Slashdot Mirror


AOL Security Compromised by Teenager

Freaky_Friday wrote with a link to an InfoWorld article about a teenage kid accessing customer information at AOL. The alleged criminal trespass began late last year, and extended up through early April. According to the article, the guy used some 'off-the-shelf' hacking software he downloaded online to gain access to, and then transmit information from, AOL's systems. "The complaint states that Nieves admitted to investigators that he committed the alleged acts because AOL took away his accounts. 'I accessed their internal accounts and their network and used it to try to get my accounts back,' the defendant is quoted as saying in the complaint. He also admitted to posting photos of his exploits in a photo Web site, according to the complaint ... If the defendant was honest about his motivation in his reported confession, it's safe to assume that he wasn't interested in stealing data for financial gain, [Managing director of technology at FTI Consulting Mark] Rasch said. Still, it'll be interesting to find out what steps AOL is taking if customer data was in fact compromised, he said."

1 of 99 comments (clear)

  1. Suuurrree by FalleStar · · Score: 5, Insightful

    Among his alleged exploits:
    * Accessing systems containing customer billing records, addresses, and credit card information
    * Infecting machines at an AOL customer support call center in New Delhi, India, with a program to funnel information back to his PC
    * Logging in without permission into 49 AIM instant message accounts of AOL customer support employees
    * Attempting to break into an AOL customer support system containing sensitive customer information
    * Engaging in a phishing attack against AOL staffers through which he gained access to more than 60 accounts from AOL employees and subcontractors
    Yeah, sounds like he was JUST trying to get his account back alright.