In Treviso

Intimate images stolen from homes, beauty salons and medical practices offered for sale on an online platform

It was discovered by the Treviso-based Yarix, a cybersecurity competence centre of the Var Group company, which reported it to the Postal Police. The price ranged from around USD 20 to USD 575. The investigation started with the case of De Martino

by Rome Editorial Staff

La trevigiana Yarix, centro di competenza per la cybersecurity dell’azienda Var Group, ha segnalato alla Polizia Postale un portale sul “clear web”, facilmente accessibile attraverso i motori di ricerca, con migliaia di registrazioni audiovideo trafugate illecitamente da oltre 2.000 videocamere di sorveglianza all’interno di abitazioni, centri estetici o studi medici

4' min read

4' min read

An investigation into the case of Stefano De Martino, the television presenter who was the victim of an intrusion into the cloud of his own home video surveillance system, gave the 'go-ahead' for the discovery of the platform of stolen intimate images being offered for sale. For the technicians of Yarix, the Treviso-based cybersecurity company of the Var Group, in the last few days there has been a chain of in-depth investigations thanks to which the existence of a portal hosting the stolen images of about 2,000 video surveillance systems, 200 of which in Italy, finally came to light. A search that is still far from being concluded, since, acknowledges the director of the technical team Diego Marson, other platforms active in the same 'business', albeit with a smaller volume of resources, emerged on the same day. The results of the investigation have been handed over to the Venice Postal Police, while it will be up to the Venice District Prosecutor's Office to decide whether and when to deactivate the platforms, which up to this moment are still active, and to formulate the crime hypothesis that best fits the case.

The Portal

.

A portal on the 'clear web', easily accessible through search engines, with thousands of audio-video recordings illicitly stolen from more than 2,000 surveillance cameras inside homes, beauty centres, or medical practices, was discovered by the Treviso-based Yarix, the cybersecurity competence centre of the Var Group company, which reported it to the Postal Police. Active at least since December 2024, the portal allows short extracts of recordings to be viewed free of charge, while also offering the possibility of purchasing access to the camera for further content or to gain control over it. The price for each varies from approximately $20 to $575.

Loading...

The news comes after the scandal of stolen photos of politicians, influencers and actresses, and published on the Phica.eu platform.

Thousands of pornographic audio-video recordings

.

The site - informs a note from Yarix - is easily accessible through the usual search engines, and collects thousands of audio-video recordings, mainly with a pornographic background, illicitly stolen from home surveillance cameras and places such as beauty salons or medical practices. Accessible without the need for registration, it offers pay-as-you-go formulas with fees that vary according to the popularity and number of views of the videos.

Some videos viewed over 20,000 times

.

Via a purpose-built Telegram bot, access to one or more cameras can be purchased. The price varies according to the number and views of public videos; among them, some have been viewed more than 20,000 times. Content can be browsed in the same way as in a normal search bar through tags, which select the content according to the request.

Violated 'supermarket' systems

.

The video cameras exploited by site operators to "steal" intimate videos and feed the stream to the benefit of their subscribers "are partly of the basic type, purchasable in supermarkets or on e-commerce portals, but also more evolved systems of a higher cost," pointed out Diego Marson, head of the Yarix technical team that brought to light the portal with the videos on sale. "The vulnerability, in our opinion," he continued, "is given above all by the use of weak credentials, without double authentication, by the preservation of passwords given by default, and by the failure to update the firmware issued by manufacturers precisely for the purpose of increasing security margins. So, the lack of defence lies mainly in the absence of awareness of the risks taken by users, who are probably almost always also self-installers of their own internal circuits, distributing video cameras even in unwise environments, such as bedrooms or bathrooms'. Simply by applying more 'cyber hygiene' measures, 90% of this leakage of intimate images could have been avoided, according to the Yarix technicians. Surprisingly, these platforms do not belong to the 'dark web' at all, but are normally indexed on the most common search engines. 'Those who found them before us,' concluded Marson, 'evidently had no interest in making this known.

The Tonga Islands Domain

.

The domain of the portal is registered in the Tonga Islands, in the South Pacific, probably motivated by reasons related to the anonymity of the site operator and legal flexibility: in fact, some states do not require rigorous verification of the identity of the purchaser, and often do not have legal cooperation agreements with other states, or have less restrictive laws on privacy and online content. As written in the 'About' section of the site, the aim is to 'draw public attention to the problem of personal data leakage caused by imperfections in hardware and software'. Yarix reported the discovery via the Operational Centre for Cyber Security (Cosc) in Venice to the Veneto Postal Police, with which it has signed a Protocol of Understanding since 2016 and has already collaborated on several investigations. The Cyber Threat Intelligence team is monitoring the portal and conducting further analysis that will be useful in the investigation, which will also establish whether all the videos came from hidden cameras and unwitting victims. The hypothesis that, alongside authentic videos, there are recordings and live broadcasts with actors to attract more users and more paid subscriptions is not ruled out.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti