Briton sentenced for huge cyber attack on Liberian telco

Operating out of Cyprus, this hacker-for-hire knocked the entire country's internet offline - thought to be world first

Graphic of a cyber criminal or hacker

A British cyber criminal hired by a Liberian telco has been jailed for 32 months in the UK for unleashing targeted DDoS attacks against another rival telco in 2016.

Being paid a monthly retainer by Cellcom, Daniel Kaye used a Mirai botnet which harnessed unsecured webcams to inundate Lonestar, the rival telco, with unsustainable levels of traffic which at its peak, caused the entire country's internet to go down.

Legal or not, it was definitely effective. Lonestar claimed its inability to provide service to its customers resulted in the loss of tens of millions of dollars as customers left the network. The telco also spent a further $600,000 in remedial action to prevent further attacks.

Kaye also hacked Deutsche Telekom's infrastructure to transmit some of the traffic to Lodestar.

After his spell in Cyprus where hs was based during his freelance Liberian attacks, Kaye returned to the UK in February 2017 and was arrested carrying $10,000 on his person, a sum which was part of the payments he received from Cellcom.

The National Crime Agency by this time had already linked him to the unsuccessful attack on three British banks - Lloyds, Barclays and Halifax - in January 2017 but Kaye claims he loaned out the botnet on the dark web during this time. These charges were later formally dropped.

Germany wanted Kaye extradited to face punishment there for hacking and misusing its infrastructure but instead, he faced the stronger charges for his crimes in Africa.

Kaye was tried and sentenced in the UK because British law (Computer Misuse Act 1990) allows a cyber criminal to prosecuted for an offence anywhere in the world.

Kaye is believed to be the first cyber criminal to bring down an entire nation's internet and as a result, "a substantial number of Lonestar's customers switched to competitors", said Babatunde Osho, Lonestar's former chief executive in written submissions to the court.

"In the years preceding the DDoS attacks, Lonestar's annual revenue exceeded $80m (62.4m). Since the attacks, revenue has decreased by tens of millions and its current liabilities have increased by tens of millions."

"Daniel Kaye was operating as a highly skilled and capable hacker-for-hire," said Mike Hulett, head of operations at the National Cyber Crime Unit. "His activities inflicted substantial damage on numerous businesses in countries around the world, demonstrating the borderless nature of cyber crime.

"Working in collaboration with international law enforcement partners played a key role in bringing Daniel Kaye to justice."

"The fact that he was caught and brought to justice shows some of the value of continued cooperation with our European counterparts in tackling cybercrime on a cross-border basis," said Paul McKay, senior analyst at Forrester. It is a rare example of a successful prosecution of a cybercriminal in an area where criminal attribution and bringing individuals to court to face prosecution is notoriously difficult."

Kaye was unsuccessful in the UK, but the botnet was so effective in Africa because Liberia's internet at the time was only provided only by a few telcos, relying on limited Atlantic cable which isn't as secure as modern European internet as traffic can reach users through more routes.

According to investigators, Liberia's internet was repeatedly downed between November 3 and November 4 2016 disrupting not just Lonestar but organisations and ordinary users up and down the state.

Featured Resources

Unleashing the power of AI initiatives with the right infrastructure

What key infrastructure requirements are needed to implement AI effectively?

Download now

Achieve today. Plan tomorrow. Making the hybrid multi-cloud journey

A Veritas webinar on implementing a hybrid multi-cloud strategy

Download now

A buyer’s guide for cloud-based phone solutions

Finding the right phone system for your modern business

Download now

The workers' experience report

How technology can spark motivation, enhance productivity and strengthen security

Download now

Recommended

What is e-safety?
e safety

What is e-safety?

27 Jan 2021
Your essential guide to internet security
Security

Your essential guide to internet security

27 Jan 2021
Mimecast links breach to SolarWinds hackers
Security

Mimecast links breach to SolarWinds hackers

27 Jan 2021
TikTok vulnerability exposed private user data
data protection

TikTok vulnerability exposed private user data

26 Jan 2021

Most Popular

How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
Hackers are actively exploiting three Apple iOS flaws
exploits

Hackers are actively exploiting three Apple iOS flaws

27 Jan 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

26 Jan 2021