A group of 20-somethings with names like "Big Balls" gain unauthorized access to your servers, delete data, take your website down, and now you can't serve your customers and your organization goes belly up unless you pay money to a mafia boss.

Sounds a lot like ransomware, doesn't it? When your government starts imitating ransomware playbooks, it's a four-alarm fire. At least in theory one can negotiate with ransomware actors.

Here's another way the DOGE team is behaving like ransomware actors: Their strategy for taking over agency databases is to wait until the federal employees go home on Friday and then show up and work through the weekend to undermine federal security.
@briankrebs im curious what good laws are, like, at all, if people can just ignore them outright and face no consequences

@Viss @briankrebs this is something I have been wondering the past few weeks.

How can we make the laws work, b/c they clearly are crumbling, unless somehow the courts are able to claw back control.

@Viss @briankrebs unless the courts are really up to arresting folks for contempt and putting them in jail. I partly fear that though b/c what happen if they force a confrontation. Are the officers going to be up to that situation?

If they don't put their foot down then they are basically useless.

@Viss @briankrebs unfortunately the ruling class has always lived under a different set of laws. Namely: "what are you going to do, stop me?"
@Viss @briankrebs (there's a reason trump likes Andrew Jackson)
@Viss @briankrebs Selective enforcement is caustic to freedom and democracy but, unfortunately, also the standard operating procedure in the USA. It has been that way for years.
Ransomware isn't always about the money: Government spies have objectives, too

Feature: Analysts tell El Reg why Russia's operators aren't that careful, and why North Korea wants money AND data

The Register
@briankrebs tbh, that's also how you prep to fire someone, or a team. Not surprising at all.
@hal8999 @briankrebs If we recall, they tried to fire a ton of people with non personal emails over the weekend.
@briankrebs We need some French farmer level style protesting to blast all congressional offices with piles of manure.
@briankrebs Why aren't security officers stopping them at at the doors? Are the security people plants in on the joke? Just baffling.

@briankrebs

showing to the world that in the us is possible is already the biggest fail of national security in history ...

so what you’re saying is that #techbros own these ransomware groups and that’s why Elon has access to a whole conspiracy of them? that the joke about McAfee back in the day ―that he used to create the viruses attacking Windows OS and paid a cut to Gates― is true? that #techbros don’t make money selling software but with the vulnerabilities they create for committing the crimes that actually enrich them?

because from here it looks like that’s what Musk is exposing with DOGE.

@briankrebs

@blogdiva @briankrebs The techbros are boosting cryptocurrency, the whole business model of ransomware groups only works because of cryptocurrency…you may be on to something here.
@briankrebs How long before ransomware actors / foreign agents use this as a strategy? Roll up in some black SUVs, escorted by guys in body armor and balaclavas, with fake badges and real guns, with some fake paperwork and real malware?

@itgrrl @briankrebs It's not the guy with the encryption keys they're trying to exploit, it's the rent-a-cop at the door with keys to every door in the entire building. Physical access beats pretty much any other attack.

But yes, I actually used this example in a presentation on Monday when talking about IT security. I turned to the guy sitting closest to me and said "How many times would I need to hit you with a wrench before you give me your bank login credentials."

Of course the answer was along the lines of "None, there's not much in there." Yowza.

@JustinDerrick @briankrebs there already was, I think the second day of doge firings.they came in to some department claiming they were doge. They got caught.

@briankrebs Succession. That's what I'm stuck on in this. Given the security risks this access will leave in its wake, it's simply not possible for Elon Musk to credibly pass control to another party voluntarily. He's created a situation in which, soon or late, *any*:successor will need to remove him by force.

It's possible he hasn't thought that one through, but to quote the man himself, "I don't care."

@briankrebs indeed and now the ransomware clowns have reporters who sit on my work on TikTok and report it for my using Thoughts and Prayers by Drive by-Yruckers for a memorial photographic look on Mollison Way in Lewiston, Maine.

