Monday, November 4, 2019

Florida Man And Canadian National Plead Guilty To Hacking/Extortion Conspiracy


Defendants admit trying to extract bounties from Uber and LinkedIn in exchange for promise to delete stolen confidential data

SAN JOSE – Brandon Charles Glover and Vasile Mereacre pleaded guilty in federal court today to their respective roles in an extortion conspiracy involving a plot to extract bounties from victim corporations in exchange for the defendants’ promise to delete stolen confidential data, announced United States Attorney David L. Anderson and Federal Bureau of Investigation Special Agent in Charge John F. Bennett.  The defendants admitted making extortion demands of several victim corporations including Uber and LinkedIn.  The plea was accepted by the Honorable Lucy H. Koh, United States District Judge.

In pleading guilty, Glover, 26, of Winter Springs, FL, and Mereacre, 23, of Toronto, Canada, admitted that from October 2016 through January 2017, they engaged in a conspiracy to use stolen credentials to gain access to confidential corporate databases being stored on Amazon Web Services, a cloud-based storage platform  After downloading confidential information from Amazon Web Services accounts belonging to the victim-corporations, Glover and Mereacre notified the victim corporations that they had found vulnerabilities in the corporations’ employees’ use of the systems.  The defendants then demanded money in exchange for deleting the stolen data.

“Companies like Uber are the caretakers, not the owners, of customers’ personal information,” said U.S. Attorney Anderson. “What gets stolen in a computer extortion belongs to your neighbors, not to yourselves.  Don’t be so concerned with your image or reputation.  Be concerned with the real losses others have suffered.  Report the intrusion promptly.  Cooperate with law enforcement.”

“We’re dealing with the most sophisticated cyber actors in the world,” said FBI Special Agent in Charge Bennett. “In order to take on those people on the front lines of the cyber security battle, we rely heavily on our valued relationships and open dialogue with private sector companies in cyber industries. Their willingness to speedily report intrusions to our investigators allows us to find and arrest those who commit data breaches.

To induce payments, the defendants used an alias and an encrypted email account to contact the victim corporations and report that their data was vulnerable.  The defendants sent a sample of the stolen data to the corporations as proof their systems had been breached and then demanded payment in exchange for deletion of the data.    

The plea agreements describe in some detail the defendants’ communications with two companies: Uber and Lynda.com.  With respect to Uber, defendants admitted they provided credentials regarding Uber’s Amazon Web Services account to a “technically proficient hacker.” The hacker identified archive files that contained 57 million Uber user records consisting of customer data and driver data.  Defendants admitted they illegally accessed and downloaded the records from Amazon Web Services and, on November 14, 2016, contacted Uber claiming to have found a major vulnerability in Uber’s computer security systems.  Defendants provided a portion of the database to prove the information had been exfiltrated and then demanded payment in exchange for deleting the stolen data.  The defendants’ plea agreements state that on November 16, 2016, Uber agreed to pay $100,000 in bitcoin to the defendants through a third party but that, as part of the agreement, Uber demanded that the defendants also sign a confidentiality agreement.  According to the plea agreements, Uber demanded that the payment for the data breach remain confidential and that the defendants destroy the data that they stole.   After three weeks of negotiation, Uber made two $50,000 payments, one on December 8 and the other on December 14, 2016.  Then, in January 2017, Uber informed the defendants that it had discovered Glover’s true identity.  On January 3, 2017, a representative from Uber met with Glover at his Florida home, where Glover admitted his role in the data breach exfiltration and signed a confidentiality agreement in his true name.  On January 5, 2017, a representative from Uber met with Mereacre at a hotel restaurant in Toronto, Canada, where Mereacre admitted his role in the data breach exfiltration and signed a confidentiality agreement in his true name.

