Feeds

Spamford Wallace charged for hacking 500,000 Facebookers

Forbidden login at 10,000 feet

Secure remote control for conventional and virtual desktops

One of the first figures to plaster the internet with millions of spam messages before being driven underground has been criminally charged for hacking some 500,000 Facebook accounts, stealing their personal information, and sending 27 million unwanted advertisements.

Sanford Wallace, now 43, first figured out a way to evade Facebook's spam filters and then employed a script that automatically logged in to the accounts he had compromised and retrieve a list of all the users' friends, according to an indictment filed Thursday in federal court in San Jose, California. He then allegedly posted junk messages on each of the friends' Facebook wall.

When people clicked on a link in the message, they were directed to a website that phished their name, and account credentials, prosecutors said. He allegedly carried out the scheme in just five months, starting in November 2008.

“Wallace continued his spamming scheme by storing the information provided by Facebook users, such as email addresses and passwords,” the indictment stated. “Wallace then used the user's email address and password to log into Facebook in order to continue to send spam messages.”

The indictment comes almost two years after Facebook was awarded $711m in damages from Wallace after suing him over the alleged scam. He faced a similar lawsuit from MySpace that in 2008 resulted in a $230m judgement. It's doubtful the company has recovered a dime of either judgement.

Wallace surrendered to FBI agents in Las Vegas on Thursday. He made his initial appearance in court a little while later and was released on $100,000 bail. He was ordered not to access Facebook or MySpace.

The indictment charges Wallace with six counts of fraud and two counts of intentional damage to a protected computer. He was also charged with two counts of criminal contempt for logging in to Facebook after the federal judge in the civil action brought by the site ordered him not to. One of the forbidden logins occurred while Wallace was aboard a Virgin Airlines flight from Las Vegas to New York.

If convicted, he faces a maximum of three years in prison and a $250,000 fine for each fraud count and 10 years and a $250,000 fine for each intentional damage count. Penalties for the contempt charges are up to the judge.

A PDF of the indictment is here. ®

New hybrid storage solutions

More from The Register

next story
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
'Speargun' program is fantasy, says cable operator
We just might notice if you cut our cables
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.