This summer, the most prominent YouTubers in the national sphere have seen the security of their social media accounts compromised, and consequently their physical security. On the internet, NOT EVERYTHING GOES—digital identity theft, illicit access, and disclosure of secrets are crimes, they are prosecuted and have legal, reputational, and security consequences.
YouTubers of the caliber of El Rubius, Miare’s Project, Wismichu, or Auronplay have suffered attacks on their social media and email security. Most of these digital celebrities have signed contracts with major brands and companies. Their social media accounts have millions of followers, and just as with a pop star or politician, they arouse passions and hatred of different kinds. As we have always indicated, the motivations for suffering an attack can be of different natures, but we are certainly talking about a targeted attack, in no case random.
Their attackers, self-identified as such through their own Twitter social media accounts, claimed responsibility for the attack and explained its nature by saying they only wanted to demonstrate that the security of these YouTubers’ accounts is vulnerable. The attackers indicated through telephone conversations with some of the YouTubers that they are or have been followers and that their motivation was solely “good” and to “help them.”
But if we broaden our perspective and consider what consequences could it have for an anonymous person if their social media accounts are accessed?
In addition to the possible risks we will see later, a domestic user generally has fewer financial resources to address their cybersecurity and, therefore, takes fewer measures. This is why they may be the victim of a random attack in which they suffer financial consequences, loss of information, or disclosure of secrets involving sensitive information (intimate, private, their own or third parties’).
Obviously, they can also be the victim of a targeted attack on their person resulting from personal/romantic, professional motivation, or a combination of both.
What if it is a public figure?
In addition to the risks we will see and personal/professional motivations, they also have an incentive for their potential attackers, which is that if their attack becomes public, the scandal can lead to a loss of reputation and consequently financial loss as well.
And what if they are also the partner of someone socially relevant? The risks keep adding up. Every user is responsible for the container and content of their information, but by sharing communication channels with third parties, some of them containing sensitive information such as conversations, audio files, videos, photos—if these are not properly safeguarded, the consequences of an attack can be devastating for us and third parties.
What if it is a member of a company?
Here we have an added risk, which is that we all have our intimate, personal, social, and professional facets, and in this fourth one we can generate serious security problems for the entities we are part of; therefore, extreme caution must be exercised.
Let us evaluate the consequences for their victims. We can order them by importance and type of risk:
- Risk to their security and privacy
- Risk to their reputation and that of third parties
- Risk to their finances and those of third parties
- Legal risk for safeguarding sensitive information of third parties
What if we change perspective and analyze the legal consequences for the attackers?
Assessment of possible offenses (civil and criminal) (Coming soon)
Evidence collection and its validity (eGarante / notary pros and cons) (coming soon)
Attack analysis (security) (coming soon)
Conclusion and infographic
Once we know that on the internet not everything can be done without consequences, it can and must be prosecuted, and prevention and protection measures must be taken, let us see what we can do post-incident.