• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Intelbroker now claims it hacked Apple

winjer

Member

Intelbroker is gaining a reputation for breaching some big-name entities. After it hacked AMD, the group now says it has also compromised Apple. However, it is difficult to verify these claims, and Apple has yet to respond. This is what we know so far.

Notorious cybercriminal Intelbroker has made another eyebrow-raising claim on dark web forum BreachForums following its report of breaking into AMD last week. A day later, the group said it also compromised Apple, stealing its source code for internal tools, including AppleConnect-SSO, Apple-HWE-Confluence-Advanced, and AppleMacroPlugin, as well as employees' personally identifiable information and other data.

AppleConnect-SSO is an authentication system that allows employees to access specific applications within Apple's network. An ex-Apple retail employee told 9to5Mac that AppleConnect serves as the employee equivalent of an Apple ID and is used to access all internal systems, with the exception of email. Not much is known about the other two tools, but it is speculated that Apple-HWE-Confluence-Advanced is likely used for internal information sharing, and AppleMacroPlugin facilitates internal processes.

Apple has not confirmed the breach, and AMD said that it is working closely with law enforcement officials and a third-party hosting partner to investigate the claim and the significance of the data. Intelbroker posted screenshots from AMD's internal systems to prove it has the data.

More information comes from security vendor AHCTS, which claims that its Intelligence team purchased the data for the USD equivalent of approximately $11. It also says that the leaked data does not include internal Apple tools, but instead contains internal custom integrations to connect Apple proprietary authentication systems to Atlassian Jira and Confluence, for SSO authentication within the Apple corporate network. "Based on information contained within the leaked data, the source code handles the authentication to retail-confluence.apple.com, a Confluence server which is not routable on the public internet," it said.

There have been previous cases of cybercriminal gangs making false claims about infiltrating big organizations and having stolen data to sell. The AMD and Apple breaches, though, do appear they could be genuine, though there is no way to know for sure. Besides the sightings of the stolen data on the dark web, Intelbroker itself is gaining a reputation for its cybertheft exploits. It has previously claimed to have breached the Los Angeles International Airport to access personal and flight details. It also broke into US federal technology consulting firm Acuity, compromising federal agencies, and Shoprite, Africa's largest retailer. Intelbroker has also tried to sell data allegedly stolen from Europol, The Home Depot (via a third-party vendor), and health insurance marketplace DC Health Link.



Dj Khaled GIF by Music Choice
 

T8SC

Member
The authentication information & admin creds are all for systems based on the Apple corporate network and most likely not even in use anymore due to the age of the systems the leaked plugins are designed for; 2011-2015.

So basically, a lot of nothing.
 
Last edited:
Top Bottom