
Even spammers have bad days. The good news is, one of the largest spam operations accidentally revealed their operations, so now we leave it to law enforcement to do their work. The bad news? About 1.4 billion accounts, including personal data about residential location, has been compromised.
MacKeeper Security Research Center published their findings, stating that it involves a database of 1.4 billion email accounts, with real names, user IP addresses, and in certain cases, physical addresses. MacKeeper Security Researcher, Chris Vickery wrote on the blog post “Chances are that you, or at least someone you know, is affected.”
The investigation was a cooperative effort from MacKeeper Security Research Center, CSOOnline, and Spamhaus. The files were initially discovered in January, where a collection of faulty backup file without password was leaked to the internet.
The files were tied to the operations of a group claiming as River City Media (RCM). The company was led by known spammers Alvin Slocombe and Matt Ferris, and masks as a legitimate marketing firm while being responsible for sending upwards of a billion daily emails. RCM uses automation and illegal hacking techniques to access and send bulk emails.
The leaked files were snapshots of backups and also included scripts and logs detailing the spammers’ activities in probing and exploiting vulnerable mail servers. As far as the report states, RCM has been using Slowloris attack, where they force the processing of bulk emails through temporarily stressing the resources of the receiving server.
Other details of more abusive scripts and techniques have since been forwarded to major tech companies including Microsoft and Apple. As law enforcement is currently involved and notified, the report state that there are limits to what can be published.
It was noted that this stint involves other smaller operations, and has collected a database of 1.4 billion peoples’ email accounts, full names, IP addresses, and often physical address. While there maybe doubts on the validity of the data, researchers have made a quick lookup and determined the data to be legitimate, although some data appears to be outdated by several years.
Vickery explained “Well-informed individuals did not choose to sign up for bulk advertisements over a billion times. The most likely scenario is a combination of techniques. One is called co-registration. That’s when you click on the “Submit” or “I agree” box next to all the small text on a website. Without knowing it, you have potentially agreed your personal details can be shared with affiliates of the site.”
At the time of reporting, it was noted that Spamhaus blacklisted RCM’s entire infrastructure.



