Elliott Gunton

Last updated

Elliott Gunton
Born
Elliott Gunton

c. 1999 (age 2425)
Other namesGlubz
planet
Known for
Criminal statusIncarcerated

Elliott Gunton (born c. 1999), also known by his online pseudonyms Glubz and planet, [1] is a convicted British cybercriminal from Norfolk. [2]

Contents

TalkTalk security breach

On 21 October 2015, [3] Gunton engaged in a "sustained cyberattack" against British telecom company TalkTalk, stealing the names, addresses, e-mails, and bank details of its users. [4] [5]

During the subsequent search of his home, law enforcement found "indecent images of children" on Gunton's devices. [4] He also confessed to targeting the websites of Manchester University and Cambridge University. [3]

In November 2016, Gunton pleaded guilty to his role in the data breach, telling the youth court that he was "just showing off to [his] mates." [6] [7] [8] He received a 12-month youth rehabilitation order. [3]

August 2019 conviction

Gunton was again investigated in April 2019, after CCleaner was found on his computer during an unannounced police visit, which was in violation of his Sexual Harm Prevention Order (SHPO). Through the investigation, he was found to have committed further crimes after his initial arrest, and in August 2019, he pleaded guilty to, in 2017 and 2018, laundering money, committing Computer Misuse Act crimes, and breaching a SHPO. He had also probed the websites of local high schools for vulnerabilities and illegally accessed Australian telecom company Telstra's systems, which he then used to gain access to the Instagram account @adesignersmind to send "grotesquely offensive" messages to the owner's customers. [9]

During a search of Gunton's home, police discovered £407,359.35 in cryptocurrency, which he had allegedly acquired from selling the account details of Instagram users on cybercrime forums. He was sentenced to 20 months of imprisonment but was immediately released due to time served. [4] Gunton's mother and father were given three- and five-month suspended sentences, respectively, for transferring the stolen funds. [10]

After his conviction, Gunton's cryptocurrency was auctioned off, the "first ever on the instruction of a police force in the UK." [11] [12]

EtherDelta cryptocurrency theft

On 13 August 2019, Gunton and Anthony Tyler Nashatka ("psycho") of Michigan [13] were indicted by a federal grand jury for their involvement in a December 2017 scheme to steal over US$1.4 million in Ethereum. [14] The two were accused of simjacking the CEO of the cryptocurrency exchange EtherDelta and using his access to redirect its users to a clone of EtherDelta, which would give Gunton and Nashatka details of cryptocurrency wallets that users had entered. [1] [15]

In July 2024, Gunton was sentenced to 3½ years of imprisonment for his involvement in the scheme. [16]

See also

Related Research Articles

<span class="mw-page-title-main">Cybercrime</span> Type of crime based in computer networks

Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or networks. These crimes involve the use of technology to commit fraud, identity theft, data breaches, computer viruses, scams, and expanded upon in other malicious acts. Cybercriminals exploit vulnerabilities in computer systems and networks to gain unauthorized access, steal sensitive information, disrupt services, and cause financial or reputational harm to individuals, organizations, and governments.

A cryptocurrency exchange, or a digital currency exchange (DCE), is a business that allows customers to trade cryptocurrencies or digital currencies for other assets, such as conventional fiat money or other digital currencies. Exchanges may accept credit card payments, wire transfers or other forms of payment in exchange for digital currencies or cryptocurrencies. A cryptocurrency exchange can be a market maker that typically takes the bid–ask spreads as a transaction commission for its service or, as a matching platform, simply charges fees.

<span class="mw-page-title-main">Virgil Griffith</span> American computer programmer

Virgil Griffith is an American programmer. He worked extensively on the Ethereum cryptocurrency platform, designed the Tor2web proxy along with Aaron Swartz, and created the Wikipedia indexing tool WikiScanner. He has published papers on artificial life and integrated information theory. Griffith was arrested in 2019 and in 2021 pleaded guilty to conspiring to violate U.S. laws relating to money laundering using cryptocurrency and sanctions related to North Korea. On April 12, 2022, Griffith was sentenced to 63 months imprisonment for assisting North Korea with evading sanctions and is currently in a federal low-security prison in Pennsylvania.

