❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayCyberScoop

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

24 September 2026 at 13:07

Law enforcement has arrested two leaders of a Russian-owned phone hacking company used by Kremlin agencies who allegedly masked its foreign ownership from the U.S. Defense Department, Department of Homeland Security and others to win millions of dollars worth of contracts, the Justice Department announced Wednesday.

Lee Reiber of Boise, Idaho, the CEO of Oxygen Forensics (Oxygen US), was arrested in his home state and Oleg Davydov, one of five Russian nationals whom DOJ said actually controlled the company, was arrested in London, from where the department plans to seek his extradition. They face charges of conspiracy to commit wire fraud.

Publicly, Oxygen went to great lengths to present Reiber as the true leader of a company based in Alexandria, Va., asserting that the company was not controlled by Russian-based executives, according to a criminal complaint., While the company told government agencies it was U.S.-owned, Russian officials with the company repeatedly overruled him, the complaint alleges. 

Oxygen’s business aims were complicated in 2022 after the United States expanded sanctions against Russia following its invasion of Ukraine. That’s when the company installed Reiber as CEO and removed the owners from public corporate filings. An unnamed co-conspirator in the complaint nonetheless said that “fateful decisions will be made by” five shareholders, including Davydov. 

Since March 2022, Oxygen has sold its forensics software to the U.S. Secret Service, Homeland Security Investigations, the DHS inspector general and DOD. After the 2022 sanctions, Oxygen won more than $2 million in contracts and purchases from the Secret Service and its National Computer Forensics Institute. Reiber asserted U.S. ownership as recently as February of this year to the NCFI, according to the complaint.

Reiber knew the company had to conceal its true ownership, the complaint states. Oxygen and its competitors have quarreled in the media and in courts. Oxygen in 2023 faced accusations that Oxygen US and Oxygen Russia were both using software code reverse-engineered from Elcomsoft’s products. Oxygen Russia’s customers included the Russian Federal Security Service (FSB). 

“The accusation mattered to Reiber because answering it truthfully would have required disclosing that Oxygen US and Oxygen Russia sold the same software, developed by the same team, and were owned by the same people,” the complaint reads, citing email correspondence.

Knowing Oxygen’s actual ownership configuration would’ve changed the equation for the government agencies, according to the complaint.

“Procurement officials at the U.S. government customers have represented that they would not have awarded or renewed contracts for the forensic software had they known that OxygenUS was a Russian-owned company,” the complaint reads.

Natalia Krapiva, senior tech-legal counsel at Access Now, celebrated what she nonetheless called an overdue move from DOJ.

“For years, civil society warned that Oxygen Forensics was owned and built from Russia. Now the Justice Department confirmed it,” Krapiva told CyberScoop. “We applaud the U.S. government for taking this crucial step, but the fact that it took so long is both a national security and a human rights scandal.”

“The same technology that extracted data for U.S. investigations has been used inside Russia to jail journalists, activists, and peaceful dissenters. And it doesn’t stop at the U.S. border,” she continued. “We call on the U.S. and over 100 governments using this technology to immediately sever all ties to the company, implement sanctions, and conduct full investigation(s) of how Russian tech designed for the FSB spent all these years inside their sensitive law enforcement operations.”

Court-listed attorneys for Reiber listed in court documents didn’t respond to requests for comment. No attorney for Davydov could be located.

The DOJ in its announcement specified that “The complaint does not allege that the software contained malicious code or that it was used to gain unauthorized access to any customer’s computer systems or data.”

The post Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges appeared first on CyberScoop.

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

20 August 2026 at 11:27

A bill to battle organized retail theft has wide bipartisan support and momentum on Capitol Hill, even as opponents say it threatens to dangerously expand surveillance centered in Immigration and Customs Enforcement at a time when the agency’s aggressive conduct is under scrutiny.

Backers counter that critics are wrong about the bill that they say only would enhance existing information sharing arrangements, and could play a role in fighting cyber-enabled crime, too.

At its core, the Combating Organized Retail Crime Act (CORCA) establishes an Organized Retail and Supply Chain Crime Coordination Center within ICE’s Homeland Security Investigations division. It also would create criminal penalties for money laundering proceeds from selling stolen goods, and a $5,000 threshold for the combined total value of stolen property over a year for charging purposes.

It passed the House in June by a vote of 348-60, and Senate supporters are pushing for its inclusion in the annual defense policy bill, considered “must-pass” legislation that Congress has cleared for more than 60 consecutive years.

Opponents are trying to beat back CORCA, which arose from fears of mass theft during the COVID-19 pandemic.

“Its design actually creates a very large and very dangerous surveillance network,” said Nina Patel, senior policy counsel at the justice division of the American Civil Liberties Union. “You would hear the words ‘organized retail crime’ and think that this might be about shoplifting, and you would be surprised to learn that much of the apparatus is concentrated within the Department of Homeland Security.”

The objections

Patel and Jina John, her colleague at the ACLU, said the bill inadequately defines key terms: “organized retail crime,” even, as well as “retailers,” and what kind of data can be shared.

“It’s very broadly and vaguely drafted, and so the way it’s done is that it establishes all these mechanisms for data sharing among these entities, including getting data directly from retailers,” said John, senior policy counsel for AI, privacy and technology. “The data sharing is for any threats related to retail and supply chain crime. That’s it, just: threats. …That’s the biggest concern, is that this is basically giving DHS access to retail surveillance,” she said, like surveillance cameras at malls and train stations, Flock cameras and automated license plate readers.

