Google Dragnet Descends On Gun Stores | Hack Hits 150,000 Surveillance Feeds |Microsoft Exchange Attacks Explode

In a recurring feature in this newsletter, I'm publishing court documents that you won't have seen anywhere else, ones that paint a picture of what police surveillance looks like in the real world. I call it The Wire IRL.

This week's edition looks at an
order on Google for location data on anyone inside or near a two Arizonian gun stores and one range that were targeted by robbers earlier this year.

It's known as a
reverse location search, in which the feds ask Google to provide information on all phones within a given geographic area during a specified period of time. The police then decide which of those devices are pertinent for the investigation and ask Google for more detailed personal information of the phone owner, such as their name, contact information and previous locations.

This February, in
Tucson, Arizona, an agent with the Bureau of Alcohol, Tobacco, Firearms and Explosives was investigating robberies or attempted robberies at three different federal firearms licensees. The robbers, who stole not just guns but safes and paintball masks too, managed to avoid being caught in the act. Security camera footage wasn't able to identify them, though it did indicate one white male was present at two of the hits.

To try to learn more about who may have been responsible, the
investigator went to Google to get information on any devices in areas inside and surrounding those gun shops during the times which the robberies were believed to have taken place. For one of the victims, the Marksman Pistol Institute, that was a period of six hours during the night. For another, The Hub Tucson, it was just half an hour in the evening.

Such warrants have proven controversial, especially in Arizona, where
one man was wrongfully arrested and kept locked up for a week because his device was caught up in a Google dragnet covering an area near a murder. As the author, Jennifer Valentino-DeVries, wrote then, the investigative technique has much promise in helping solve crimes, but "it can also snare innocent people." Showing how broad such orders can be, I previously reported on a case in 2019 where Google returned information on 1,500 devices in response to a request from the ATF regarding some arsons in Milwaukee, Wisconsin.

Given these new Google reverse location searches are in Arizona, and cover areas surrounding three gun stores over nearly ten hours, the risk of innocents being unwittingly caught up in a criminal investigation could be significant. The DOJ declined to comment as the investigation was ongoing.

You can read the search warrant in full for yourself
here.

If you have any tips on government surveillance or cybercrime, drop me an email on tbrewster@forbes.com or message me on Signal at +447837496820.

Thomas Brewster

Thomas Brewster

Associate Editor, Cybersecurity

The Big Story

Up To 125,000 Servers Remain Vulnerable To Devastating Microsoft Exchange Attacks
 
 
 
Up To 125,000 Servers Remain Vulnerable To Devastating Microsoft Exchange Attacks

A crazy-huge cyberattack on hundreds of thousands of Microsoft Exchange servers around the world continues, as tens of thousands still haven't patched. Microsoft had already warned about attacks allegedly carried out by Chinese hackers earlier this month, and released a fix. But hackers have gone into overdrive, targeting the email servers of as many as 30,000 in the U.S. alone. Both government-backed and cybercriminals of various ilks are now taking control of Exchange systems, with as many as 125,000 servers still open to attack, according to two cybersecurity firms.

Read The Full Story →

The Stories You Have To Read Today

Verkada, a Silicon Valley startup that provides surveillance camera and facial recognition tech, was hacked and access to its feeds exposed, William Turton from Bloomberg reports. Its customers, whose internal surveillance footage was leaked to the media, include Tesla and CloudFlare. Turton subsequently found Verkada employees had extensive access to that same footage. Meanwhile, the hacker, Till Kottmann, has been raided.

As expected,
cybercriminals are now actively exploiting those nasty Exchange vulnerabilities. Microsoft warned about a brand of ransomware targeting those still vulnerable.

Google's location data
is also proving useful to investigators of the January 6 Capitol Hill riots, providing information relating to one particular person suspected to storming the home of American democracy.

Joseph Cox is back with more reporting in Vice on government agencies buying location data that comes from everyday smartphone apps. This time it's the Florida Department of Corrections. It might be buying the tech to learn which prisoners are illegally using smartphones.

T-Mobile is going to start selling customers' web-usage data to advertisers unless they opt out, starting April 26, reports Ars Technica. Privacy advocates are, understandably, unhappy with the telecoms giant.

Winner Of The Week

If you've been reading this newsletter for the last couple of months since launch, you might know that I'm a big fan of DocumentCloud. I put all of those search warrants for The Wire IRL in there and open up access for everyone. But there's more to the service than that, annotation, easy embeds and analysis tools being especially useful. This last week, it announced a revamped service, which provides more speed and mobile-friendly features. I've been trialling it for a while and it sure feels more modern than the old system. Get publishing and get sharing all those valuable docs, folks!

Loser Of The Week

The CEO of Canada-based encrypted phone provider Sky Global, Jean-Francois Eap, has been indicted on charges that he and a colleague knowingly and intentionally participated in facilitating narcotics trafficking. Eap and Thomas Herdman, a former distributor of Sky Global devices, were charged with a conspiracy to violate the federal Racketeer Influenced and Corrupt Organizations Act (RICO). Sky sells iPhone, Google Pixel, Blackberry and Nokia phones that come preloaded with an encrypted comms app, which in itself doesn't sound awful. But according to the Justice Department, the company had created a tool that could remotely delete any evidence of drug trafficking from customers' devices. And, the DOJ said, the company had "generated hundreds of millions of dollars in profit by facilitating the criminal activity of transnational criminal organizations and protecting these organizations from law enforcement." Eap told Vice the charges were false and that the company had only been targeted because it provided privacy-enhancing phones. As the case unfolds, it'll be fascinating to see who is the eventual loser.

