Hackers are compromising police and government email accounts to send Emergency Data Requests to ISPs, telecoms, social networks, and others, who quickly comply
Krebs on SecurityBrian Krebs
Context & Ripple Effects
This is the second day running that Krebs on Security has documented the scheme — the paper trails an earlier report on hacked law enforcement emails being used to fire off Emergency Data Requests, which platforms treat as skip-the-paperwork asks and honor quickly. What makes it potent is the inversion: the emergency channel built so police could get subscriber data fast is now the criminals' fastest route to the same data.
It also rhymes with VICE's 2020 reporting on police buying access to hacked data to end-run normal legal process — in both cases the formal warrant path is bypassed, only now the impersonators sit on the other side of the request.
First-order effects
ISPs, telecoms, and social networks receiving these fraudulent Emergency Data Requests hand over subscriber records — locations, account details — directly to criminal actors, because the requests arrive from what looks like a legitimate government address.
Every police department or agency with a compromised mailbox becomes an unwitting data broker until the intrusion is detected.
Second-order effects
Platforms face pressure to add out-of-band verification for emergency requests, which slows down the legitimate law-enforcement use case the fast lane was built for — the trade-off between speed and authenticity lands on compliance teams.
Government agencies become liable for their own email security in a new way: a single phished officer's inbox is now an attack surface against every company that honors official requests.
Third-order effects
If the pattern holds, the informal trust that underpins expedited legal-process channels erodes, pushing the industry toward authenticated, auditable request frameworks rather than email-based ones — a structural shift in how lawful-access requests are verified.
The broader lesson echoes earlier government-infrastructure compromises like the DHS emergency directive on DNS hijacking: state systems themselves are becoming the pivot point for attacks on private-sector data.
The trend: Lawful-access channels are turning from a one-way pipe for government surveillance into a two-way attack surface, as criminals learn to impersonate the requester rather than hack the target.
Crooks are now hacking police, govt email accounts/websites to send fake “emergency data requests” to wireless providers, ISPs, social media firms. The requests claim it's a matter of life & death, can't wait for subpoena. The compliance rate is high. https://krebsonsecurity.com/…
LAPUS$'s methods were a mystery, but now @briankrebs sheds light on how the gang pulled it off: they impersonated cops, issuing EDRs to service providers, who *just handed over data* they used to break into agencies, companies, and personal accounts. https://krebsonsecurity.com/ …
Have you been following the LAPSUS$ story? Krebs has EXTREMELY thorough coverage including several new scoops. For example, the EDR TTP was news to me! https://krebsonsecurity.com/ ... https://twitter.com/...
If I was the sort of person who wrote cyberpunk dystopias, I would include teenagers compromising LE-related email accounts to send out emergency requests for PII to tech companies: https://krebsonsecurity.com/ ...
Here is also a case where a scammer created a fake domain for a law enforcement task force to trick a telecom into providing location data without a warrant: https://www.vice.com/... https://twitter.com/...
2016: Season 2 of Mr. Robot has Elliot looking up “US mobile exigent circumstance” to impersonate law enforcement and get real time location of mobile phone https://www.youtube.com/... 2022: 14 year olds are using same method to hack, dox, harass, swat people https://krebsonsecur…
This is why many of us have been against any kind of special access/rights for law enforcement since Clipper. Yes it makes the job harder, but the trade off is worth it. https://twitter.com/...
Mind boggling story. If you want private data just register a fake US police domain and send a request a request from him, as there's tens of thousands of US police departments and no standardised process. https://twitter.com/...