2013-03-15: Security Researcher Brian Krebs Harassed By Cybercriminals
Level Three Attack
After his site was taken down by a DDoS, Brian Krebs' home was the subject of a faked 911 call (an act called 'SWATting') that resulted in an armed police response. It looks like the person or persons who attacked his site also used a fake caller ID to make the police think that Krebs' home was being robbed and that his wife had been shot. Naturally, the police responded in full force.
He points out on his blog that for many American homes, this armed response could have led directly to physical violence and shooting due to the misunderstanding - even when both the police and the victim of the "prank" were innocent. He had notified his local police six months ago that something like this might happen, and although the on-scene commanding officer had not heard about the report, the situation was still resolved peacefully.
I've ranked this as a Level Three Attack for a few reasons:
- A fraudulent letter, claiming to be from the FBI, was sent to his anti-DDoS provider
- His site was taken down for a period of time by a distributed denial of service attack
- The criminals faked the caller ID of his mobile phone when they placed the phone call to 911
- Later in the day, the Ars Technica website was bombarded by a DDoS allegedly from the same source as the previous attack
- An armed SWAT team showed up at his house
Related Links
- Krebs On Security: The World Has No Room For Cowards
- ArsTechnica: Security reporter tells Ars about hacked 911 call that sent SWAT team to his house (Updated)