Skip to main content

Hacker behind Ripoff Report extortion attempt extradited to the US.

Hacker emailed the Ripoff Report CEO, shared a video accessing the exec's account, and asked for a $90,000 payment.

A Cypriot national has been extradited to the US to face charges of hacking into review portal Ripoff Report, extorting the company, and selling access to its backend to a third-party.

The man, named Joshua Polloso Epifaniou, 21 years, and a resident of Nicosia, Cyprus, arrived in the US on Friday and is scheduled to be arraigned in front of a US court on Monday, July 20, where he'll be formally charged.

🌀 The Ripoff Report hack

"Epifaniou and his co-conspirator removed at least 100 complaints from the ROR database, charging SEO Company's 'clients' approximately $3,000 to $5,000 for removal of each complaint," the US Department of Justice said in a press release on Saturday.

The court documents did not identify Epifaniou's partner, but a Fox 11 investigation claims the Cypriot hacker worked with Pierre Zarokian, the founder of Submit Express, a reputation management company.

🌀 Pre-2016 hacks

In addition to his Ripoff Report hack and extortion, US officials have also accused Epifaniou of hacking and extorting other websites between October 2014 and November 2016.

To extort victims, officials said Epifaniou used two techniques.

He used security bugs to hack target sites and then steal user data himself, or he bought the victim site's user data from other hackers and then used it to extort the victim into paying a ransom.


Comments

Popular posts from this blog

What is BLACK WINDOWS 10 V2 windows based penetration testing os,and what are its features.Download link inside

                         Black Windows 10 V2

Mandiant Discloses Critical Vulnerability Affecting Millions of IoT Devices

Today, Mandiant disclosed a critical risk vulnerability in coordination with the Cybersecurity and Infrastructure Security Agency (“CISA”) that affects millions of IoT devices that use the ThroughTek “Kalay” network. This vulnerability, discovered by researchers on Mandiant’s Red Team in late 2020, would enable adversaries to remotely compromise victim IoT devices, resulting in the ability to listen to live audio, watch real time video data, and compromise device credentials for further attacks based on exposed device functionality. These further attacks could include actions that would allow an adversary to remotely control affected devices. At the time of writing this blog post, ThroughTek advertises having more than 83 million active devices and over 1.1 billion monthly connections on their platform. ThroughTek’s clients include IoT camera manufacturers, smart baby monitors, and Digital Video Recorder (“DVR”) products. Unlike the vulnerability published by researchers from Nozomi Ne...