A Kansas City man has been charged with allegedly hacking into computer networks and using that access to promote his cybersecurity services.
See also: How long does it take an organization to recover from a cyberattack?

According to the Department of Justice, Nicholas Michael Kloster, 31, of Kansas City, Missouri, hacked into two computer networks, a health club and a nonprofit organization.
According to the indictment, Kloster was involved in at least three incidents investigated by the FBI against an equal number of organizations not named in the document.
The first incident occurred around midnight on April 26, 2024, when Kloster breached the premises of a health club that operates several gyms in the state and gained access to its systems. He then sent an email to one of the gym owners claiming to have hacked computers and promoted his cybersecurity services in the same message, apparently seeking to be hired by the company for security consulting services.
In addition to offering a contract to the gym owner, the U.S. Department of Justice says Kloster reduced the gym's monthly membership to just $1, deleted his photo from the database and stole a staff member's tag. Weeks later, the suspect posted a screenshot on social media showing the gym's security camera system under his control.
See also: Vulnerability in PostgreSQL allows hackers to exploit environment variables

Later, on May 20, the indictment says Kloster hacked into a nonprofit organization and accessed a restricted area where he used a bootable disk to bypass authentication requirements and access sensitive information. Kloster allegedly installed a virtual private network (VPN) on the nonprofit organization's computer and changed account passwords.
The DOJ says Kloster's efforts to promote his cybersecurity services caused an estimated $5,000 in to the nonprofit, which had to remediate the breach and secure its systems. Finally, Kloster is accused of using stolen credit card information from his former employer to purchase "hacking thumb drives" designed to exploit vulnerable systems.
If convicted, Kloster could face up to 15 years in prison (5 years for unauthorized access + 10 years for reckless damage), fines, and compensation to victims for financial losses.
See also: GitHub CLI RCE vulnerability allows execution of malicious commands
Network security has become one of the most critical issues of the digital age, as threats of network breaches continue to grow. When a network is compromised, attackers can gain access to sensitive data, causing serious consequences for businesses and consumers. Compromised networks can lead to information loss, identity theft, and financial losses. Organizations must invest in advanced cybersecurity measures and educate their employees about the risks, while implementing strict access policies and security controls, to protect their information in the ever-evolving threat landscape.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
