Powered by MOMENTUM MEDIA
cyber daily logo
Breaking news and updates daily. Subscribe to our Newsletter

National Public Data hacker USDoD arrested in Brazil

Brazil’s federal police force has arrested the infamous hacker USDoD, the very same threat actor connected to the National Public Data and CrowdStrike data breaches.

user icon Daniel Croft
Thu, 17 Oct 2024
National Public Data hacker USDoD arrested in Brazil
expand image

Yesterday (16 October), Brazil’s Polícia Federal (PF) announced the arrest of Luan BG, better known online as USDoD, after it was suspected that he had breached PF systems.

“The Federal Police launched Operation Data Breach on Wednesday (16/10), with the aim of investigating invasions of the systems of the Federal Police and other international institutions,” said the PF.

“A search and seizure warrant and a preventive arrest warrant were served in the city of Belo Horizonte/MG against an investigated person suspected of being responsible for two publications selling Federal Police data, on May 22, 2020 and on February 22, 2022.”

============
============

The threat actor, also known as EquationCorp, has been connected to a number of high-profile data breaches, including on Airbus, a 70-million-record-strong US criminal database, and most recently, US background-checking firm National Public Data, which recently filed for bankruptcy.

However, it was USDoD’s breach of US cyber security firm CrowdStrike that landed him in deep water.

In July, the threat actor claimed to have leaked CrowdStrike’s “entire threat actor list” list on popular threat forum BreachForums, with a link to the alleged list.

In response to the alleged breach, CrowdStrike sent an anonymous report to Brazilian publication TecMundo, revealing the identity of USDoD as 33-year-old Brazilian man Luan BG.

Speaking with HackRead, USDoD confirmed that the information CrowdStrike leaked about him was real and that he was, in fact, Luan BG and lived in Brazil.

“So congrats to Crowdstrike for doxing me, they are late for the party, intel421 Plus and a few other companies already doxed me …,” he told HackRead.

Likely with the assistance of this information, the PF arrested USDoD.

“The prisoner boasted of being responsible for several cyber invasions carried out in some countries, claiming, on websites, to have disclosed sensitive data of 80,000 members of InfraGard, a partnership between the Federal Bureau Investigation – FBI and private critical infrastructure entities in the United States of America,” said the PF.

“The investigation will continue to identify any other cyber intrusions that were committed by the person under investigation.”

Discussion of USDoD’s arrest ignited on BreachForums, with fellow users shocked by the incident.

One user said that he had spoken to Luan BG the morning of the arrest and that, despite confirming his identity to media, the arrest caught him by surprise.

“He had been in touch with me this morning, and I can tell you that he had no idea this was even a possibility at this point based on what the Federal Police had told his lawyer a couple of months ago,” said BreachForums user DissentDoe.

Daniel Croft

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.

newsletter
cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.