Teenager Busted For CRA Heartbleed Hack
Good news….. Sort of.
A 19 year old was arrested by the Royal Canadian Mounted Police for the hack using the heartbleed bug that resulted in 900 social insurance numbers being stolen from the Canada Revenue Agency. Here’s what The Globe And Mail said:
In a statement Wednesday, the RCMP’s national division said it has arrested Stephen Arthuro Solis-Reyes, 19, of London, Ont., and charged him with one count of unauthorized use of a computer and one count of mischief in relation to data.
“The RCMP treated this breach of security as a high priority case and mobilized the necessary resources to resolve the matter as quickly as possible. Investigators from National Division, along with our counterparts in ‘O’ Division, have been working tirelessly over the last four days analyzing data, following leads, conducting interviews, obtaining and executing legal authorizations and liaising with our partners,” assistant commissioner Gilles Michaud said.
A computer was seized at the suspect’s residence. Mr. Solis is a second-year student at the University of Western Ontario. In 2012, he graduated from a London high school, Mother Teresa Catholic Secondary.
It’s good that they caught (or at least appear to have caught as these charges have not been tested in court) this hacker. But Canadians still need some answers. Such as how this happened and what the CRA is going to do to make sure that this never happens again. It’s a safe bet that while this guy did use the heartbleed bug to get in, he did other things that led to him both stealing this data and leading to his arrest. Thus Canadians need to know that those failings have been addressed.
March 13, 2017 at 8:28 am
[…] hit by someone who pwned them via an Open SSL bug known as Heartbleed a few years back. That led to a 19 year old being put in the clink because of it. But not before other Canadian Government websites had to be taken down to fix the issue and […]
August 16, 2020 at 5:41 pm
[…] is that this isn’t the first time that the Canada Revenue Agency has been hacked. Though the person behind that hack was ultimately tracked down and arrested. While credential stuffing isn’t entirely the fault of the Canada Revenue Agency, you would […]