Hackers expose personal data of thousands on probation and parole | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Hackers have exposed personal information about thousands of people on probation and parole — and about agents tasked with tracking them.

The data includes names, home addresses, email addresses and telephone numbers. It was stolen from VeriTracks, a subsidiary of Texas-based Securus Monitoring, which uses physical devices and GPS technology to help law enforcement agencies keep tabs on people in the criminal justice system.

Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™

Point phone camera here

Hackers from a group known as the Internet Yiff Machine provided the data to Straight Arrow and the leak archiving organization DDoSecrets.

In a statement,  the hackers told Straight Arrow they targeted Veritracks as part of a broader effort to “disrupt the current flow of the police and prison industrial complex.”

“Our first reason for hacktivism is to support the many other forms of protest,” the hackers wrote. “The people on the streets, the journalists covering our work, the insiders who feed us information and sabotage from within; we all work in tandem. We make previously private data public. We aim to disrupt the current flow of the police and prison industrial complex. We aim to show others it’s not hard to be a part of the resistance, in whatever way you see fit.”

The Internet Yiff Machine also cited animus towards law enforcement earlier this year after breaching the crime tip management software company P3 Global Intel, resulting in the exposure of 8.3 million crime tips sent to law enforcement, Crime Stoppers, the U.S. military and thousands of schools.

Straight Arrow reached out to Securus Monitoring for a statement about the breach of Veritracks but did not receive a reply.

The Veritracks platform can be used in tandem with numerous monitoring products, such as GPS and RF monitoring devices as well as alcohol testing devices “with GPS location tracking and facial recognition capabilities,” according to Securus Monitoring.

Among the files provided to Straight Arrow include one labeled “agents” that contains 90,258 entries. The entries include data such as first and last names, employers, phone numbers and email addresses. A separate file called “users” also contains 56,851 entries detailing those with access to the Veritracks system.

Many of the email addresses are for Securus Monitoring employees, while others are linked to drug and alcohol recovery organizations and the government of Arkansas, all of which use Veritracks. Straight Arrow called one of the phone numbers and confirmed it was associated with an Arkansas government employee as stated in the data. When informed about the data leak, the employee hung up.

Another file named “offenders” holds 29,670 entries. Detailed identifying characteristics are listed in some entries: eye color, gender, hair color, height, markings and tattoos, race and whether the individual is a registered sex offender. Vehicle descriptions, including make, model, year, color and license plate number, are present throughout.

The file “enrolleeAddress” includes 25,077 entries, added into the Veritracks system between 2014 and 2026. In addition to standard identifying information, the entries contain latitude and longitude coordinates. Several addresses analyzed by Straight Arrow were associated with private homes and recovery centers, likely the residences of those being monitored. A file called “tagVisitLink” also held 160,813 entries related to approved locations where offenders could visit, such as schools, work offices, grocery stores, rehabs and physical therapy practices. 

“A leaked criminal record can follow someone for years and make rehabilitation much harder,” Sean O’Brien, founder of Yale Privacy Lab and CEO of Ivy Cyber, told Straight Arrow. “A breached treatment history exposes deeply private information, and privacy protections are a major promise during treatment for substance use.”  

“Coupled with location data, the people impacted by this breach face very real dangers that include stalking, harassment, and targeted surveillance,” O’Brien continued. “Physical descriptions such as tattoos can now be used as surveillance identifiers in systems like Flock that allow police to search video based on visible characteristics.”

A small file called “incident” detailed alleged criminal offenses, seemingly carried out by those being monitored, and their corresponding locations and case numbers. In one such entry, an offender is accused of carrying out a robbery last year in Arkansas. Other data lists the results for a small number of on-demand alcohol tests and 10,566 entries regarding the supervision schedules for offenders.

While the Internet Yiff Machine did not reveal how exactly it gained access to the data, the hacker group said that “Veritracks could’ve prevented our attack many different ways” but failed.

Round out your reading



Click Here For The Original Source.

——————————————————–

..........

.

.