From Doxing to Doorstep: Exposing Privacy Intrusion Techniques used by Hackers for Extortion

Unknown

Black Hat USA 2024 · Day 1 · Briefing

Overview

In a stark presentation at Black Hat USA, Jacob Larson unveiled the chilling evolution of doxing, demonstrating how online privacy intrusions have escalated from digital harassment to severe real-world threats, including physical violence and extortion. Titled "From Doxing to Doorstep," Larson, an offensive security team lead by day and a threat researcher by night, shared deeply personal insights stemming from his own experience as a doxing victim nine years prior. His unique research methodology involved conducting direct interviews with notorious hackers, including a wanted individual who breached a US Drug Enforcement Agency (DEA) data portal and an administrator of the infamous doxing platform, Doxbin.

Watch on YouTube

Visual summary for From Doxing to Doorstep: Exposing Privacy Intrusion Techniques used by Hackers for Extortion by Unknown
Visual summary for From Doxing to Doorstep: Exposing Privacy Intrusion Techniques used by Hackers for Extortion by Unknown

Key moments

  1. 0:00 Speaker's personal doxing experience and research motivation
  2. 2:10 Vile gang's DEA portal breach for doxing and extortion
  3. 3:30 How Doxbin enables anonymous doxing and extortion
  4. 4:30 Interviewing Vile gang member "Ego" for insights
  5. 6:00 Physical intimidation and real-world violence in doxing
  6. 7:00 Accessing exclusive interview transcripts via QR code
  7. 8:00 Secure alternatives to SMS-based multi-factor authentication

From Doxing to Doorstep: Exposing Privacy Intrusion Techniques used by Hackers for Extortion

Speakers: Jacob Larson, Offensive Security Team Lead, Cyx

Conference: Black Hat USA

YouTube: https://www.youtube.com/watch?v=sg3CpRQdBek

Overview

In a stark presentation at Black Hat USA, Jacob Larson unveiled the chilling evolution of doxing, demonstrating how online privacy intrusions have escalated from digital harassment to severe real-world threats, including physical violence and extortion. Titled "From Doxing to Doorstep," Larson, an offensive security team lead by day and a threat researcher by night, shared deeply personal insights stemming from his own experience as a doxing victim nine years prior. His unique research methodology involved conducting direct interviews with notorious hackers, including a wanted individual who breached a US Drug Enforcement Agency (DEA) data portal and an administrator of the infamous doxing platform, Doxbin.

This talk meticulously dissects the sophisticated techniques employed by cybercriminals to acquire, weaponize, and monetize personal information. Larson’s research exposes the intricate ecosystem of doxing gangs like "Vile" and platforms that facilitate the permanent publication of sensitive data, illustrating how these elements combine to create a pervasive threat landscape. The presentation not only sheds light on the grave privacy implications but also provides actionable advice for individuals to safeguard their digital and physical safety, while simultaneously highlighting critical gaps in current legal frameworks that inadvertently enable these illicit activities to flourish.

Background

▶ Watch: Speaker's personal doxing experience and research motivation (0:00)

The term doxing, a portmanteau of "dropping documents," refers to the act of publishing an individual's private or identifying information online without their consent. This sensitive data, often linked to an online username or alias, can include real names, residential addresses, phone numbers, email addresses, and even details about property or vehicles. Jacob Larson's personal connection to this phenomenon began nine years ago when he became a victim of doxing himself. His personal information was released on a website where he was powerless to have it removed, leading to a violation of his privacy, threats to his safety, and demands for extortion. This harrowing experience, triggered by hackers seeking to acquire a rare online username he possessed, ignited his long-standing interest and research into the doxing subculture.

