
Show notes
This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far. Sponsors Support for this show comes from ThreatLocker®. ThreatLocker® is a Zero Trust Endpoint Protection Platform that strengthens your infrastructure from the ground up.
Highlighted moments
Matthew had been using Williams' identity for 31 years, which means he has tons of supporting evidence to prove he's really William. What do you want? W-2s, electricity bills, library cards, credit cards, a marriage certificate.
“The manager is still on the phone with Matthew. And since he knows all the answers to the security questions and the real William looks like some homeless guy, he's more convinced that the guy on the phone is the true account holder.”
“He got so wild and furious with everyone that they really did think he was having a psychotic breakdown and decided that he's not fit for court and sent him away to a mental hospital without even having a trial.”
“the data broker company's total cash in the bank is $563 insurance expense $1,327 cybersecurity budget zero”
Transcript
Sponsor Introduction
0:00This episode is sponsored by Cohesity. Cyber resilience isn't just about getting systems back online. It's about keeping your business operating when disruption strikes. That's the idea behind the Minimum Viable Company, or MVC, a trusted operating core for recovery. Cohesity built the MVC to help organizations identify the essential applications, data, people, and processes required to serve customers, maintain communication, protect revenue, and meet critical obligations.
0:30By restoring this trusted operating core first, organizations can reduce downtime, accelerate recovery, and maintain continuity while broader restoration efforts continue. It also provides a clear recovery target, enabling teams to focus resources where they will have the greatest business impact. Learn more at Cohesity.com slash resilience. That's Cohesity.com slash resilience. Cohesity. Resilience everywhere.
Identity Theft Story
1:00So back in 1988, there was this identity theft incident that happened, which, when I read it, it infuriated me so badly. And, um, well, now I want to infuriate you. So check this story out. This all started in Albuquerque, New Mexico, like I said, 1988. And there was a hot dog stand there, which seemed to hire people who were really down and out. Like, if you had a past criminal record, that's fine. You hired a homeless. Homeless? Okay, here's a job, buddy. Get yourself together. William Woods was the homeless guy working there.
1:30And then they hired Matthew Kierens. Matthew had a long criminal record and was trying to separate himself from that past. And he was new in town, just needed, like, a little cash to probably just get him to the next town or something. But as soon as Matthew started working at this hot dog stand, he stole William Woods' wallet, the homeless guy that was also working there. William found out that Matthew stole his wallet and confronted him. And he threatened him, and he got the wallet back. But, jeez, what kind of jerk steals someone's wallet like that? Neither of them lasted long at this hot dog stand.
2:01William, the homeless guy, actually left town to find a new job. He went over to Texas for a while. He did some day labor jobs there. Then went over to Las Vegas and worked in a laundromat. And eventually he ended up in Los Angeles, scavenging for gems and metals.
Matthew's New Identity
2:14But little did he know, while he was struggling to get his life together, Matthew had started calling himself William Woods. See, since Matthew didn't have a house, he carried all his important documents with him. So when Matthew stole his wallet, his birth certificate and social security card was in his wallet. So Matthew copied those things down and then moved to another state and then started to register stuff in that name. He asked for an official birth certificate from the state and a social security card for William Woods and got them.
2:46And he got a driver's license with William Woods' name on it, but it had Matthew's picture on it. And he got a job as William Woods. Because remember, Matthew had a criminal past and he was eager to leave that behind. A fresh start was really great for him. But he didn't stop there. Matthew opened a bank account as William Woods too. By 1994, six years after stealing Williams' wallet, Matthew had completely took on this new identity. And William had no idea. Matthew even got married to a woman who thought his name was William Woods.
3:22And then they had kids and they called themselves the Woods family. Matthew wanted to know more about William, to have a solid backstory, and went on Ancestry.com and convinced them that he's William Woods and he learned all about his childhood and his family. And actually, this all had a huge payoff for Matthew. This was great for him because he had a criminal past, but that was essentially erased. And now, he got a $100,000 a year IT job at the University of Iowa and a car and even took out a loan for a house under his assumed identity.
3:54This fresh start was looking great for him. The real William still had no clue and was busy scavenging for gems and minerals in California. He was an off-the-grade kind of guy, so he wasn't filing his taxes or opening bank accounts himself. And he only used cash wherever he went and kept a pretty quiet life. And because of that, Matthew was able to use William Woods' name for decades without anyone knowing.
