Hackers are increasingly using hacked law enforcement emails to send Emergency Data Requests to ISPs, telecoms, social networks, and others, who quickly comply
There is a terrifying and highly effective “method” that criminal hackers are now using to harvest sensitive customer data … Tweets: @briankrebs , @rayredacted , @michaelguimarin , @elizabeth_joh , @villi , and @gossithedog Tweets: @briankrebs : Crooks are now hacking police, govt email accounts/websites to send fake “emergency data requests” to wireless providers, ISPs, social media firms. The requests claim it's a matter of life & death, can't wait for subpoena. The compliance rate is high. https://krebsonsecurity.com/ ... @rayredacted : Have you been following the LAPSUS$ story? Krebs has EXTREMELY thorough coverage including several new scoops. For example, the EDR TTP was news to me! https://krebsonsecurity.com/ ... https://twitter.com/... Michael Guimarin / @michaelguimarin : This is why many of us have been against any kind of special access/rights for law enforcement since Clipper. Yes it makes the job harder, but the trade off is worth it. https://twitter.com/... Elizabeth Joh / @elizabeth_joh : very big problem— https://twitter.com/... @villi : This is wild. Scary. https://twitter.com/... Kevin Beaumont / @gossithedog : Mind boggling story. If you want private data just register a fake US police domain and send a request a request from him, as there's tens of thousands of US police departments and no standardised process. https://twitter.com/...
Context & Ripple Effects
Krebs on Security's report lands on top of an established pattern: police have already been buying access to hacked data — passwords, IP addresses — as an end-run around normal legal process, and companies handling user data under GDPR and CCPA were flagged back in 2020 for insecure verification practices when handing it over. What is new here is direction reversal: instead of police exploiting weak corporate controls, criminals are exploiting police identity itself, sending fraudulent Emergency Data Requests from compromised law enforcement email accounts.
First-order effects
- ISPs, telecoms, and social networks are handing over sensitive customer records in response to forged life-or-death requests sent from hacked police and government mailboxes, because their fast-track compliance path assumes sender authenticity.
- Customers of those providers — including targets of harassment and doxxing campaigns — have their location and account details exposed without any warrant, subpoena, or notice.
Second-order effects
- Providers now face pressure to add out-of-band callback verification for emergency requests, slowing down genuine law-enforcement workflows that were built for speed.
- The same communities tied to this technique — Krebs later traced activity by members of The Com, the online circle linked to Scattered Spider — gain a reusable playbook that scales across every provider with an expedited-request channel.
Third-order effects
- If forged-official requests keep working, the informal trust placed in government email domains collapses as an authentication mechanism, pushing regulators and platforms toward formalized, independently verifiable request channels — a structural fix to the same verification gap identified in corporate privacy compliance years earlier.
The trend: Law-enforcement data-access channels built on trust in official identity are being inverted by criminal hackers, forcing a shift toward cryptographically verifiable government requests.