Larson’s research gained significant momentum in March 2023 when two members of a notorious doxing gang named Vile were charged by the Department of Homeland Security (DHS). Vile had achieved infamy for breaching a critical DEA web portal, an incident that served as a potent example of how deeply adversaries could penetrate government systems to acquire vast quantities of personal data. This portal granted them the ability to query 16 different US federal law enforcement databases, allowing them to retrieve comprehensive personal identifiable information (PII) such as full names, residential addresses, email addresses, mobile numbers, property ownership details, vehicle registrations, and licenses for virtually anyone. The affidavit related to the Vile charges explicitly stated that the group leveraged this compromised access to threaten victims with the public release of their PII unless extortion demands were met, mirroring Larson's own past ordeal.

A critical component of this threat model is the persistence of published information. Unlike typical online harassment that might fade with time, doxing thrives on platforms designed for permanence. Larson highlighted Doxbin as a prime example, a website that prides itself on its unwavering commitment to not remove published doxes. As per its own website, Doxbin states, "If your information goes up, it's not coming down unless it breaks our terms of service," a policy that instills significant fear in victims. Doxbin has grown into the largest doxing community online, boasting over 300,000 users and 165,000 published doxes.

Doxbin was founded in 2018 by two threat actors known as KT and Brenton. Notably, KT is also identified as one of the five core members of the Vile doxing gang, alongside Ego, Kane, Weep, and Convict. While Weep and Convict were apprehended by authorities in 2023, KT, Ego, and Kane remain wanted for their involvement. Larson's research provided an unprecedented look into Vile's operations through his personal interview with Ego, a member who had not been apprehended. Ego, who started his illicit activities in the Xbox Live internet service provider (ISP) doxing scene by finding IP addresses to launch denial-of-service attacks and extort players, later joined Doxbin and ascended to a high-ranking "click" role, signifying his close ties to the platform's owner. This background underscores the progression of skills and the interconnectedness between various facets of the cybercrime underground.

Key Findings

▶ Watch: How Doxbin enables anonymous doxing and extortion (3:30)

The talk revealed several critical findings that underscore the escalating and multifaceted nature of doxing and privacy intrusion:

  1. Escalation to Physical Violence: Perhaps the most alarming finding is the progression of doxing from purely online harassment to tangible, severe physical threats. Larson presented evidence, corroborated by his interview with Vile member Ego, that doxing gangs are not only threatening but actively purchasing physical intimidation services. These services, described chillingly by Ego, can involve breaking into residences, torturing individuals (including "cutting their fingers off"), and even murder, often with the objective of extorting cryptocurrencies. This shatters the common misconception that online threats remain confined to the digital realm.
  1. Sophisticated PII Acquisition: The breach of the DEA web portal by the Vile gang exemplifies a highly sophisticated capability for acquiring extensive PII. Access to 16 different US federal law enforcement databases allowed them to gather a comprehensive dossier on individuals, including residential addresses, mobile numbers, property ownership, and vehicle details. This demonstrates that adversaries possess the means to obtain data far beyond what is typically available through public records, forming a powerful basis for targeted extortion.
  1. Doxbin's Role as an Extortion Enabler: Doxbin's "private doxes" feature emerged as a key mechanism for extortion. Adversaries can upload a victim's sensitive information, receive a private link, and then use this link to threaten the victim with public exposure to Doxbin's 300,000 users and its community of 165,000 published doxes. This functionality provides a potent leverage point for demanding payment, as victims face the terrifying prospect of permanent, widespread dissemination of their private lives.
  1. Organized Cybercrime Ecosystem: The interconnectedness between the Vile gang and Doxbin, with KT being a member of both, highlights the organized and collaborative nature of this cybercrime ecosystem. The progression of Ego's skills, from Xbox Live ISP doxing to high-level involvement in Vile and Doxbin, illustrates a clear career path within these illicit communities, where individuals develop and apply increasingly sophisticated techniques.
  1. Unique Research Access: Larson's ability to conduct interviews with active and wanted hackers, including a Vile member (Ego) and a Doxbin administrator, provided unparalleled insights into the motivations, techniques, and internal workings of these groups. This direct engagement offered a rare glimpse into the adversary's perspective, moving beyond speculative analysis to concrete, first-hand accounts of their operations and the severity of their actions.
  1. Gaps in Legal and Defensive Frameworks: The talk implicitly and explicitly pointed to significant gaps. The persistence of doxes on platforms like Doxbin, despite their severe impact, highlights the inadequacy of current legal frameworks for information removal. Furthermore, common defensive advice often fails to address the unique challenges posed by doxing, particularly when it escalates to physical threats.

