Hacker legislation begins to take effect
Just a couple of years ago, none of the Internet users could even imagine that you could be put on trial for certain actions on the Internet. Novice networkers smiled and frightened each other with the fate of the famous hacker Levin. But Internet technologies are developing by leaps and bounds, and with them the level of skill and demands of “young” hackers are growing. The secret services are not far behind the criminals. Recent arrests of Internet fraudsters in Russia have given rise to a lot of rumors about a certain Directorate “R”, which was specially created to control the Russian segment of the Internet. Read below about the work of the most mysterious of all departments of the Ministry of Internal Affairs from the words of the deputy head of the first Russian Directorate for Combating Crimes in the Field of High Technologies of the Ministry of Internal Affairs of the Russian Federation, Colonel Konstantin Machabeli .
The development of e-commerce, shops and supermarkets has attracted enormous interest from the criminal world. Crimes carried out using the Internet have become a reality. Although it all started with quite harmless things - orders of goods and services using other people's credit cards. At first, kids aged 13 to 20 ordered T-shirts and CDs to their homes. Over time, appetites grew and hobbies grew into real professional crime. Russian operational services are faced with the problem of identifying and proving this type of crime. About a year ago, in order to counter virtual villains, the Directorate “R” (UBPSVT - Directorate for Combating Crimes in the Sphere of High Technologies) was created under the Russian Ministry of Internal Affairs.
The work of this department has its own specifics, because the actions of the criminals are not obvious - no one came, broke into the safe or stole something, leaving traces. Everything happens virtually. When the crimes just started and the relevant articles of the Criminal Code were prescribed, no one knew how to work on them. But there is a “prospect” in this, since the interest of the criminal world in the information stored in computers is very great. With every criminal case in the field of computer communications brought to an end, this type of crime becomes quite real for judicial and investigative practice. Information about crimes comes to the Department in different ways. "Erovtsy" have the status of a subject of full-cycle operational investigative activities, like, for example, the famous Organized Crime Control Department. Therefore, all means of obtaining operational information are used to identify and detain criminals. The department clearly understands the algorithm of criminal actions they work with, which allows them to achieve good results.
The employees of Directorate "R" already have something to be proud of; there are already real cases that have been solved and brought to court. For example, some time ago, FSB materials were implemented regarding Bulgarian suppliers of audio and video products. People have already been convicted in this case, although it has not been possible to completely stop the existence of supply channels for pirated products.
The so-called Gazprom case was widely covered in the media. In this case, the criminal act was classified under three articles. Now the Gazprom case is being investigated by the Prosecutor General's Office against a group of individuals who unlawfully penetrated the Gazprom network, distributed malware there and thus caused property damage. Gazprom's technical security service is at a very high level, and without their assistance and active work the criminals would hardly have been identified. An operation was carried out in which a decoy computer was placed in such a way as to imitate the computer of the Gazprom company network. That is, the car was virtually in Gazprom, and physically in the “R” Directorate. There could be no talk of any control of gas flows through a computer network. The criminals just wanted to get some information, but now they are under investigation.
The "P" department also deals with so-called "Trojan" programs, when they send some program to your email address and thus try to take over your login password for accessing the Internet. Some groups make this practice a permanent professional practice in order to further sell these passwords. The price of login passwords ranges from 1 to 30 dollars. To date, several dozen similar crimes have been solved.
Pirates of cellular networks are also the area of activity of Directorate "R". There are cases where a person receives a large telephone bill for supposedly long calls with Vietnam or Thailand. Another area of the department’s work is the fight against the use of Panasonic cordless phones, which are not certified and operate on the frequencies of the Ministry of Internal Affairs. The department is closely involved in the elimination of negotiation points that are formed in the places where foreign students live. That is, there is plenty of work in management, and over time its volume will only grow.
It is impossible not to mention the latest high-profile case, which was solved thanks to the work of the employees of Directorate “R”. As a result of an operational development to suppress a group of so-called hackers, although it would be more accurate to say scammers, five “burglars” were arrested.
In December 1999, a certain Levitin created a group whose goal was to steal other people's property through deception using the Internet. On December 8, Levitin's group opened an electronic store "Polit-shop", the website of which contained advertisements for the provision of a number of services. After this, Levitin entered into agreements with a commercial bank for settlement services for this store. By hacking the servers of other electronic stores, Levitin's friends obtained information about credit card holders and made purchases in Levitin's store on their behalf. All operations were carried out via the Internet provided by Moscow providers. The proceeds, passing through several commercial banks, were cashed and distributed among members of the criminal group.
In total, from December 1999 to April 2000, Levitin and his “comrades” stole more than 18 million rubles from the accounts of over five and a half thousand cardholders. As a result of the operation on April 27, all the criminals were arrested, and a criminal case was opened under Part 3 of Article 159 “Taking possession of someone else’s property by fraud as part of an organized group.” It is this case that gives reason to believe that Russian special services have begun to seriously engage in Internet technologies and, accordingly, Internet crimes.
Divisions similar to Directorate "R" exist not only in Moscow, but also in almost all constituent entities of the Russian Federation. With the exception of the Yamalo-Nenets or Koryak Autonomous Okrug, where there are practically no computers. There are also successes in the regions - the first criminal case was recently opened against the creator of a computer virus. The Department of the Federal Security Service for the Kirov Region detained an employee of the information systems department of one of the companies in the regional center. He created a program that caused computers and local computer networks to malfunction. According to the data received, the criminal installed the program on his company’s server, and every visitor became infected with the virus. This was also a precedent, because before that no one had been brought to criminal liability for writing viruses, since it is very difficult to accurately establish the authorship of a virus program. There was another case in the Sverdlovsk region, but there it was only about responsibility for the spread of viruses.