The defendants employed a similar strategy in an aborted attempt to extort funds from Lynda.com’s parent company, LinkedIn.  Glover and Mereacre admit that in December of 2016, they possessed information regarding over 90,000 confidential Lynda.com user accounts that the defendants had illegally accessed and downloaded from Lynda.com’s Amazon Web Services account.  On December 11, 2016, defendants emailed a portion of the user account information to the security team at LinkedIn.  Defendants also demanded compensation in exchange for deleting the stolen data.  Rather than pay the bounty, LinkedIn sought to identify the source of the extortionist email.  Specifically, LinkedIn tried to lure the writer of the email to enroll with a third party to assist in the negotiation of terms for payment to the defendants.  In this way, LinkedIn hoped to identify the extortionist and notify law enforcement of the plot.  Defendants told LinkedIn’s representatives, “[p]lease keep in mind, we expect a big payment as this was hard work for us, we already helped a big corp which paid close to 7 digits, all went well.”  The defendants stopped communicating with LinkedIn in January 2017, and the company did not pay defendants for the data or for confidentiality.

Glover and Mereacre both were charged by a Superseding Information on October 30, 2019.  Each defendant was charged with one count of conspiracy to commit extortion involving computers, in violation of 18 U.S.C. §§ 1030(a)(7)(B) and (c)(3)(A).  Today, Glover and Mereacre pleaded guilty to their respective roles in the conspiracy.

The defendants have been released on bond pending sentencing.  Judge Koh has scheduled a status conference regarding sentencing for March 18, 2020.  The maximum statutory penalty for conspiracy to commit extortion involving computers is five years imprisonment and a fine of $250,000.  The court may also order an additional term of supervised release and restitution; however, any sentence will be imposed by the court only after consideration of the U.S. Sentencing Guidelines and the federal statute governing the imposition of a sentence, 18 U.S.C. § 3553.

Assistant U.S. Attorneys Susan Knight and Amie Rooney are prosecuting the case with the assistance of Elise Etter and Lakisha Holliman.  The prosecution is being handled by the Office of the U.S. Attorney, Northern District of California’s new Corporate Fraud Strike Force and is the result of an investigation by the FBI.

Bronx Man Sentenced To More Than 12 Years In Prison For Conspiring To Distribute Narcotics On The Dark Web


Luis Fernandez Shipped Fentanyl and Carfentanil from New York to Customers Across the United States

Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced today that LUIS FERNANDEZ was sentenced to 151 months in prison for participating in a conspiracy to distribute carfentanil, fentanyl, and a fentanyl analogue over the “dark web,” and for possessing a firearm after being convicted of a felony.  Fentanyl is a synthetic opioid that is significantly stronger than heroin, and carfentanil is a fentanyl analogue that is approximately 100 times stronger than fentanyl.  FERNANDEZ was also ordered to forfeit $269,623 in narcotics proceeds.  FERNANDEZ pled guilty on July 30, 2019, before U.S. District Judge Denise L. Cote, who imposed today’s sentence.

Manhattan U.S. Attorney Geoffrey S. Berman said:  “Luis Fernandez and his co-defendant Richard Castro sold large quantities of fentanyl and carfentanil to hundreds of individuals across the country, including over the dark web.  Today’s sentence should be another clear reminder that any short-term profits from drug dealing are not worth the long-term price.”

According to the allegations in the Superseding Information to which FERNANDEZ pled guilty, public court filings, and statements made in court:

From at least in or about November 2015 through March 2019, FERNANDEZ and his co-defendant Richard Castro[1] conspired to distribute carfentanil, fentanyl, and phenyl fentanyl (an analogue of fentanyl).  For most of this period, the conspiracy dealt drugs over the dark web, using the monikers “Chemsusa”, “Chems_usa”, and “Chemical_usa.”  Castro was an operator of these online monikers and the leader of this conspiracy.  On one dark web marketplace, Dream Market, Castro boasted that he had completed more than 3,200 transactions on other dark web markets, including more than 1,800 on AlphaBay.  The customer feedback for “Chemsusa” included, “Extremely potent and definitely the real Carf,” as well as “The Carfent is unbelievably well synthesized, keep up the amazing work.”  In June 2018, Castro, using the “Chemsusa” moniker, informed customers that he was moving his business off of dark web marketplaces and would accept purchase requests for narcotics only via encrypted email.  To learn the off-market email address, “Chems_usa” required willing customers to pay a fee.  An undercover law enforcement officer paid this fee, obtained the encrypted email address, and placed orders with Castro.  Castro’s customers paid him in Bitcoin.

