Reading view

Russia Charges Telegram Founder Durov With Facilitating Terrorism

Russia has charged Telegram founder Pavel Durov with facilitating terrorism, alleging the platform was used by Ukrainian intelligence "to prepare and co-ordinate acts of sabotage and terror" inside Russia. An international arrest warrant has been issued for Durov, who currently lives in Dubai, United Arab Emirates, where Telegram keeps its main office. The BBC reports: Shortly after the charge was announced, Telegram's account on X posted an image showing Durov holding up his middle finger. He has previously accused Russian authorities of "fabricating new pretexts to restrict Russians' access to Telegram." [...] Multi-billionaire Durov, 41, has lived outside of Russia for many years and holds French and United Arab Emirates (UAE) passports. It is unclear whether other countries or authorities would comply with an arrest warrant issued by Russia. Durov left Russia in 2014 after refusing to comply with government demands to shut down opposition communities on the platform. He had previously founded popular Russian social media company VKontakte - dubbed the "Facebook of Russia." In 2024, Durov was arrested and investigated by the French government in connection with criminal activity on the platform and a lack of cooperation with law enforcement. "He was allowed to go home months later, with the investigation continuing," notes the BBC.

Read more of this story at Slashdot.

  •  

A Missing Underscore Sent Innocent Man To Prison For 18 Months

An anonymous reader quotes a report from Ars Technica: One missing underscore in a Skyrim-themed username put an innocent Nova Scotia man in prison for 18 months. A 2018 child-luring investigation, which began in Madison, Wisconsin, and eventually extended to Halifax, Canada, was based on a false premise. Police were looking for a man using the Kik messaging service under the name "fus__ro_dah" (two underscores after "fus"), but they accidentally requested records for the username "fus_ro_dah" (one underscore after "fus"). This one-character difference led them not to the perpetrator but to a Canadian man named Brandon Klayme. (Ars readers may recognize "fus ro dah" as the Unrelenting Force "dragon shout" from The Elder Scrolls V: Skyrim.) Despite finding no evidence of the crime on his digital devices, Canadian police arrested Klayme in 2020 on child sex abuse charges. He was convicted after a trial in 2023 and sentenced in 2024 to 18 months in prison. He served the full term. Even after release, Klayme continued to fight his conviction. In the process of preparing his appeal, the username mistake that led to all these years of disruption was finally discovered. On Thursday, the Nova Scotia Court of Appeal overturned Klayme's conviction, writing: "Mr. Klayme is factually innocent of the offences. He should never have been charged, let alone convicted." [...] As the court puts it, "Although the information about the usernames was available at the time of the trial, there is no evidence confirming or explaining how it went unnoticed."

Read more of this story at Slashdot.

  •  

Typo-Squatting Scammers Con South Carolina Town Out of $545K

It started with some underground utility work for the South Carolina town of Surfside Beach (population: 4,155). "Public records confirm that a payment of $545,598.30 was issued," according to a local news station — but the CEO of Wildcat Contractors "stated that the account that received the money is a scammer account and that his company has an overdue invoice for underground utility work completed in Surfside Beach." Yahoo picks up the story: After the payment issue surfaced, Wildcat said Surfside Beach sent over the email thread containing the payment confirmation. The company told WMBF it noticed multiple red flags in the chain. One involved an email address where "Wildcat" appeared with an extra "i." Another involved documents that the company said included a forged signature taken from a prior notarized document. Wildcat said the money was sent to a spoofing account claiming to be the contractor. More local reports are unraveling what happened: According to the Wall Street Journal, the town's finance director said a town employee called Wildcat's project manager on March 13, the day the payment was sent. The project manager referred the caller to [Wildcat CEO] Bowker. The town then called Bowker's mobile phone and left a voicemail about the ACH transfer. Bowker told the Wall Street Journal she does not recall the voicemail but acknowledged she may have missed it. Now a new report released by a law firm hired by the town to investigate "shows it did make an attempt to verify before sending $545,000 to a fraudulent bank account," according to local news reports: According to the report, the town sent an email to Wildcat's legitimate email domain on March 13 requesting a callback for verbal verification before sending the payment. Surfside received a response to that email with a phone number, though it remains unclear whether that response came from a real Wildcat employee or from the scammers. The report found that the fake town domain was used in communications between both parties throughout the process, which the law firm overseeing the investigation said was likely created to facilitate the fraud and delay its discovery. That seems to be the case in a nutshell: Investigators determined the fraudsters used spoofed and typo-squatted email domains, including surfsidesbeach.org, to impersonate town officials and redirect the payment. The fraudulent domain was created March 9 and was used to help conceal the scheme, according to investigators. Town officials said they are continuing to work with the FBI, South Carolina Law Enforcement Division, and their insurance partners to recover the funds. "The town has also implemented additional security measures to strengthen payment verification procedures and reduce the risk of similar incidents."

Read more of this story at Slashdot.

  •  
❌