A web threat is any threat that uses the World Wide Web to facilitate cybercrime. Web threats use multiple types of malware and fraud, all of which utilize HTTP or HTTPS protocols, but may also employ other protocols and components, such as links in email or IM, or malware attachments or on servers that access the Web. They benefit cybercriminals by stealing information for subsequent sale and help absorb infected PCs into botnets.

<span class="mw-page-title-main">Cryptocurrency</span> Digital currency not reliant on a central authority

A cryptocurrency, crypto-currency, or crypto is a digital currency designed to work through a computer network that is not reliant on any central authority, such as a government or bank, to uphold or maintain it.

The dark web is the World Wide Web content that exists on darknets that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communicate and conduct business anonymously without divulging identifying information, such as a user's location. The dark web forms a small part of the deep web, the part of the web not indexed by web search engines, although sometimes the term deep web is mistakenly used to refer specifically to the dark web.

<span class="mw-page-title-main">Ethereum</span> Open-source blockchain computing platform

Ethereum is a decentralized blockchain with smart contract functionality. Ether is the native cryptocurrency of the platform. Among cryptocurrencies, ether is second only to bitcoin in market capitalization. It is open-source software.

Monero is a cryptocurrency which uses a blockchain with privacy-enhancing technologies to obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses trading Monero, transaction amounts, address balances, or transaction histories.

The Lazarus Group is a hacker group made up of an unknown number of individuals, alleged to be run by the government of North Korea. While not much is known about the Lazarus Group, researchers have attributed many cyberattacks to them since 2010. Originally a criminal group, the group has now been designated as an advanced persistent threat due to intended nature, threat, and wide array of methods used when conducting an operation. Names given by cybersecurity organizations include Hidden Cobra and ZINC or Diamond Sleet. According to North Korean defector Kim Kuk-song, the unit is internally known in North Korea as 414 Liaison Office.

Dridex, also known as Bugat and Cridex, is a form of malware that specializes in stealing bank credentials via a system that utilizes macros from Microsoft Word.

Bitfinex is a cryptocurrency exchange owned and operated by iFinex Inc, and is registered in the British Virgin Islands. Bitfinex was founded in 2012. It was originally a peer-to-peer Bitcoin exchange, and later added support for other cryptocurrencies.

A cryptocurrency wallet is a device, physical medium, program or an online service which stores the public and/or private keys for cryptocurrency transactions. In addition to this basic function of storing the keys, a cryptocurrency wallet more often offers the functionality of encrypting and/or signing information. Signing can for example result in executing a smart contract, a cryptocurrency transaction, identification, or legally signing a 'document'.

Cryptocurrency and crime describe notable examples of cybercrime related to theft of cryptocurrencies and some methods or security vulnerabilities commonly exploited. Cryptojacking is a form of cybercrime specific to cryptocurrencies used on websites to hijack a victim's resources and use them for hashing and mining cryptocurrency.

Bithumb is a South Korean cryptocurrency exchange. Founded in 2014, Bithumb Korea has 8 million registered users, 1 million mobile app users, and a current cumulative transaction volume has exceeded USD $1 trillion.

<span class="mw-page-title-main">Justin Sun</span> Chinese cryptocurrency entrepreneur

Justin Sun is a Chinese-born cryptocurrency entrepreneur and business executive. He is the founder of TRON, a cryptocurrency with an associated blockchain DAO ecosystem and USDD, a stablecoin issued by TRON DAO Reserve. Sun is also the owner of Rainberry, which developed the BitTorrent protocol and under Sun's leadership developed the BTT cryptocurrency token. Sun also owns the crypto exchange Poloniex, and is affiliated with the crypto exchange HTX. Sun served as Permanent Representative of Grenada to the World Trade Organization (WTO) in Geneva from 2021 to 2023.