Rather than the federal government purchasing data from brokers for surveillance purposes — already a contentious practice — CORCA gives them an avenue to get it freely, John said.

A variety of civil liberties and civil rights organizations are among the coalition trying to defeat CORCA. A key issue for many of them is the fusion center at ICE, which has collated data like cell phone location, health and other information, said Spencer Reynolds, senior counsel at the Justice in Public Safety Project at the NAACP Legal Defense and Education Fund. Adding retail data makes that worse, he said. 

“Together, this information allows ICE to hunt down people, find their families and associates, and pull them from their communities,”  he said. “The agency, over the last couple of years, especially, has been openly engaging in racial profiling, and poor Black and Brown people are likely to feel the impact of this the most.”

Reynolds continued: “The entire model that CORCA is going to impose allows government and industry participants to overcome protections, safeguards, guardrails, and use government to target their opposition.”

The support

Backers argue that the bill poses no risk to anyone but organized retail crime leaders.

“Over the years, organized retail crime has evolved into a deadly, multi-jurisdictional threat to American lives, the United States’ economy and our national security,” Senate Judiciary Chairman Chuck Grassley, R-Iowa, said in a statement. “My Combating Organized Retail Crime Act is a targeted, bipartisan bill that would crack down on large-scale retail theft by coordinating federal, state and local law enforcement efforts, while aligning existing resources.” 

A Senate Judiciary Committee spokesperson said the bill doesn’t give DHS any additional enforcement authorities, and is housed within DHS’s Homeland Security Investigations to build on the role they currently have in addressing transnational and organized criminal activity.

The American Trucking Associations supports the bill, and its legislative director Alex Rosen disputed opponents’ claims about its surveillance risks. 

“When you can’t argue the merits of the legislation, it’s easy to revert back to stale, overused buzzwords and an attempt to rile up opposition,” she said. “The idea that this would increase government surveillance is nutty because what this does is it creates within HSI a kind of central reporting repository for industry to report high-level crimes, crimes that are part of big organized criminal theft groups … The idea that this would somehow give the government more authority to surveil Americans is crazy because nowhere in the text does it say that.”

David Johnston, vice president of asset protection and retail operations for the National Retail Federation, noted the difference between ICE’s HSI, focused on a variety of criminal investigations including cybercrime, and its Enforcement and Removal Operations division that’s focused on finding and evicting those who violate U.S. immigration laws.

The bill could be one answer to rising cybercrime, he said.

“There has really been a substantial increase in not only the activity but the methods, the tactics, and as retail has evolved into the digital environment as much as it is in the physical store environment — we’ve seen the criminal, the organization, the structure, the convergence between how cyber and physical thieves operate,” he said, mentioning gift card fraud, or e-commerce fraud that started from a phishing or account takeover. “It’s really become a substantial issue for retailers, consumers, communities across the board.”

Cyber means have also aided cargo theft with the creation of false personas and more, Johnston said: “They’re not going and stealing these trucks with physical violence. They’re driving them right out of the yard, waving to the security officer because they’ve got this whole organization behind them that are using these cybercriminal tactics.”

Where it’s headed

Both sides are optimistic that they’re making progress on the bill. Kristina Roth, the senior policy associate leading the NAACP LDF’s criminal legal system policy portfolio, said a number of lawmakers who actually sponsored the legislation voted against it on the floor.

That points to lawmakers becoming more educated on the bill, which moved swiftly this year from committee to a full vote. “I think the connections that this legislation has through DHS were maybe not well enough described as they could have been,” Roth said.

Patel said there’s more work to be done.

“What is really disturbing about this bill is the way it’s been presented to a number of legislators, and it keeps getting this moniker of being a bipartisan bill,” she said. “But I think few people recognize just how much power is being given to ICE, the complete lack of accountability from DHS and ICE under this administration and in the past, and empowering them to reach into Main Street and into consumer spaces.”

Rosen pointed to the wide House vote as well as bipartisan support from leaders of key committees, such as the Judiciary and the Senate Homeland Security and Government Affairs committees, to include the bill in the annual National Defense Authorization Act. The nature of the support has supporters optimistic about the chances for CORCA to become law.

The defense legislation often wins passage around the end of each calendar year. 

The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.

Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas

By: Greg Otto
11 August 2026 at 14:02

Delta Airlines said Tuesday it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.

Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.

Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”

Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.

“We are fully investigating to gather a complete set of facts, which will take time,” Durrant told CyberScoop. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”

The Atlanta office of the FBI, along with the Federal Aviation Administration, said it was aware of the incident, but did not provide further comment. The Transportation Security Administration referred CyberScoop to the FBI. Homeland Security Investigations did not respond to a request for comment.

The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.  

The timing of the incident comes as the annual DEF CON cybersecurity conference concluded in Las Vegas on Sunday. The flight, originally scheduled for Sunday, did not leave Las Vegas until 8:30 a.m. Monday.

Monika Hathaway, head of press for DEF CON, told CyberScoop that Delta nor any federal authorities have reached out about the incident. However, she said this year’s conference had trouble with similar attacks.

“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Hathaway told CyberScoop. “If we had caught them doing this at DEF CON we would have removed and banned them from the conference.”

The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.

❌
❌