly more criminals know the place an individual lives, performs financial institution transactions, what automobile they’ve, what their password is, what telephone numbers they’ve, the place they work, go to high school and many others. The place it was once needed to watch individuals for weeks to determine the fitting sufferer, now a push of a button suffices.
What subsequent?
We’ll let you already know if and once we study extra about this case.
We all know for certain that the Dutch police and prosecutors are usually not going to lose curiosity, as a result of the Ministry concludes its annoucement with these phrases:
This sort of prison exercise not solely grossly violates the privateness of hundreds of thousands of individuals but additionally causes monetary harm to people and companies. Police and prosecutors are dedicated to preventing this complicated type of crime by detecting and prosecuting cybercriminals.
However we will’t assist questioning whether or not the Austrian radio and TV licence charge assortment firm would possibly entice the curiosity of investigators of various type, this time from the Austrian knowledge safety regulators slightly than the police.
Though corporations that endure breaches are undeniably cybercrime victims themselves, they often find yourself in authorized bother of their very own if the regulator kinds the opinion that they might and will have performed extra to guard their clients.
In any case, because the Dutch prosecutors level out, it’s the people whose knowledge really will get stolen who’re the first victims right here.