Site navigation

Emergency Data Request Exploit Catches Meta and Apple off Guard

David Paul

,

Meta and Apple data
The tech giants have fallen foul of cyber-actors posing as law enforcement using forged legal requests to access data on millions of users.

Tech giants Apple and Facebook parent company Meta have provided customer data to hackers pretending to be law enforcement officials, according to various sources.

Hackers exploited  an ‘emergency data request’. The request, which is used by law enforcement officials in the US, is used to get access to user data in extreme circumstances.

An emergency data request functions differently to something like a subpoena or search warrant, as those must be signed by a judge, emergency data requests do not.

In Apple and Meta’s case, hackers accessed legitimate emails of global law enforcement agencies to request data. Apple and Meta complied with the request.

The companies handed over basic subscriber details, including a customer’s address, phone number and IP address, in mid-2021.

According to some cybersecurity researchers, it is suspected that the hackers may have been children located in the UK and the US.

Researchers also said they believed one of the minors is believed to be behind the cybercrime group Lapsus$, which has previously hacked large corporations including Microsoft, Samsung, and Nvidia Corp.

Irene Coyle, Training Director at OSP Cyber Academy, commented: “The implications from the Apple and Meta data breach are immense especially the sophisticated new technique used in these breaches and reinforces the mindset that no organisation, regardless of size is exempt from being targeted.

“The extent the hackers went to was substantial and not forgetting that they were fully aware of the vulnerability that emergency requests posed to companies in the US. The urgency with this style of data breach is a common tactic which relies on individuals/company representatives to have to make quick decisions and potentially bypass security protocols.”

Attacks such as these are becoming increasingly common, according to cybersecurity investigators KrebsonSecurity.

Researchers at Krebs said there was a “terrifying and highly effective” method of cyberattack being used to “harvest sensitive customer data from Internet service providers, phone companies and social media firms”.

Hackers send demands for subscriber data under the guise that they cannot wait for a court order because it relates to an urgent matter of life and death.


Recommended


A security specialist and lecturer at the University of California, Nicholas Weaver, told KrebsonSecurity that a major challenged to combating these types of attacks is that there is fundamentally no notion of global online identity.

“The only way to clean it up would be to have the FBI act as the sole identity provider for all state and local law enforcement. But even that won’t necessarily work because how does the FBI vet in real time that some request is really from some podunk police department?”

Commenting on the hack, Brian Higgins, security specialist at Comparitech told DIGIT: “Emergency data requests from law enforcement are often vital in live ‘crime in action’ and vulnerable missing person cases, among others.

“They come from dedicated units and registered investigators and by their very nature can frequently relate to vulnerable individuals, companies or groups.

“To describe the success of this methodology as a ‘slip-up’ is fairly accurate as the implementation of some very basic cyber hygiene (in this case, a mandatory verification call-back for all emergency requests) on the part of Apple, Meta, or any law enforcement liaison team for that matter, would see attackers looking for other less simple ways to commit their crimes and offer an added layer of much needed protection.”


Big tech and data

This is not the first time that Meta and Apple have been both been caught short when it comes to handling user data.

In January this year, Meta was hit with an anti-trust lawsuit in the UK after claims data of 44 million users was misused over a four-year period.

Financial Conduct Authority adviser Liza Lovdahl Gormsen said was looking to sue the company for £2.3 billion on behalf of millions of UK users who used the platform between 2015 and 2019.

In March, the social media giant was handed a substantial €17 million (£14.2m) GDPR fine for breaching EU data privacy laws.

Back in November 2019, Apple said it was looking to capture the healthcare data of iPhone users and Apple watch wearers through a new Research app.

The company says the app will help “advance science” by sharing the gathered data with ongoing medical studies.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

David Paul

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data