Celebrity hacker Guccifer's confession gives us all a lesson in security

He pleaded guilty to unauthorized access to a protected computer and aggravated identity theft

The activity of Romanian hacker Guccifer, who has admitted to compromising almost 100 email and social media accounts belonging to U.S. government officials, politicians and other high-profile individuals, is the latest proof that humans are the weakest link in computer security.

Marcel Lehel Lazar, 44, is not a hacker in the technical sense of the word. He's a social engineer: a clever and persistent individual with a lot of patience who a Romanian prosecutor once described as "the obsessive-compulsive type."

By his own admission, Lazar has no programming skills. He didn't find vulnerabilities or write exploits. Instead, he's good at investigating, finding information online and making connections.

Lazar pleaded guilty Wednesday in U.S. District Court for the Eastern District of Virginia to charges of unauthorized access to a protected computer and aggravated identity theft.

According to the Department of Justice, Lazar admitted that from at least October 2012 to January 2014, he gained unauthorized access to the email and social media accounts of around 100 Americans with the intention of obtaining their personal information and correspondence.

His victims included an immediate family member of two former U.S. presidents, a former U.S. Cabinet member, a former member of the U.S. Joint Chiefs of Staff, and a former presidential adviser, the DOJ said.

While the victims weren't named in the indictment, Guccifer is known to have released documents, pictures and information that were stolen from the personal email accounts of former U.S. Secretary of State Colin Powell and several members and friends of the Bush family, including Dorothy Bush Koch, daughter of 41st U.S. President George H.W. Bush and sister of 43rd U.S. President George W. Bush.

In an interview with online publication PandoDaily in 2015, Lazar said that he gained access to Powell's AOL email account by guessing the password, which was based on the former secretary of state's grandmother's name. There he found correspondence between Powell and a Romanian politician named Corina Cretu, which led to him targeting her as well.

In the same interview, Lazar claims that he broke into Cretu's Yahoo email account after guessing the answer to her security question: the street where she grew up. First he found the name of the primary school that she attended on her public Facebook page. Then he methodically tried out street names close to Cretu's childhood school until he found the right one, correctly assuming that she attended a school close to her home.

This shows how apparently harmless information like a school's name can help criminals and why people should be careful with what they disclose about their lives online.

Of course, celebrities, politicians and other public figures can't always avoid information about their personal lives appearing online. If they don't disclose it themselves, someone else probably will, in Wikipedia pages, news articles, gossip blogs, biographies and so on.

It might be a good idea then, especially for high-ranking politicians, to attend training courses on how to protect themselves and their online accounts from social engineering attacks. Other politicians whose personal email accounts were compromised in the past by hackers using social engineering techniques include former Alaska Governor Sarah Palin and CIA Director John Brennan.

Once they achieve a certain level of fame that could make them a target, everyone should go back and review their online accounts: Do those websites really need so much real personal information or can some be removed? Are passwords strong enough and different between accounts? Do the websites offer two-factor authentication? What account recovery or password reset options do they offer? Are they easy to bypass using public information? Are the answers to security questions for those accounts easily guessable? Are those accounts even needed anymore? If not, is there an account delete option?

These are good issues for anyone -- not just the rich and famous -- to address. It might be a time-consuming process, but not more than having to later deal with a potential data breach and having your private conversations with friends, family or past lovers dumped in the public domain.

Guccifer was extradited earlier this year to the U.S. from Romania, where he was already serving a prison sentence for hacking into the email accounts of various local public figures.

His sentencing in the U.S. is scheduled for Sept. 1. After that he could be returned to his home country to serve out his sentence there, as the Romanian courts granted extradition for a maximum of 18 months.

In Romania, Lazar is serving two prison sentences, for a total of seven years. In June 2014 he was sentenced to four years in prison for hacking into the personal email account of George Maior, the former head of the Romanian Intelligence Service and current Romanian ambassador to the U.S.

However, at that time he was already under a six-year supervised release term after receiving a three-year suspended prison sentence in 2012 for hacking into the email accounts of other Romanian celebrities. Because he violated the release terms, the older three-year prison sentence got activated and he must serve seven years.

It's not clear if the U.S. sentence, which can carry a punishment of between two and seven years in prison, will be served separately.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Toys for Boys

Family Friendly

Stocking Stuffer

SmartLens - Clip on Phone Camera Lens Set of 3

Learn more >

Christmas Gift Guide

Click for more ›

Brand Post

Bitdefender 2019

This Holiday Season, protect yourself and your loved ones with the best. Buy now for Holiday Savings!

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Aysha Strobbe

Microsoft Office 365/HP Spectre x360

Microsoft Office continues to make a student’s life that little bit easier by offering reliable, easy to use, time-saving functionality, while continuing to develop new features that further enhance what is already a formidable collection of applications

Michael Hargreaves

Microsoft Office 365/Dell XPS 15 2-in-1

I’d recommend a Dell XPS 15 2-in-1 and the new Windows 10 to anyone who needs to get serious work done (before you kick back on your couch with your favourite Netflix show.)

Maryellen Rose George

Brother PT-P750W

It’s useful for office tasks as well as pragmatic labelling of equipment and storage – just don’t get too excited and label everything in sight!

Cathy Giles

Brother MFC-L8900CDW

The Brother MFC-L8900CDW is an absolute stand out. I struggle to fault it.

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?