On Friday, I revealed that Veritracks, an online platform used by law enforcement, parole officers and probation officers to track offenders with GPS devices such as ankle monitors, had been hacked.
The data, provided to me by a hacktivist group, contained information on not only the thousands of people being monitored, but on the government agents and private sector employees doing the monitoring as well.
Sensitive data including names, home addresses, phone numbers — as well as identifying characteristics like eye color, gender, hair color, height, markings and tattoos, race and whether the individual is a registered sex offender — was also exposed.
When it comes to dealing with hacked and leaked data, confirming its legitimacy is the most important step. And if you’ve ever wondered what that looks like, it often involves contacting people found in the data to ask whether the information is accurate.
Doing so is always a somewhat awkward task. When someone picks up the phone, I have a short window to explain who I am and why I am calling.
And when people hear that I’m a journalist and that they may have been hacked or had their data exposed, they are almost always skeptical. I can’t count the number of times I’ve been hung up on by people who seem to be convinced that I’m a scammer.
Dealing with the Veritracks data was no different. While calling phone numbers in the dataset, I got on the phone with an employee of the Arkansas government. After letting them know about the data breach, I was met with a long silence before the eventual “click” of the phone call ending. That is a very common reaction.
I called another person, while looking at their home on Google Maps, and was hung up on as well. While my goal is to alert the public to their data being exposed, I always feel somewhat uncomfortable having the data to begin with.
Luckily, in this case, the hackers — as far as I know — made the data available only to me and the non-profit leak archiver DDoSecrets. And once I’m done analyzing and writing about the data, it is destroyed. The goal of the hack, according to the group behind it, was to expose the poor security practices of a law enforcement-related entity.
Yet, as of this week, the Veritracks system remains online. And the company behind it, which never responded to my emails, doesn’t seem to have released any public statement on the breach.
Click Here For The Original Source.
