FBI Catches Hacker That Stole Nintendo's Secrets For Years (arstechnica.com) 31
An anonymous reader quotes a report from Ars Technica: A 21-year-old California man has pleaded guilty to hacking Nintendo's servers multiple times since 2016, using phishing techniques to gain early access to information about the company's plans. Ryan S. Hernandez, who went by RyanRocks online, worked with an unnamed associate to phish employee login credentials for proprietary Nintendo servers, according to an indictment filed in Washington state federal court in December and unsealed over the weekend. Hernandez used that unauthorized access to "download thousands of files, including proprietary developer tools and non-public information" about upcoming Nintendo products and "access pirated and unreleased video games."
That information (and discussion of Nintendo's internal server vulnerabilities) was leaked to the public via Twitter, Discord, and a chat room called "Ryan's Underground Hangout," prosecutors said. At one point, "RyanRocks" drew at least a little infamy in the Nintendo hacking community for allegedly leaking a Nintendo Software Development Kit that had a piece of hidden Remote Access Tool malware added to it. FBI agents confronted Hernandez about his hacking in 2017, according to a prosecution press release, and secured a promise from Hernandez "to stop any further malicious activity." But the hacking continued in 2018 and 2019, according to the indictment, until a June 2019 FBI raid that obtained hard drives with thousands of proprietary Nintendo files. The seized hard drives also included sexually explicit images of minors in a folder labeled "BAD STUFF," according to prosecutors. Hernandez has agreed to pay almost $260,000 to Nintendo as part of a plea agreement. Prosecutors are recommending a jail term of three years for Hernandez's crimes when sentencing is decided in April.
That information (and discussion of Nintendo's internal server vulnerabilities) was leaked to the public via Twitter, Discord, and a chat room called "Ryan's Underground Hangout," prosecutors said. At one point, "RyanRocks" drew at least a little infamy in the Nintendo hacking community for allegedly leaking a Nintendo Software Development Kit that had a piece of hidden Remote Access Tool malware added to it. FBI agents confronted Hernandez about his hacking in 2017, according to a prosecution press release, and secured a promise from Hernandez "to stop any further malicious activity." But the hacking continued in 2018 and 2019, according to the indictment, until a June 2019 FBI raid that obtained hard drives with thousands of proprietary Nintendo files. The seized hard drives also included sexually explicit images of minors in a folder labeled "BAD STUFF," according to prosecutors. Hernandez has agreed to pay almost $260,000 to Nintendo as part of a plea agreement. Prosecutors are recommending a jail term of three years for Hernandez's crimes when sentencing is decided in April.
Re: More consumer electronics spam from BeauHD! (Score:2)
What, no fucking?
It's MsMash as in MISS Mash, right? Not Microsoft Mash, right?
Re: (Score:2)
I assumed this to mean copies of their games from pirate sites to study how they were cracked or to have hashes to check against other sites for the same files.
Re: (Score:2)
Hernandez used that unauthorized access to "download thousands of files, including proprietary developer tools and non-public information" about upcoming Nintendo products and "access pirated and unreleased video games."
So Nintendo had pirated games on its servers?
I see a lot of posts on this site about "English is a living language," and I am not sure whether they are trolls or what. This is a classic example of ambiguity bred from that kind of mindset. Nintendo pirating games is definitely how I read it, but who knows. I don't have the greatest confidence in Ars anymore.
Re: Pirated games (Score:5, Insightful)
I was about to make the same comment. Why was Nintendo pirating games?
Also how many fucking times is the FBI going to magically find child porn on the HDD of every suspected hacker they arrest?? How are people not demanding an oversight committee to go through every PC, every thumb drive, and every laptop in their cybercrime division? Obviously has to be planted evidence. Cybercrime has more childporn convictions than the human trafficking division actually tasked with prosecuting child porn at this point! Its statistically impossible that every hacker happens to be a pedophile.
Re: (Score:1)
Re: (Score:3)
however if you follow the logic the industry uses against piracy -- that it harms them by cutting into revenue; wouldn't pirating such material be a positive?
(slightly flippant, please don't throw rocks at me, thanks!)
Re: (Score:2)
Re: (Score:2)
Re: Pirated games (Score:2)
Yeah that does not meet the burden of proof of beyond reasonable doubt. Did you miss the part where the directory was called bad stuff? Pretty sure web browser cache doesnt make a directory called bad stuff.
Re: (Score:3)
I would expect from someone who knows a thing or two about computer security (and, well, let's pretend for a moment he does or I'd have to assume that Nintendo is too stupid to use passwords more complex than "12345" for their admin accounts) to encrypt shit like this in a way that the FBI couldn't tell from a hard drive overwritten with if=/dev/urandom.
Re: (Score:2)
I would expect from someone who knows a thing or two
Yeah, you would, wouldn't you? But knowledge and wisdom are two different things. For one thing knowledge doesn't preclude wishful thinking.
Re: (Score:2)
I thought there was an article on Slashdot a few months back about how shitty the cybersecurity of crackers is? Just because they know how to break into somebody else's shit doesn't mean they bother being smart about securing their own.
Bigger Question (Score:2)
Re: (Score:2)
Like the old - My kid beat up your honor student bumper sticker?
Stole images of children from Nintendo? (Score:2)
US definition of "explicit". (Score:2)
In many countries, it is normal for kids below a certain age to go naked e.g. at beaches, lakes, or at home in the summer. And if parents take photo of them, nothing special is thought of it. (Cause we haven't got those perverted minds that are so popular in, sorry, can't say it in a nice way, Abrahamic religious countries.)
Most parents here in Germany probably have photos of their kids as naked babies or playing on a rug or in the grass or at a lake/beach as small children.
Also, the separarion of child and
Re: (Score:2)
Those parents don't keep the photos of little Bobby in the bathtub in a folder marked "BAD STUFF" though.
I hope those who fell for the phishing are fired. (Score:3, Insightful)
Seriously, there should be a natural selection to separate the weed from the chaff that falls for this crap.
Comment removed (Score:5, Insightful)
Re: (Score:2)
Re: (Score:3)
How it usually shakes out is:
"If you plead guilty, you'll be out in 2, and 5 years probation. Fight it, and you'll be facing 20 to life"
Re: (Score:3)
Re: (Score:2)
it's more a product of a "justice" system geared towards retribution, rather than rehabilitat
Re: (Score:3)
I would ask why the court is more interested in incarcerating an innocent person than they are in actually finding the guilty party.
The court is not paid to find the innocent not guilty.