Technical Deep Dive

▶ Watch: Interviewing Vile gang member "Ego" for insights (4:30)

The technical underpinnings of doxing, as exposed by Jacob Larson, illustrate a progression from rudimentary online harassment to sophisticated data acquisition and weaponization. Understanding these techniques is crucial for comprehending the full scope of the threat.

1. Initial Information Gathering (Xbox Live ISP Doxing):

Vile member Ego's origin story provides insight into foundational doxing techniques. In the Xbox Live ISP Doxing scene, younger threat actors would employ methods to resolve the IP address of other players. This often involved exploiting vulnerabilities in networking protocols, using network sniffers, or leveraging social engineering tactics to trick targets into revealing their IP addresses. Once an IP address was obtained, attackers would launch Distributed Denial of Service (DDoS) or Denial of Service (DoS) attacks against the target's home internet connection, effectively "hitting them off" Xbox Live. This disruption served as leverage for extortion, demanding money in exchange for ceasing the attacks. While seemingly simple, this technique established a pattern of identifying targets, acquiring sensitive network information, and weaponizing it for financial gain.

2. Advanced PII Acquisition (DEA Web Portal Breach):

The Vile gang demonstrated a significantly elevated level of technical sophistication by breaching a US Drug Enforcement Agency (DEA) web portal. The specifics of the breach vector were not detailed in the talk, but the outcome was profound: compromise of a system providing access to 16 different US federal law enforcement databases. This implies the exploitation of critical vulnerabilities, likely involving:

  • Weak Authentication/Authorization: Gaining unauthorized access through stolen credentials, brute-force attacks, or bypassing authentication mechanisms.
  • Web Application Vulnerabilities: Exploiting common web vulnerabilities such as SQL Injection, Cross-Site Scripting (XSS), or insecure direct object references to access backend databases.
  • Insider Threat/Social Engineering: Potentially leveraging an insider or tricking an authorized user into providing access.

Once inside, Vile could query these databases to retrieve an astonishing breadth of personally identifiable information (PII). This included:

  • Full legal names
  • Residential addresses
  • Email addresses
  • Mobile phone numbers
  • Records of property ownership
  • Vehicle registration details
  • Professional licenses

The ability to aggregate such comprehensive and authoritative data from federal sources provided Vile with an unparalleled arsenal for doxing and extortion, offering a level of detail and verification that is difficult to dispute, making threats highly credible.

3. Information Laundering and Weaponization (Doxbin Platform):

Doxbin serves as a critical infrastructure for weaponizing acquired PII. Its primary technical feature for extortion is the "private doxes" functionality.

  • Upload Mechanism: Adversaries upload a victim's doxing package (containing all acquired PII) to Doxbin's platform.
  • Private Link Generation: Instead of immediate public publication, Doxbin generates a unique, private URL for the uploaded doxe.
  • Extortion Leverage: The attacker then sends this private link to the victim, threatening to change the doxe's status from private to public. This threat is potent because Doxbin explicitly states it will not remove published information, effectively promising permanent online exposure to its community of over 300,000 users. This technical design turns Doxbin into a powerful tool for psychological manipulation and financial coercion.

4. Exploited Defensive Weaknesses:

Larson's Q&A session highlighted a key defensive vulnerability exploited by adversaries: SMS-based Multi-Factor Authentication (MFA).