FERNANDEZ managed the conspiracy’s stash house, packaged narcotics, and shipped the narcotics via U.S. mail from the New York City area to hundreds of individuals throughout the United States.  For example, in early March 2019, FERNANDEZ was observed dropping several envelopes in a mailbox in Coney Island, New York; law enforcement seized and searched these envelopes, each of which contained carfentanil.

In mid-March 2019, law enforcement searched FERNANDEZ’s residence in the Bronx, New York.  During this search, officers found, among other things, the following evidence in FERNANDEZ’s bedroom: (1) mailing labels similar to those found on packages connected to the conspiracy, (2) addresses of customers who had received packages from the conspiracy, and (3) approximately 78 grams of fentanyl analogues and 307.5 grams of u-47700 (an opioid analgesic that is approximately 7.5 times more potent than morphine).  Law enforcement also recovered a fumigation mask and rubber gloves.  In a different bedroom of FERNANDEZ’s residence, law enforcement recovered a Model R-73 handgun.  Because FERNANDEZ had previously been convicted of a felony (stemming from his sale of cocaine), he was legally prohibited from possessing this handgun.

*                *                *

In imposing sentence, the Court stated that the defendant played a “critical” role in the conspiracy and that he was responsible for “shipping death.”

In addition to his prison term, FERNANDEZ, 42, of the Bronx, was sentenced to four years of supervised release.

Mr. Berman praised the Federal Bureau of Investigation, the U.S. Postal Inspection Service, and the New York City Police Department for their outstanding investigative work.  Mr. Berman also thanked the Internal Revenue Service and the Orange County, Florida, Sheriff’s Office for their valuable assistance. 

This matter is being handled by the Office’s Narcotics Unit.  Assistant United States Attorneys Michael D. Neff, Aline R. Flodr, and Ryan B. Finkel are in charge of the prosecution.


[1] Castro pled guilty to money laundering and narcotics distribution conspiracy on July 25, 2019. 

Koreatown Man Arrested on Federal Charges that He Coerced Girls He Met Online into Sending Him Sexually Explicit Selfies


          LOS ANGELES – Law enforcement this morning arrested a Los Angeles man on child sexual exploitation charges alleging that he met at least eight teenage girls on the internet and pressured them – sometimes by threatening suicide – into sending him sexually explicit images of themselves.

          Francisco Sanchez, 30, of Koreatown, is scheduled to be arraigned this afternoon on an 11-count federal grand jury indictment in United States District Court in downtown Los Angeles.

          Sanchez is charged in the indictment with seven counts of production of child pornography, one count of distribution of child pornography, one count of possession of child pornography, and two counts of cyberstalking.

          According to the indictment, between January 2014 and September 2016, Sanchez, posing as a teenage boy, contacted teenage girls online, using the pseudonym “Eddie Nash” to conceal his identity. He allegedly coerced some of them into producing sexually explicit photos and videos of themselves, sometimes by threatening suicide or threatening to post compromising pictures of the girls online.

          In June 2016, Sanchez, while concealing his identity, allegedly sent a victim a text message and threatened to make her “internet famous” if she continued to ignore him. When the victim replied, “If you do that u will get arrested for child pornography,” Sanchez texted back, “so, but u will be famous” and “so be nice to me, i love u so much, i dont want to hurt u,” the indictment alleges.

          An indictment contains allegations that a defendant has committed a crime. Every defendant is presumed innocent until and unless proven guilty beyond a reasonable doubt.

          The charge of production of child pornography carries a 15-year mandatory minimum federal prison sentence. The charge of distributing child pornography carries a mandatory minimum sentence of five years in federal prison. If convicted of all charges, Sanchez would face a statutory maximum sentence in excess of 200 years in federal prison.

          This matter was investigated by the FBI and the Los Angeles Child Exploitation and Human Trafficking Task Force.

          This case is being prosecuted by Assistant United States Attorneys Damaris Diaz of the Violent and Organized Crime Section, and Julia S. Choe of the Cyber and Intellectual Property Crimes Section.