© 2025 Connecticut Public

FCC Public Inspection Files:
WEDH · WEDN · WEDW · WEDY
WEDW-FM · WNPR · WPKT · WRLI-FM
Public Files Contact · ATSC 3.0 FAQ
Play Live Radio
Next Up:
0:00
0:00
0:00 0:00
Available On Air Stations

Dark Basin: Global Hack-For-Hire Organization That Targeted Thousands Over The Years

MARY LOUISE KELLY, HOST:

We're all familiar with email scams, phishing, attempts to steal passwords. We know less about who's behind them. We learned today, federal prosecutors are looking into a global hack-for-hire organization. It has targeted journalists, activists and government officials and thousands of others. Here's NPR's Hanna Rosin.

HANNA ROSIN, BYLINE: Like most stealth operations, this one has a code name, Dark Basin. And it started with a tip.

JOHN SCOTT-RAILTON: A journalist got in touch with us and shared some suspicious messages.

ROSIN: That's John Scott-Railton, a researcher with Citizen Lab, a cybersecurity watchdog group. In a report released today, Citizen Lab tracked those messages back to a group based in India.

SCOTT-RAILTON: A sprawling operation that has hundreds of clients around the world who seem to pay these people to target hundreds and thousands of people at a time.

ROSIN: Among the targets were environmental activists who were involved with a campaign called #ExxonKnew. These activists have accused the oil company of keeping the public and shareholders in the dark about climate damage they knew they were causing. Kert Davies of the Climate Investigations Center was one of the activists who were targeted.

KERT DAVIES: Out of the blue, you start getting these freaky emails, and you think, what - you know, who's behind it? The story is not this company in India. The story is who hires them.

ROSIN: A spokesman for Exxon Mobil said the company has no knowledge of or involvement in the hacking activities outlined in Citizen Lab's report. And as Scott-Railton put it, it is in fact devilishly difficult to connect the hackers directly with the people who use their services. It's all done through middlemen. And federal prosecutors have arrested one middleman. An Israeli private investigator named Aviram Azari was charged in New York with wire fraud, identity theft and conspiracy to commit computer hacking. The indictment said he'd been invited to India to meet with senior managers of the hacking group. He's pleaded not guilty.

Citizen Lab has started to connect those dots, and Scott-Railton says they're sharing their information with federal investigators.

SCOTT-RAILTON: The people who were targeted were often on the other side of some kind of a pitched battle, maybe with a company, maybe with an individual.

ROSIN: Perhaps the scariest cases involve individuals, like a man named Matthew Earl, who woke up one morning three years ago to a document online supposedly written by a former employee of his.

MATTHEW EARL: I mean, it was accusing me of being a criminal.

ROSIN: Earl knew it was all fiction. He had no former employees. But still, it affected him.

EARL: I felt shame that that's the impression that people would see.

ROSIN: Scott-Railton described Earl to me as the most targeted man he's ever met. Earl had PIs come to his door, he was followed and photographed on the street, and for years, Earl received phishing emails, which if he fell for the trap, would have allowed the hackers to harvest his passwords and wreak havoc on his life.

EARL: Because you're paranoid of clicking on anything, and so you kind of retrench a bit from life.

ROSIN: The Citizen Lab report connects Earl's case to a number of other journalists and investors. What they had in common was publishing damaging information about a German company called Wirecard. This week, police in Munich raided Wirecard's headquarters, and German prosecutors launched a criminal investigation into accounting irregularities and disclosure violations by certain executive board members of Wirecard.

As for Matthew Earl, as of last week, he was still getting suspicious emails, so he was happy to hear from Scott-Railton that Citizen Lab had at least honed in on his hackers, if not yet the people who hired them.

SCOTT-RAILTON: It'll be nice to have a little celebratory victory lap tomorrow or the next day.

EARL: Well, we could get a drink organized on Zoom or something (laughter).

SCOTT-RAILTON: Oh, yeah.

ROSIN: Now it's up to the prosecutors in the U.S. and Germany to do the difficult work of finding out definitively who the corporate clients are.

Hanna Rosin, NPR News.

(SOUNDBITE OF MUSIC) Transcript provided by NPR, Copyright NPR.

NPR transcripts are created on a rush deadline by an NPR contractor. This text may not be in its final form and may be updated or revised in the future. Accuracy and availability may vary. The authoritative record of NPR’s programming is the audio record.

Along with Alix Spiegel, Hanna Rosin co-hosts Invisibilia, a show from NPR about the unseen forces that control human behavior—our ideas, beliefs, assumptions, and thoughts. Invisibilia interweaves personal stories with the latest human behavior and brain science, in a way that ultimately makes you see your own life differently. The show was nominated for a Peabody Award in 2015. Rosin's stories have won a Gracie Award and a Jackson Hole Science Media Award. Excerpts of the show are featured on the NPR News programs Morning Edition and All Things Considered. The program is available as a podcast.

The independent journalism and non-commercial programming you rely on every day is in danger.

If you’re reading this, you believe in trusted journalism and in learning without paywalls. You value access to educational content kids love and enriching cultural programming.

Now all of that is at risk.

Federal funding for public media is under threat and if it goes, the impact to our communities will be devastating.

Together, we can defend it. It’s time to protect what matters.

Your voice has protected public media before. Now, it’s needed again. Learn how you can protect the news and programming you depend on.

SOMOS CONNECTICUT is an initiative from Connecticut Public, the state’s local NPR and PBS station, to elevate Latino stories and expand programming that uplifts and informs our Latino communities. Visit CTPublic.org/latino for more stories and resources. For updates, sign up for the SOMOS CONNECTICUT newsletter at ctpublic.org/newsletters.

SOMOS CONNECTICUT es una iniciativa de Connecticut Public, la emisora local de NPR y PBS del estado, que busca elevar nuestras historias latinas y expandir programación que alza y informa nuestras comunidades latinas locales. Visita CTPublic.org/latino para más reportajes y recursos. Para noticias, suscríbase a nuestro boletín informativo en ctpublic.org/newsletters.

The independent journalism and non-commercial programming you rely on every day is in danger.

If you’re reading this, you believe in trusted journalism and in learning without paywalls. You value access to educational content kids love and enriching cultural programming.

Now all of that is at risk.

Federal funding for public media is under threat and if it goes, the impact to our communities will be devastating.

Together, we can defend it. It’s time to protect what matters.

Your voice has protected public media before. Now, it’s needed again. Learn how you can protect the news and programming you depend on.