Yes hacked Cellebrite: In an unusual case where hackers become victims, an anonymous hacker breached a popular mobile device hacking service known for providing surveillance solutions and data extraction to government agencies.
Motherboard reports the intruder managed to obtain 900GB of data from the Israeli company Cellebrite, which includes customer credentials, databases, and technical data of the company's products.
Cellebrite has developed the Universal Forensic Extraction Device (UFED) which has the ability to retrieve data from a wide range of smartphones. Once connected, the UFED can pull various data such as SMS messages, email messages and call log files.
The Israeli company is alleged to supply government services of the USA, and the authoritarian regimes of Russia, the United Arab Emirates and Turkey.
The Motherboard confirmed that the stolen data is indeed authentic. According to the publication, the information appears to have been retrieved from the customer section of Cellebrite's website, from where users can access new software updates.
In addition to user passwords and databases, the breach is reported to also include log files from the devices that “broke” Cellebrite as well as evidence files from seized mobile devices.
The company then confirmed the breach on its website, and advises its customers to change their password:
“Cellebrite recently experienced an unauthorized access to an external server. The company is conducting an investigation to determine the extent of the breach.
Currently, it is known that the leaked information includes basic contact information of users who have signed up for notifications or announcements about Cellebrite's products and hashed passwords for users who have not yet been transferred to the new system. To date, the company is not aware of any specific increased risk to its customers as a result of this incident. However, account holders on my.Cellebrite are urged to change their passwords as a precautionary measure”
In a similar case from the past year, hacker PhineasFisher breached two surveillance services involved in providing hacking applications that have been designed for espionage on unsuspecting citizens in various government agencies.
Then PhineasFisher leaked the stolen data onto the internet, while the Cellebrite intruder is said to adopt a more cautious approach, giving the information exclusively to Motherboard and to a few selected individuals in IRC chat rooms.
