Google Dragnet Descends On Gun Stores | Hack Hits 150,000 Surveillance Feeds |Microsoft Exchange Attacks Explode

In a recurring feature in this newsletter, I'm publishing court documents that you won't have seen anywhere else, ones that paint a picture of what police surveillance looks like in the real world. I call it The Wire IRL.

This week's edition looks at an
order on Google for location data on anyone inside or near a two Arizonian gun stores and one range that were targeted by robbers earlier this year.

It's known as a
reverse location search, in which the feds ask Google to provide information on all phones within a given geographic area during a specified period of time. The police then decide which of those devices are pertinent for the investigation and ask Google for more detailed personal information of the phone owner, such as their name, contact information and previous locations.

This February, in
Tucson, Arizona, an agent with the Bureau of Alcohol, Tobacco, Firearms and Explosives was investigating robberies or attempted robberies at three different federal firearms licensees. The robbers, who stole not just guns but safes and paintball masks too, managed to avoid being caught in the act. Security camera footage wasn't able to identify them, though it did indicate one white male was present at two of the hits.

To try to learn more about who may have been responsible, the
investigator went to Google to get information on any devices in areas inside and surrounding those gun shops during the times which the robberies were believed to have taken place. For one of the victims, the Marksman Pistol Institute, that was a period of six hours during the night. For another, The Hub Tucson, it was just half an hour in the evening.

Such warrants have proven controversial, especially in Arizona, where
one man was wrongfully arrested and kept locked up for a week because his device was caught up in a Google dragnet covering an area near a murder. As the author, Jennifer Valentino-DeVries, wrote then, the investigative technique has much promise in helping solve crimes, but "it can also snare innocent people." Showing how broad such orders can be, I previously reported on a case in 2019 where Google returned information on 1,500 devices in response to a request from the ATF regarding some arsons in Milwaukee, Wisconsin.

Given these new Google reverse location searches are in Arizona, and cover areas surrounding three gun stores over nearly ten hours, the risk of innocents being unwittingly caught up in a criminal investigation could be significant. The DOJ declined to comment as the investigation was ongoing.

You can read the search warrant in full for yourself
here.

If you have any tips on government surveillance or cybercrime, drop me an email on tbrewster@forbes.com or message me on Signal at +447837496820.

Thomas Brewster

Thomas Brewster

Associate Editor, Cybersecurity

The Big Story

Up To 125,000 Servers Remain Vulnerable To Devastating Microsoft Exchange Attacks
 
 
 
Up To 125,000 Servers Remain Vulnerable To Devastating Microsoft Exchange Attacks

A crazy-huge cyberattack on hundreds of thousands of Microsoft Exchange servers around the world continues, as tens of thousands still haven't patched. Microsoft had already warned about attacks allegedly carried out by Chinese hackers earlier this month, and released a fix. But hackers have gone into overdrive, targeting the email servers of as many as 30,000 in the U.S. alone. Both government-backed and cybercriminals of various ilks are now taking control of Exchange systems, with as many as 125,000 servers still open to attack, according to two cybersecurity firms.

Read The Full Story →

The Stories You Have To Read Today

Verkada, a Silicon Valley startup that provides surveillance camera and facial recognition tech, was hacked and access to its feeds exposed, William Turton from Bloomberg reports. Its customers, whose internal surveillance footage was leaked to the media, include Tesla and CloudFlare. Turton subsequently found Verkada employees had extensive access to that same footage. Meanwhile, the hacker, Till Kottmann, has been raided.

As expected,
cybercriminals are now actively exploiting those nasty Exchange vulnerabilities. Microsoft warned about a brand of ransomware targeting those still vulnerable.

Google's location data
is also proving useful to investigators of the January 6 Capitol Hill riots, providing information relating to one particular person suspected to storming the home of American democracy.

Joseph Cox is back with more reporting in Vice on government agencies buying location data that comes from everyday smartphone apps. This time it's the Florida Department of Corrections. It might be buying the tech to learn which prisoners are illegally using smartphones.

T-Mobile is going to start selling customers' web-usage data to advertisers unless they opt out, starting April 26, reports Ars Technica. Privacy advocates are, understandably, unhappy with the telecoms giant.

Winner Of The Week

If you've been reading this newsletter for the last couple of months since launch, you might know that I'm a big fan of DocumentCloud. I put all of those search warrants for The Wire IRL in there and open up access for everyone. But there's more to the service than that, annotation, easy embeds and analysis tools being especially useful. This last week, it announced a revamped service, which provides more speed and mobile-friendly features. I've been trialling it for a while and it sure feels more modern than the old system. Get publishing and get sharing all those valuable docs, folks!

Loser Of The Week

The CEO of Canada-based encrypted phone provider Sky Global, Jean-Francois Eap, has been indicted on charges that he and a colleague knowingly and intentionally participated in facilitating narcotics trafficking. Eap and Thomas Herdman, a former distributor of Sky Global devices, were charged with a conspiracy to violate the federal Racketeer Influenced and Corrupt Organizations Act (RICO). Sky sells iPhone, Google Pixel, Blackberry and Nokia phones that come preloaded with an encrypted comms app, which in itself doesn't sound awful. But according to the Justice Department, the company had created a tool that could remotely delete any evidence of drug trafficking from customers' devices. And, the DOJ said, the company had "generated hundreds of millions of dollars in profit by facilitating the criminal activity of transnational criminal organizations and protecting these organizations from law enforcement." Eap told Vice the charges were false and that the company had only been targeted because it provided privacy-enhancing phones. As the case unfolds, it'll be fascinating to see who is the eventual loser.