Across Forbes

 
2021 Forbes CIO Summit Series
 
 
 

ForbesLive

2021 Forbes CIO Summit Series

Join us on Thursday, March 25 for Episode 1 of our 2021 Forbes CIO Summit Series, “Planning The Future Of Work In A Fast-Changing World”. You will hear from a number of leading CIOs and technology leaders on their plans to restabilize their business environments and prepare for growth in 2021.

Register To Attend →
Forbes

You’ve received this email because you’ve opted in to receive Forbes newsletters.

Unsubscribe from The Wiretap.

Manage Email Preferences | Privacy

Forbes Media | 499 Washington Blvd.

Jersey City, NJ 07130

Older messages

Everything About Democrats' 'Big' And 'Green' Multi-Trillion-Dollar Infrastructure Plan

Monday, March 15, 2021

Plus: Dow Jumps 150 Points, Adds To Record High Despite Threat Of Increased Taxes Forbes | Topline Here's What We Know About Democrats' 'Big' And 'Green' Multi-Trillion-Dollar

Pfizer’s Fizzling Stock | Biggest-Ever NFT Buyer | The Grammys’ Winning Women

Monday, March 15, 2021

Plus: The Surprise Investors Who Scored Billions From Coupang's IPO Forbes Good morning. Pfizer's shares are not performing as well as other Covid-19 vaccine manufacturers—CEO Albert Bourla

Coupang's Surprising VC Winners | Why Figma's CEO Sold A CryptoPunk For Millions | Are SPACs Slipping?

Sunday, March 14, 2021

Alex Konrad & Becca Szkutak Forbes staff Welcome to our second edition of Midas Touch, your weekly newsletter destination for exclusive insights, reporting and analysis from the world of venture

Beeple's $69 Million Crypto Art Score | JPMorgan’s Bitcoin Basket

Saturday, March 13, 2021

Also: Operation Hidden Treasure Is Here. If You Have Unreported Crypto, Get Legal Advice Also: Operation Hidden Treasure Is Here. If You Have Unreported Crypto, Get Legal Advice View in browser THE

AI Models Suggests These Stocks Amid Rising Uncertainty

Saturday, March 13, 2021

Forbes | Under 30 What does the rising 10 year yield mean for the stock market? Markets rallied for the majority of the week but cooled down going into Friday after treasury yields increased.

You Might Also Like

After lobbying from Uber and DoorDash, new proposal could overhaul minimum wage law

Tuesday, April 23, 2024

Microsoft's headquarters campuses connected by new pedestrian bridge ADVERTISEMENT GeekWire SPONSOR MESSAGE: Science Firsthand: Learn how Bristol Myers Squibb unlocked the potential of CAR T cell

☕ Inside pitch

Tuesday, April 23, 2024

Palantir's AI pitch to advertisers. April 23, 2024 Marketing Brew PRESENTED BY Slack It's Tuesday. And it might not be a great week to be an EV marketer. Just under a year after CEO Elon Musk

☕ Buy the month

Tuesday, April 23, 2024

August's co-founder on running a mission-based business. April 23, 2024 Retail Brew It's Tuesday, and the week is already heavy on industry intrigue. Lululemon announced layoffs. Nordstrom is

A Burlesque Family at Home

Tuesday, April 23, 2024

Design editor Wendy Goodman takes you inside the city's most exciting homes and design studios. Design Hunting A visual diary by Design Editor Wendy Goodman A Burlesque Family at Home Showbiz

Congress reauthorizes the Foreign Intelligence Surveillance Act

Tuesday, April 23, 2024

Plus, a reader asks about Tangle's diversity guidelines for hiring. Congress reauthorizes the Foreign Intelligence Surveillance Act By Isaac Saul • 23 Apr 2024 View in browser View in browser A

Finding Passion

Tuesday, April 23, 2024

Stay open-eared and open-eyed Finding Passion By Kaamya Sharma • 23 Apr 2024 View in browser View in browser The Trouble With Passion Tyler Burgese & Erin Cech | Culture Study | 21st April 2024 Why

Keeping the CEO in the family

Tuesday, April 23, 2024

+ how you eat affects generations ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

⚡️ Apple Has Lost Control of the iPhone

Tuesday, April 23, 2024

Plus: 'Deadpool & Wolverine' just rebooted Logan's canon all over again. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌

The Pentagon’s 30-Year Lobbying Swindle

Tuesday, April 23, 2024

For decades, corporations have used taxpayer-funded fellowship opportunities to help them secure billion-dollar defense contracts. For decades, the Defense Department has used taxpayer money to send

Can Canada stave off populism?

Tuesday, April 23, 2024

Plus: News from space, updates from a busy week at the Supreme Court, and more. April 23, 2024 View in browser Good morning! Our friends over at Today, Explained (the podcast) spoke with Canadian Prime