As an exchange of experience, and not only, Russian specialists cooperate with their foreign colleagues. Specialists from Directorate “R” have 24-hour contact with similar services in Western countries. There, such crimes have become commonplace for a long time, and the Russian “Erovites” are consulting with specialists from the USA, England, and France through the so-called “national contact point.” Every day, Department "R" receives requests and operational information from law enforcement agencies of the G8 countries and beyond. They are associated with unauthorized access to porn sites, the distribution of child pornography, etc. Of course, in management they meet their colleagues halfway and help them, check their information and stop violations.
There are also closer contacts - at the end of last year, colleagues from the United States held seminars in Moscow and St. Petersburg. I don’t want to belittle the dignity of foreign computer scientists, but, according to sources in the Ministry of Internal Affairs who were present at these meetings, “their” questions are not comparable to “ours.” Americans are “obsessed” with child pornography on websites, but they steal from us under a million dollars. As for technical education, the same sources in the Ministry of Internal Affairs stated with full responsibility that the level of our employees does not lag behind and sometimes even exceeds the level of their Western European colleagues.
As for the actual popularity of hacking as an activity, many may think that management employees “have a grudge” against magazines like “Hacker,” which seem to contribute to the spread and popularization of illegal access to information. But, according to the employees of the "R" Department, they work closely with this magazine and often communicate with publishers. The fact is that the main message of Directorate "R" is: "A hacker is not a criminal." The department believes that a hacker is one of the trends in youth culture, just like rockers, metalheads, and nudists used to be. Then, about ten years ago, a detachment was created at the Central Internal Affairs Directorate, which was designed not to force hackers into a bottle, but to understand them. Then these movements entered a certain direction. Some people engage in hacking for sport, others for self-affirmation, and others for material gain. The department views this favorably as long as the hackers' actions do not cross the line of law. It is impossible to equate a hacker with a criminal.
If we talk about punishment for various atrocities on the Internet, then, for example, a simple hacking of a site does not amount to “extracting material benefits,” but falls under the term “modification,” that is, changing information that is protected by law. The Criminal Code stipulates many things. A hacker is a law-abiding citizen of a country until he comes into contact with the country's criminal code.
Many young fans of computer “hacking” often do not fully understand how severe the punishment they may face. Although the “hacking” law in Russia is still quite humane. People who first come to the attention of law enforcement agencies under these articles are brought to criminal liability at the final stage, still conditionally. For committing crimes that do not involve major material damage, for the first time or not as part of an organized group, the hacker faces a maximum of 3 years. Mostly, the people charged today are young people, students. Taking into account all mitigating circumstances, they receive suspended sentences.
Of course, there are cases when criminals received up to 5 years in prison for purposefully stealing goods using someone else’s credit cards. But this has already been interpreted by articles about fraud. Pure hacking can result in a maximum sentence of 7 years. Fraud - maximum 10 years. So, everyone who does not deny themselves the pleasure of “hacking” someone’s site for sports or for some other reason of interest now still needs to think carefully. Judging by the actions of Directorate “R”, the Internet spaces have ceased to be a “free” zone in our country.
"Hacker" articles of the Criminal Code
Chapter 28. Crimes in the field of computer information
Article 272. Illegal access to computer information
1. Unlawful access to computer information protected by law, that is, information on computer media, in an electronic computer (computer), computer system or their network, if this act entailed the destruction, blocking, modification or copying of information, disruption of the operation of the computer, system Computers or their networks, is punishable by a fine in the amount of two hundred to five hundred times the minimum wage, or in the amount of wages or one income of the convicted person for a period of two to five months, or by correctional labor for a term of six months to one year, or by imprisonment for up to two years.
2. The same act, committed by a group of persons by prior conspiracy or by an organized group or by a person using his official position, as well as having access to a computer, a computer system or their network, is punishable by a fine in the amount of five hundred to eight hundred times the minimum wage or the amount of wages or other income of the convicted person for a period of five to eight months, or correctional labor for a term of one to two years, or arrest for a term of three to six months, or imprisonment for a term of up to five years.
Article 273. Creation, use and distribution of malicious computer programs
1. Creating computer programs or making changes to existing programs, knowingly leading to unauthorized destruction, blocking, modification or copying of information, disruption of the operation of a computer, computer system or their network, as well as the use or distribution of such programs or computer media with such programs is punishable imprisonment for a term of up to three years with a fine in the amount of two hundred to five hundred times the minimum wage or in the amount of wages or other income of the convicted person for a period of two to five months.
2. The same acts, which through negligence entailed grave consequences, are punishable by imprisonment for a term of three to seven years.
Article 274. Violation of the rules for operating computers, computer systems or their networks
1. Violation of the rules for operating a computer, a computer system or their network by a person who has access to a computer, a computer system or their network, resulting in the destruction, blocking or modification of legally protected computer information, if this act caused significant harm, is punishable by deprivation of the right to hold certain positions or engage in certain activities for a period of up to five years, or compulsory work for a period of one hundred eighty to two hundred and forty hours, or restriction of freedom for a period of up to two years.
2. The same act, which has caused grave consequences through negligence, is punishable by imprisonment for up to four years.