Canadian Teen Arrested for Heartbleed Hack

One week after the OpenSSL Heartbleed vulnerability was unveiled, authorities have made the first arrest connected to exploiting the security hole. Canadian mounties arrested 19-year-old Stephen Solis-Reyes from London, Ontario for allegedly using his knowledge of Heartbleed to steal about 900 Social Insurance Numbers (SINs) from the Canada Revenue Agency (CRA).

Just five days ago Bloomberg reported that the U.S. National Security Agency (NSA) had know about the bug since 2012 and also exploited it for two years. Though the NSA is denying the report, it is likely that people have used Heartbleed in some way because of its prevalence around the Internet.

In fact, Heartbleed hackers have hit Mumsnet, a parent-to-parent Web site in the U.K., potentially putting the personal information of its 1.5 million registered users at risk before the hack was discovered and the flaw patched, according to The Telegraph.

While the majority of financial and government institutions have already updated their services to a secure version of OpenSSL, it appears as though 50 million Android users could still be at risk. One version of the mobile operating system, Android 4.1.1, is both vulnerable and widely used.

The Arrest

Solis-Reyes is not only the first person to be arrested for allegedly using the Heartbleed bug to his advantage but his attack is also the first to be recorded. Now that Heartbleed is in the public spectrum, Web sites know what an attack looks like, enabling Solis-Reyes to be caught. Authorities discovered that during a six-hour window, someone was able to exploit Heartbleed to steal private taxpayer information.

It is concerning that any government Web site was not patched immediately after Heartbleed was announced, though the Canada Revenue Agency said that it had been working to update its system. "The CRA is one of many organizations that was vulnerable to...

Comments are closed.