  • SIM Swapping/SMS Interception: SMS-based MFA relies on mobile carrier networks, which are susceptible to SIM swapping attacks or other forms of SMS interception. In a SIM swap, an attacker convinces a mobile carrier to transfer a victim's phone number to a SIM card controlled by the attacker. This allows the attacker to receive the one-time passcodes (OTPs) sent via SMS, thereby bypassing MFA and gaining access to accounts.
  • Identity Linkage: Traditional mobile numbers are typically linked to an individual's real identity. If attackers can resolve a target's mobile number, they can then use this information to attempt SIM swaps or other social engineering attacks against the carrier, further compromising the victim's accounts.

This reliance on SMS-based MFA, especially for critical services, creates a significant attack surface that doxing groups can exploit to gain access to further accounts and deepen their PII collection.

Demo / Proof of Concept

▶ Watch: Accessing exclusive interview transcripts via QR code (7:00)

While the talk did not feature a live coding demonstration or a traditional technical proof of concept, Jacob Larson presented compelling evidence and demonstrations of the real-world impact and capabilities of doxing groups.

The most visceral "proof of concept" was a video of a physical intimidation service that the Vile gang had reportedly purchased and utilized to assist with their extortion efforts. The video, though brief, contained chilling audio and a direct threat: "Vile has come to get you. Bye bye." This short clip served as a stark illustration of how online threats translate into tangible, terrifying real-world consequences. Larson further contextualized this by sharing direct quotes from his interview with Ego, the Vile member, who elaborated on the grim reality of these services. Ego's testimony confirmed that "things get pretty wicked online, much more than people realize," detailing instances where individuals "break into the residence torturing individuals with anything from cutting their fingers off to killing them, all to take the crypto currencies they behold." This direct account from an active participant served as a powerful validation of the extreme severity of the threats.

Additionally, Larson announced the public release of transcripts from his interviews with the hackers, including the wanted individual who breached the DEA portal and the administrator of Doxbin. These transcripts, made available via a QR code during the presentation and through a subsequent blog post, function as critical evidentiary material. They provide direct, first-hand accounts from the adversaries themselves, offering unparalleled insight into their methodologies, motivations, and the operational realities of doxing and extortion. In essence, these interviews and the video clip served as a "proof of concept" for the extreme lengths to which doxing has evolved, demonstrating the profound and often violent impact it can have beyond the digital realm.

Defensive Implications

▶ Watch: Secure alternatives to SMS-based multi-factor authentication (8:00)

The insights gleaned from Jacob Larson's talk offer crucial defensive implications for both individuals and organizations aiming to mitigate the risks of doxing and privacy intrusion.

1. Re-evaluate Multi-Factor Authentication (MFA) Strategies:

One of the most immediate and actionable recommendations pertains to MFA. Larson explicitly advised against the use of SMS-based MFA due to its susceptibility to SIM swapping and other interception techniques.

  • Prioritize Authenticator Apps: Individuals should switch to authenticator applications like Google Authenticator or Microsoft Authenticator, which generate time-based one-time passwords (TOTP) directly on the device, independent of mobile carrier networks.
  • Leverage Hardware Tokens: For the highest level of security, particularly for high-risk accounts or individuals, physical hardware security tokens (e.g., YubiKey) are recommended. These devices require physical interaction, making them extremely difficult to compromise remotely.
  • Virtual Mobile Numbers for Legacy Systems: If a service (e.g., Yahoo Mail) offers no alternative to SMS-based MFA, Larson suggested using a **virtual mobile number that is not linked to one's personal identity**. This disassociates the phone number from the individual's name in carrier databases, complicating SIM swap attempts. The key is to ensure the virtual number provider does not associate the number with the user's PII.

2. Enhance Personal Information Hygiene and Digital Footprint Management:

Individuals must adopt a proactive approach to managing their online presence and the PII associated with it.