@briankrebs

Engaging in such data theft and destruction from a Federal Department seems like sedition or treason....high crimes against the nation and its citizens.

@yuhasz01 @briankrebs
Sadly Congress does not agree, so #Trump is safe.

And it's done by henchmen of #Trump, so these are safe too, should they get prosecuted accidentally, #Trump can just pardon them.

Yes, in an abstract, academic way, you are right, it looks like sedition, treason (IANAL), but it is not relevant, they won't be prosecuted for it.

@yacc143 @briankrebs

Not legislative action(compromised) or prosecution by DOJ,(compromised) ; US military deposing them....

@yuhasz01 @briankrebs
Commander-in-chief is also compromised, so the US military would have literally to mutiny.
@yacc143 @briankrebs Military coup....No soldier has to follow an unlawful order from superiors(Nuremberg trials 1947)

@briankrebs

but it's a different kind of ransomware.

those computers control all the money in the world.

by owning those systems, they have all the money. they don't actually need to blackmail anyone. it's a perfect crime that way.

@briankrebs I can’t like, but I agree

@briankrebs I know this definitely has to be affecting tax morale. So many of us are lectured about not falling for scams, and to make sure you know where your money is going when you send money to others. How many of us have been victim blamed when we got scammed?

US Treausry is compromised as far as I'm concerned. No one can trust that thier federal income tax is going where it's supposed to. How does anyone know that they won't get told to pay thier taxes a second time?.... months after they paid taxes the first time.

All the kinds of questions that we can't ask, and that also arent going to be answered

@Catwoman69y2k @briankrebs

and if we don't actually have a government, why should we pay taxes at all? Or follow any other federal laws? The whole thing simply breaks down, which is their real intent.

@darwinwoodka yeah, this is exactly the kind of thought process I have right now.
I know I suffered low morale in previous years (during Trump's first presidential term). I kinda held my nose and did it. (besides, I wanted to pay my state taxes)

But this time.... with "the DOGE brothers" and the kinds of people that suddenly have access our financials and personal info? Umm..... this seems like Gangland shit to me.

@briankrebs

@briankrebs Government has ALWAYS acted like the mafia. They are basically one.
@briankrebs I do hope you posted this on LinkedIn so we can identify the collaborators who would turn us in
A group of 20-somethings with names like "Big Balls" gain unauthorized… | Brian Krebs | 65 comments

A group of 20-somethings with names like "Big Balls" gain unauthorized access to your servers, delete data, take your website down, and now you can't serve… | 65 comments on LinkedIn

@briankrebs @blogdiva Ransomware groups probably are a better support experience than governments šŸ˜…

@briankrebs My worry (until this morning) was that people wouldn’t get social security checks this month. We know the GOP wants to end those payments, as well as Medicare and VA benefits, SNAP and Medicaid—and what’s to stop the boyz from simply deleting entire systems? Anything?

So I looked up the payment dates for 2025 and then checked my bank account this morning—all good this month (huge sigh of relief).

How long will the system hold?

#socialsecurity #wevebeenhacked

@briankrebs Elon Musk is just Sam Bankman-Fried, if he were not caught. His money isn't real, either.

@briankrebs

You cannot negotiate with dictators…

@briankrebs I wasn't going to say it—why give anyone ideas?—but I have been thinking that all along.
@briankrebs I know for sure their #goon accounts all got pings from #Russian IPs.
@briankrebs all you have to do is pay $1M and put that "Builders of the world, unite!" sign in your shop window.
http://webseitz.fluxent.com/wiki/PowerOfThePowerless
Power of the Powerless

Power of the Powerless

WebSeitz
@briankrebs " When your government starts imitating ransomware playbooks, it's a four-alarm fire." šŸ’Æ
@briankrebs is it time to have off shoobank accounts?
@briankrebs Government has a legal monopoly on violence, Brian. That's the main distinction between it and criminal organizations, who practice violence illegally.