Tuesday, December 17, 2024
Homecyber securityDark Web Market Admin Gets 42 Months Prison for Selling Login Passwords

Dark Web Market Admin Gets 42 Months Prison for Selling Login Passwords

Published on

SIEM as a Service

Sandu Boris Diaconu, a 31-year-old Moldovan national, has been sentenced to 42 months in federal prison for his role in operating a notorious dark web marketplace known as E-Root.

The sentencing was carried out by U.S. Senior District Judge James Moody, Jr. in Tampa, Florida, marking a pivotal moment in the fight against the illicit trade of compromised computer credentials on the dark web.

Diaconu’s guilty plea on December 1, 2023, came after charges of conspiracy to commit access device and computer fraud, along with possession of 15 or more unauthorized access devices.

- Advertisement - SIEM as a Service

His involvement in the E-Root Marketplace, a platform that facilitated the sale of access to compromised computers worldwide, including servers belonging to companies and individuals in the United States, has drawn significant attention from law enforcement agencies.

Document

Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

The E-Root Marketplace, under Diaconu’s administration, operated across a widely distributed network, employing measures to conceal the identities of its administrators, buyers, and sellers.

Compromised Computer Credentials

This marketplace allowed buyers to search for compromised computer credentials, such as Remote Desktop Protocol (RDP) and Secure Shell (SSH) access, based on various criteria, including price, geographic location, internet service provider, and operating system.

The operation of E-Root and its subsequent takedown is a testament to the collaborative efforts of international law enforcement agencies. Diaconu’s extradition from the United Kingdom in May 2021, following his arrest while attempting to leave the country, underscores the global reach and commitment to dismantling cybercriminal networks.

According to court documents, the E-Root Marketplace was instrumental in the sale of more than 350,000 compromised computer credentials, affecting victims across the globe and spanning all industries.

The marketplace’s operations have been linked to ransomware attacks and stolen identity tax fraud schemes, highlighting the extensive damage and risk posed by such illicit online platforms.

The sentencing of Diaconu is a clear message to cybercriminals about the serious consequences of engaging in the illicit sale of compromised computer credentials.

The U.S. Department of Justice, along with international partners, remains steadfast in its pursuit to disrupt and dismantle dark web marketplaces that threaten the security and privacy of individuals and businesses worldwide.

This case also emphasizes the importance of cybersecurity vigilance and the need for individuals and organizations to protect their digital assets against unauthorized access and exploitation.

As cybercriminals continue to evolve their tactics, the collaborative efforts of law enforcement and cybersecurity professionals are crucial in safeguarding against the pervasive threat of cybercrime.

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Hitachi Authentication Bypass Vulnerability Allows Attackers to Hack the System Remotely

Critical Authentication Bypass Vulnerability Identified in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer.A...

ConnectOnCall Data Breach, 900,000 Customers Data Exposed

 The healthcare communication platform ConnectOnCall, operated by ConnectOnCall.com, LLC, has confirmed a significant data...

Kali Linux 2024.4 Released – What’s New!

Kali Linux has unveiled its final release for 2024, version Kali Linux 2024.4, packed...

CISA Warns of Adobe & Windows Kernel Driver Vulnerabilities Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert, adding two...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Hitachi Authentication Bypass Vulnerability Allows Attackers to Hack the System Remotely

Critical Authentication Bypass Vulnerability Identified in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer.A...

ConnectOnCall Data Breach, 900,000 Customers Data Exposed

 The healthcare communication platform ConnectOnCall, operated by ConnectOnCall.com, LLC, has confirmed a significant data...

Kali Linux 2024.4 Released – What’s New!

Kali Linux has unveiled its final release for 2024, version Kali Linux 2024.4, packed...