Across Forbes

 
2021 Forbes CIO Summit Series
 
 
 

ForbesLive

2021 Forbes CIO Summit Series

Join us on Thursday, March 25 for Episode 1 of our 2021 Forbes CIO Summit Series, “Planning The Future Of Work In A Fast-Changing World”. You will hear from a number of leading CIOs and technology leaders on their plans to restabilize their business environments and prepare for growth in 2021.

Register To Attend →
Forbes

You’ve received this email because you’ve opted in to receive Forbes newsletters.

Unsubscribe from The Wiretap.

Manage Email Preferences | Privacy

Forbes Media | 499 Washington Blvd.

Jersey City, NJ 07130

Older messages

Everything About Democrats' 'Big' And 'Green' Multi-Trillion-Dollar Infrastructure Plan

Monday, March 15, 2021

Plus: Dow Jumps 150 Points, Adds To Record High Despite Threat Of Increased Taxes Forbes | Topline Here's What We Know About Democrats' 'Big' And 'Green' Multi-Trillion-Dollar

Pfizer’s Fizzling Stock | Biggest-Ever NFT Buyer | The Grammys’ Winning Women

Monday, March 15, 2021

Plus: The Surprise Investors Who Scored Billions From Coupang's IPO Forbes Good morning. Pfizer's shares are not performing as well as other Covid-19 vaccine manufacturers—CEO Albert Bourla

Coupang's Surprising VC Winners | Why Figma's CEO Sold A CryptoPunk For Millions | Are SPACs Slipping?

Sunday, March 14, 2021

Alex Konrad & Becca Szkutak Forbes staff Welcome to our second edition of Midas Touch, your weekly newsletter destination for exclusive insights, reporting and analysis from the world of venture

Beeple's $69 Million Crypto Art Score | JPMorgan’s Bitcoin Basket

Saturday, March 13, 2021

Also: Operation Hidden Treasure Is Here. If You Have Unreported Crypto, Get Legal Advice Also: Operation Hidden Treasure Is Here. If You Have Unreported Crypto, Get Legal Advice View in browser THE

AI Models Suggests These Stocks Amid Rising Uncertainty

Saturday, March 13, 2021

Forbes | Under 30 What does the rising 10 year yield mean for the stock market? Markets rallied for the majority of the week but cooled down going into Friday after treasury yields increased.

You Might Also Like

A huge win + huge discount

Saturday, November 16, 2024

We just scored a big win — and to keep the victories coming, we need your help. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

Top Democrats just voted to let Trump unilaterally silence the resistance

Saturday, November 16, 2024

If this bill is signed into law, The Intercept and every nonprofit organization in America that dares to stand up to Trump will be in existential danger. A bipartisan majority in the House of

How Amazon is adapting to the TikTok generation

Saturday, November 16, 2024

What Elon Musk said privately about Microsoft's first offer to OpenAI ADVERTISEMENT GeekWire SPONSOR MESSAGE: Get your ticket for AWS re:Invent, happening Dec. 2–6 in Las Vegas: Register now for

Bitcoin Blazes Past $90,000 On Trump Euphoria | Meme Coin Mania

Saturday, November 16, 2024

The record-breaking surge signals the market's optimism about Trump's crypto promises. ADVERTISEMENT Forbes START INVESTING • Newsletters • MyForbes Nina Bambysheva Staff Writer, Forbes Money

Guest Newsletter: Five Books

Saturday, November 16, 2024

Five Books features in-depth author interviews recommending five books on a theme Guest Newsletter: Five Books By Sylvia Bishop • 16 Nov 2024 View in browser View in browser The Browser is launching

Collection of old skulls illustrates American diversity

Saturday, November 16, 2024

+ evidence that Earth was frozen 700M years ago ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

My Hunt for Relaxed-Fit Men’s Pants That Don't Make Me Look Like a Toddler

Saturday, November 16, 2024

Plus: What Maddy DeVita (aka Hand Me the Fork) can't live without. The Strategist Every product is independently selected by editors. If you buy something through our links, New York may earn an

YOU LOVE TO SEE IT: Fighting The Lunchroom Bully

Saturday, November 16, 2024

The Feds crack down on school lunch fees, ghost networks get summoned, a big mine gets slapped with a big fine, and America gets its ethics chief. YOU LOVE TO SEE IT: Fighting The Lunchroom Bully By

The Insanity Begins

Saturday, November 16, 2024

November 16, 2024 The Weekend Reader Required Reading for Political Compulsives 1. The Resistance Is Dead. Long Live the Resistance? The women who set out to bury Donald Trump are doing things

The best winter boots

Saturday, November 16, 2024

One of our favorites is on sale View in browser Ad The Recommendation Ad Winter boots we love A selection of our picks for the best winter boots, lined up side-by-side. Rozette Rago/NYT Wirecutter Cold