Colorado Politics

Iranian hackers charged in ransomware scheme that targeted CDOT, others (VIDEO)

WASHINGTON – Two Iranian computer hackers were charged Wednesday in connection with a multimillion-dollar cybercrime and extortion scheme that targeted government agencies, cities and businesses, the Justice Department said.

Faramarz Shahi Savandi, 34, and Mohammad Mehdi Shah Mansouri, 27, are accused of creating ransomware known as SamSam that encrypted data on the computers of more than 200 victims, including the Colorado Department of Transportation.

Starting in January 2016, the hackers were able to exploit cyber weaknesses, gain access to the victims’ computers and install the ransomware remotely, prosecutors said. The hackers would then allegedly encrypt the files on the computers and demand that the victims pay a ransom in bitcoin in order to have their data unlocked.

VIDEO: Watch a 9News report below.

The hackers, who are not believed to be connected to the Iranian government, were able to make about $6 million and caused the victims of the scheme to lose more than $30 million, prosecutors said.

Other victims included the cities of Atlanta and Newark, N.J., the Port of San Diego and six health care companies across the U.S., according to the Justice Department.

“SamSam ransomware is a dangerous escalation of cybercrime,” said Craig Carpenito, the U.S. attorney for New Jersey, where Wednesday’s indictment was unsealed. “This is a new type of cybercriminal. Money is not their sole objective. They are seeking to harm our institutions and our critical infrastructure.”

The Justice Department would not say whether any of the municipalities paid the ransom. The Atlanta Journal-Constitution reported in April that Atlanta entered into emergency contracts worth $2.7 million to help restore the city’s computer network after the attack.

The hacking scheme was sophisticated not only because it targeted public institutions but because the hackers targeted the entities after business hours and used European-based servers to launch the remote attacks, Carpenito said.

The two men remained fugitives and were believed to be in Iran. Although the U.S. does not have an extradition treaty with Iran, the Justice Department expressed some confidence that the men may one day face the inside of a U.S. courtroom.

“American justice has a long arm and we will wait and eventually we’re confident that we will take these perpetrators into custody,” Deputy Attorney General Rod Rosentein said.

Deputy Attorney General Rod Rosenstein speaks during a news conference announcing the indictment against international computer hacking, at Department of Justice in Washington on Nov. 28. The Justice Department says two Iranian computer hackers have been charged in connection with multimillion-dollar cybercrime and extortion scheme that targeted U.S. government agencies and businesses.
(AP Photo/Jose Luis Magana)
Tags

PREV

PREVIOUS

OUT WEST ROUNDUP | Border town once invaded by Pancho Villa rejects talk of troops

NEW MEXICO Border town once invaded by Pancho Villa rejects talk of troops COLUMBUS, New Mexico – A small New Mexico border town once attacked by Mexican revolutionary Pancho Villa is rejecting talk of a wall and troops while embracing its legacy to draw tourists. U.S. Defense Secretary Jim Mattis has cited Villa’s 1916 raid […]

NEXT

NEXT UP

Ex-governors, including former Colorado College president: Inmate execution decisions a tough burden

COLUMBUS, Ohio – Ohio’s three living former governors have no trouble agreeing on the toughest burden they faced in office: deciding whether someone should live or die. And after a collective 20 years as Ohio’s governor, Richard F. Celeste, Bob Taft and Ted Strickland all wish they had spared more people from execution. Celeste, who […]


Welcome Back.

Streak: 9 days i

Stories you've missed since your last login:

Stories you've saved for later:

Recommended stories based on your interests:

Edit my interests