This guy was under the impression that what he was doing wasn’t illegal.
IANAL but the fact that he is being charged with access device fraud might suggest that DOJ had to engage in some mental gymnastics in order to charge this. E: I’ll take that back since I actually read the indictment now, besides the usual raidforums fare he was also selling credit card data which would very much tend to attract access device fraud charges.
He knew what he was doing was illegal. You don't go through all the steps he did to stop authorities taking down the website without knowing what you're doing is illegal.
What steps were those? How are they distinguishable from the steps you would take to protect your website from being taken down because of abuse reports from upset people?
Trading in hacked data might not be illegal unless it’s credit card information, but your average hosting provider probably isn’t going to care about such nuances.
They focus on payment information as those are the most serious crimes and would provide the harshest sentence. Trading hacked emails does not carry the same weight as trading hacked credit card details.
If trading hacked emails wasn't illegal, you'd have legitimate and big businesses trading them. You don't see any businesses like that because it is infact illegal.
As someone else mentioned, an 'access device' actually refers to many things, including emails. You have an extremely poor understanding of the law if you even remotely think that trading hacked emails would somehow be legal.
> If trading hacked emails wasn't illegal, you'd have legitimate and big businesses trading them.
But there are in fact big infosec businesses trading them. They just brand it as “data leak monitoring” or “darknet intelligence” or whatever. Equifax does this, NortonLifeLock does this as do many others. There are also products aimed specifically for pentesters.
> As someone else mentioned, an 'access device' actually refers to many things, including emails
>”Access device" is defined at 18 U.S.C. § 1029(e)(1). Instead of using the term "credit card," or "debit/credit instrument," the term "access device" is used in the statute and is defined broadly as any "card, plate, code, account number, electronic serial number, mobile identification number, personal identification number, or other telecommunications service, equipment, or instrument identifier, or other means of account access that can be used, alone or in conjunction with another access device, to obtain money, goods, services, or any other thing of value, or that can be used to initiate a transfer of funds...." The only limitation, i.e., "other than a transfer originated solely by paper instrument," excludes activities such as passing forged checks.
What he was doing might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords. That was the bulk of the trade on raidforums anyway.
But yeah, definitely not the sharpest knife in the drawer.
If this sticks he will be gone for a long, long time, and, crucially, he handed over the the evidence himself so no amount of 'it wasn't me' is going to help here.
> Whoever, knowing that an offense against the United States has been committed, receives, relieves, comforts or assists the offender in order to hinder or prevent his apprehension, trial or punishment, is an accessory after the fact.
It’s not obvious at all that selling e.g. the leaked Linkedin database would be illegal in any way. You wouldn’t retroactively become an accessory to the original crime.
Of course, that stopped mattering the moment he started trafficking in stolen payment card information…
Also important to keep in mind he ( most likely ) wasn’t aware of US law. Not sure how Portugal classifies businesses such as these, but we know how e.g. Russia differs in this regard.
Yes, true, but that's exactly why if you aren't aware of something or unsure of something you play it safe. The number of people that got busted like this is large enough that I'm 100% sure that he was aware that this wasn't a legal operation, in fact he went to some length to hide his identity, which shows at least minimal awareness of this.
When I was a teen I did lots of stupid stuff but generally I was aware of where the line was and if and when it was crossed I was pretty careful about it (mostly: experimenting with 'modulated high frequency sine wave generation').
IANAL but the fact that he is being charged with access device fraud might suggest that DOJ had to engage in some mental gymnastics in order to charge this. E: I’ll take that back since I actually read the indictment now, besides the usual raidforums fare he was also selling credit card data which would very much tend to attract access device fraud charges.