Decentralized finance provides financial instruments and services through smart contracts on a programmable, permissionless blockchain. This approach reduces the need for intermediaries such as brokerages, exchanges, or banks. DeFi platforms enable users to lend or borrow funds, speculate on asset price movements using derivatives, trade cryptocurrencies, insure against risks, and earn interest in savings-like accounts. The DeFi ecosystem is built on a layered architecture and highly composable building blocks. While some applications offer high interest rates, they carry high risks. Coding errors and hacks are a common challenge in DeFi.

<span class="mw-page-title-main">Graham Ivan Clark</span> American hacker and cybercriminal (born 2003)

Graham Ivan Clark is an American computer hacker, cybercriminal and a convicted felon regarded as the mastermind behind the 2020 Twitter account hijacking.

References

  1. 1 2 "Alleged Cryptocurrency Thief 'Psycho' Charged In Brazen Digital Scheme". CBS. 11 October 2019. Retrieved 1 September 2024.
  2. Gilbert, Dominic (1 September 2019). "Revealed: How police caught teenage hacker who made £400,000 from his bedroom". Eastern Daily Press . Retrieved 1 September 2024.
  3. 1 2 3 "Teenager who hacked TalkTalk website given rehabilitation order". The Guardian . 13 December 2016. Retrieved 1 September 2024.
  4. 1 2 3 Corfield, Gareth (19 August 2019). "Teen TalkTalk hacker ordered to pay £400k after hijacking popular Instagram account". The Register . Retrieved 1 September 2024.
  5. Corfield, Gareth (22 October 2015). "TalkTalk: Hackers may have nicked personal, banking info on 4 million Brits". The Register . Retrieved 1 September 2024.
  6. Corfield, Gareth (15 November 2016). "TalkTalk teen hacker pleads guilty as firm reveals £22m profit jump". The Register . Retrieved 1 September 2024.
  7. Oates, John (26 September 2019). "Now Uncle Sam would like a word with Brit teen TalkTalk hacker about a huge crypto-coin heist". The Register . Retrieved 1 September 2024.
  8. Gilbert, Dominic (2 October 2019). "'Misguided' - parents of teenage hacker moved hoard of cryptocurrency during investigation". Eastern Daily Press . Retrieved 1 September 2024.
  9. Gilbert, Dominic (5 April 2019). "Three Norwich schools probed for weakness by teenage hacker". Eastern Daily Press . Retrieved 1 September 2024.
  10. "TalkTalk hacker Elliott Gunton: Parents acted out of 'misguided loyalty'". BBC. 2 October 2019. Retrieved 1 September 2024.
  11. Gilbert, Dominic (30 September 2019). "'Historic' auction of ill-gotten hoard of Bitcoin from Norwich computer hacker earns £240,000". Eastern Daily Press . Retrieved 1 September 2024.
  12. "TalkTalk hacker Elliott Gunton: Cryptocurrency auctioned by police". BBC. 30 September 2019. Retrieved 1 September 2024.
  13. "Michigan Resident Appears In Bay Area Federal Court On Hacking Charges". United States Department of Justice. 10 October 2019. Retrieved 1 September 2024.
  14. "TalkTalk hacker Elliott Gunton accused of computer fraud in US". BBC. 24 September 2019. Retrieved 1 September 2024.
  15. Stevens, Robert (23 September 2019). "US Attorney's Office indicts two suspects in EtherDelta hack". Yahoo News . Retrieved 1 September 2024.
  16. Parkin, Simon (26 July 2024). "TalkTalk hacker Elliott Gunton jailed in cryptocurrency scam". Eastern Daily Press. Archived from the original on 26 July 2024. Retrieved 1 September 2024.