  • Minimizing PII Exposure: Be cautious about what personal information is shared online, even in seemingly innocuous contexts. Adversaries can piece together disparate data points to build a comprehensive profile.
  • Rare Username Awareness: Larson's own experience highlights that even seemingly minor details like a "rare username" can make one a target. Consider the value of unique online identifiers and the potential risks they carry.
  • Scrutinize Data Brokers: While not explicitly mentioned, the extensive PII gathered by groups like Vile implies the potential use of data brokers. Individuals should be aware of services that allow them to opt-out or remove their data from such platforms.
  • Beware of "It'll Go Away" Advice: Victims of doxing must understand that the common advice of "don't worry, it'll just go away with time" is dangerously inapplicable to platforms like Doxbin. Proactive steps, including legal action or engaging specialized services, may be necessary for removal, though often challenging.

3. Strengthen Organizational Security for Sensitive Data:

The breach of the DEA web portal serves as a critical warning for organizations, especially those holding vast amounts of PII or sensitive government data.

  • Robust Access Controls and Authentication: Implement strong, multi-layered access controls, including mandatory hardware-token-based MFA for administrative and privileged accounts accessing sensitive databases.
  • Continuous Vulnerability Management: Regularly audit and penetration test web applications and infrastructure to identify and remediate vulnerabilities that could lead to data breaches.
  • Employee Training and Awareness: Educate employees about social engineering tactics, phishing, and the importance of strong security hygiene to prevent initial compromise.
  • Incident Response Planning: Develop and regularly test comprehensive incident response plans specifically for data breaches involving PII, including communication strategies and legal obligations.

4. Advocate for Legal and Policy Reform:

Larson's research implicitly calls for greater attention to the legal and policy gaps that enable doxing to thrive.

  • Information Removal Laws: There is a clear need for more effective legal frameworks that compel platforms to remove doxing content, particularly when it poses a direct threat to physical safety.
  • Increased Law Enforcement Awareness: Law enforcement agencies need to be fully equipped and educated about the evolving nature of doxing, recognizing it as a serious crime that can lead to physical violence, rather than merely online harassment.
  • International Cooperation: Given the global nature of cybercrime, international cooperation is essential to apprehend perpetrators and dismantle doxing infrastructures like Doxbin, which often operate across jurisdictions.

By implementing these defensive measures, individuals and organizations can significantly reduce their attack surface and better protect themselves against the growing threat of doxing and privacy intrusion.

Key Takeaways

  • Doxing has escalated beyond online harassment: It now encompasses severe physical threats, including torture and murder, often driven by financial extortion (e.g., cryptocurrency).
  • Sophisticated groups leverage deep breaches: Organizations like the Vile gang can compromise critical government portals (e.g., DEA web portal) to acquire vast amounts of highly sensitive PII from multiple federal databases.
  • Platforms like Doxbin enable persistent threats: Doxbin's "private doxes" feature and its policy against information removal provide a powerful tool for extortion, ensuring that published PII remains online indefinitely, amplifying victim fear.
  • SMS-based MFA is a critical vulnerability: Reliance on SMS for multi-factor authentication is insecure due to SIM swapping and interception risks; stronger alternatives like authenticator apps, hardware tokens, or identity-unlinkable virtual numbers should be prioritized.
  • Proactive privacy hygiene is essential: Individuals must be vigilant about their online footprint, the PII they share, and the potential risks associated with unique online identifiers like rare usernames.
  • Legal frameworks and law enforcement response need modernization: Current legal structures are often inadequate to address the evolving and severe nature of doxing, highlighting a need for better mechanisms for information removal and robust investigation of these crimes.

About the Speaker(s)

Jacob Larson is an Offensive Security Team Lead at Cyx, where he focuses on securing customer applications and infrastructure through security testing. Based in Perth, Australia, Larson also dedicates his evenings to threat research, a field he has been actively involved in since 2016. His personal connection to the subject matter is profound; he was a victim of doxing nine years ago, an experience that has since fueled his extensive research into the underground cybercrime groups involved in privacy intrusion and extortion. Larson's unique research methodology includes personally conducting interviews with notorious hackers, such as a wanted individual responsible for breaching a US DEA data portal and an administrator of the Doxbin website, providing unparalleled insights into the adversary's perspective.

All talks from Black Hat USA 2024