So, this post has been a long time in the making, but after receiving the OK from Chedburn, here it goes.
Between 2017 and 2018, some of you may remember Torn was being hit with DDoS attacks constantly. You may remember some of the announcements:
https://www.torn.com/forums.php#/p=threads&f=1&t=16046850&b=0&a=0
https://www.torn.com/forums.php#/p=threads&f=1&t=16039600&b=0&a=0
Now I work in cybersecurity, so I know how petty but damaging these can be, so I wondered what I could do about it. During one attack in particular, somebody sent me an interesting Pastebin, containing a chat from a username which was purportedly the attacker, so I decided to dig deeper.
Here is the original Pastebin: https://pastebin.com/LMKj1dj7
Using the alias, I found a variety of Torn accounts, and accounts on the internet, all matching the original name of "Mezy" or variants of it. Also with that, I was able to locate his full name, date of birth, phone number, home address, names of relatives, social media accounts and more (I even found a whole bunch of unflattering pictures of him which have since been removed). FYI much of this information has been removed for various reasons since lots of the websites involved were taken down by police.
Some of his Torn Accounts:
https://www.torn.com/profiles.php?XID=2118604
https://www.torn.com/profiles.php?XID=2145649
https://www.torn.com/profiles.php?XID=2118584
https://www.torn.com/profiles.php?XID=2151999
https://www.torn.com/profiles.php?XID=2151997
https://www.torn.com/profiles.php?XID=2136835
As part of the findings, it appeared he also ran a website called stress.wtf - offering "booting" services. For those unfamiliar, a "booter" is when somebody offers a DDOS-for-hire service in exchange for (usually stolen) money or cryptocurrency. I had some pretty solid connections to show it was him running it or at least heavily involved.
Sensing an easy win, I forwarded my findings to Chedburn. We had several conversations in verifying the data, but also guided him through the process of getting it reported to the correct UK government agency for the police to take action, since not all police forces really know how to handle cybercrime reports like a DDOS.
Fast forward a few weeks to September 2018, our guy is arrested. I'll quote the email Ched sent me, but it was safe to say my information on him was spot on:
Hi {my real name},
So thanks to the information you provided and that reporting link you gave me...
Our DDoS attacker was picked up by the police yesterday for an interview.
- 15 years old
- Mother attended (was shocked and didn't know as expected)
- He is the sole owner of the website stress.wtf, it's being shut down
- Was completely open and provided read access to the police
- Obviously very apologetic now that he's been caught
- He had also attacked other sites, including law and financial institutions
- Prosecution very likely
Thanks again.
Surprise surprise, the attacks stopped, and Ched posted this: https://www.torn.com/forums.php#/p=threads&f=1&t=16061308&b=0&a=0
And then fast forward a few more weeks to October 2018, some quotes from the detectives investigating when providing a summary to Ched:
>In summary, the 3000+ User DDoS collective have been greatly disrupted and have abandoned the Stresser and its social media platforms from which attacks were launched.
>the matter has snowballed the investigation into the detection of literally hundreds of crimes worldwide. Thank you for your engagement once again.
>DDoS attacks have been confirmed from this group on multiple law enforcement sites, Justice Depts, Servers, financial institutions, even PPV boxing events! Moreover, a network involving credit card fraud has also been exposed.
>We are branching out in respect of suspects and have 50+ nominals confirmed as buying the stresser globally
>In respect of our Suspect, the attacks on Torn were the tip of the iceberg, the volume of activity has been incredible, particularly the credit card fraud element.
> the volume is unprecedented.
Nominals in police work is a way of saying people/suspects. So yeah, 50 people involved were identified.
Now some of this was a surprise of course, but being quite used to working in cybercrime areas, it wasn't shocking really. Often, people paying for these "booter" services use stolen credit cards bought online. Nevertheless, it was good to see the matter was being taken seriously.
Thanks to a variety of factors, such as the UK court system being painfully slow to prosecute and Covid-19, it took a long time to move further with this. However, in January 2023, "Mezy" finally pleaded guilty to 19 offences and received a 20 month suspended prison sentence. There were plenty of news articles covering this since it also impacted several pay-per-view streams of high profile people and some mentioned Torn too, but I won't link to them here.
A little opinion here - this isn't to demonize somebody. He was a 15 year old kid at the time, who made some very stupid mistakes, but it shouldn't define him going forward. I really hope he can move on and put his skills to legitimate use. I hope nobody in the community gives him a hard time for that. That being said, if anyone gets a feel for doing something similar, these are crimes, and they will be investigated. There is always somebody smarter than you, and you only need to make 1 mistake to get caught.
I speak from personal experience. Many years ago when I was a teenager I was like this kid. I used my skills for questionable purposes. Now yes I never started DDOSing people or started a fraud ring and had the police get involved because of it, but I did do some things for the kudos. The thing to keep in mind is that the internet doesn't forget - long after that kudos fades away and you stop talking to those people (because you will outgrow it), those news articles will linger and impact everything like your jobs, your future kids will see it, your family will be disappointed in what you've done and you could end up with a criminal record. Just don't do it.