William Discovers Identity Theft
4:21In 2019, the real William started getting a hunch that someone might be using his identity and talked to someone about it and they gave him some money to do a credit check. And that's when William discovered there's loans out at a bank under his name. So he goes in the bank, identifies himself as William Woods, shows them his California ID, and they're like, okay, how can we help you? And he's like, well, I don't have an account here. Someone else is using my social security number or name or whatever because that account is not mine. The assistant branch manager walks over
4:53and he looks at William's account and there are some security questions associated with it and a PIN. William cannot answer any of the security questions and doesn't know the PIN, obviously. So the manager's like, okay, well, there's a phone number here. And William's like, that's not my phone number. So the manager's like, well, let's see what happens when I call it. So he calls the number and Matthew picks up over in Iowa. But Matthew abandoned that name, Matthew, long ago. He's like, yeah, I'm William Woods. What's the problem? And they asked him the security questions
5:23and he got it right. So now the bank has two people who have authenticated themselves to be the owner of this account and they have to figure out who's the real owner.
Bank Investigation
5:33The manager is still on the phone with Matthew. And since he knows all the answers to the security questions and the real William looks like some homeless guy, he's more convinced that the guy on the phone is the true account holder. So he tells Matthew, well, there's someone here in the bank claiming to be you. And Matthew's like, in California? I'm in Iowa. Nobody in California should be accessing my account. So William's standing there and the manager's looking at him and the manager starts thinking, this guy in the bank must be faking his identity
6:04to get into this guy's account. So he calls the cops on William for identity fraud. The cops call Matthew and they ask for proof that he's actually William Woods. And Matthew just sends him his driver's license, social security card, birth certificate. At this point, Matthew had been using Williams' identity for 31 years, which means he has tons of supporting evidence to prove he's really William. What do you want? W-2s, electricity bills,
6:35library cards, credit cards, a marriage certificate. I can give you supporting documents for days. I am the real William Woods. And in the meantime, the real William Woods has very little to show that he's actually who he says he is. He has an ID from the state of California, but that's about it. He just didn't have much documentation to prove he was actually William. But that's just the beginning.
USDOD Introduction
6:58Get this. Matthew must have known what was going on because when Williams went to court in California, he was tried under the name Matthew Kearans. So that must mean that Matthew told the cops that William is probably this guy, Matthew Kearans, which is so messed up and backwards. Now, William is going out of his mind. He is disgruntled. He is furious. He's confused and absolutely angry with the cops and the court. I mean, I would be too, but it's not helping his situation at all.
7:29He seems wild and crazy, which makes everyone in the court think he's actually nuts. Even his lawyer doubted the story. He got so wild and furious with everyone that they really did think he was having a psychotic breakdown and decided that he's not fit for court and sent him away to a mental hospital without even having a trial. So poor William got thrown in the mental ward and not only that, but they forced him to take psychiatric drugs.
7:59The whole time, they were calling him Matthew and he's like, no, I'm not Matthew. Matthew stole my identity. I'm William Woods and he was forced to stay in the mental hospital for five months and when he finally calmed down, they said, okay, now we can have your trial and the judge looked at the case and found him guilty for trying to steal William Woods' identity. So they sent him to jail. Not only that, but they charged him
8:30a $118,000 fee for his hospital bill. This is the stuff that makes me furious. I mean, like, absolutely furious that the victim gets treated like this and the actual identity thief got away with it. I'm sure William must have thought he was crazy at times and it's no fun when you start doubting your own reality and don't even know who you are anymore because the court forced him to call himself Matthew. He was admitted to jail as Matthew. The guards called him Matthew
9:00and they made him call himself Matthew. So poor William just had to serve his jail time. He didn't have any resources to fight this. So months go by in jail, a year goes by and after a year and a half he served his complete sentence and was able to get out. And when he gets out he is mad. So mad at Matthew for putting him through all this that he calls Matthew's work University of Iowa to report him. And this makes its rounds to some people
9:30at the University of Iowa and someone decided to do their own little investigation. They thought what if William is right and Matthew did actually steal his identity instead of the other way around. And surprisingly at this point no one had done a DNA test on either man. So the person from the University of Iowa figured out who William Woods his real father was which wasn't easy and was able to get a DNA sample from the father. And then he went to California and took a DNA sample from William Woods and bingo
10:01there was a clear match. The investigator called Matthew and asked him what his father's name was but Matthew had no idea. So after a year and a half in jail and five months drugged in a mental hospital everyone finally realized that William was telling the truth the whole time. Ugh! The courts apologized they exonerated him of all wrongdoing and they even canceled out his $118,000 medical fee that they charged
10:31him with like oops sorry that was our mistake and he was free to go on calling himself William once again. But then the cops turned towards Matthew in Iowa and were like uh bro you lied to us you lied under oath in court and you made a poor man suffer for years because of this? Not to mention you conducted identity theft? So they arrested Matthew and sentenced him to 12 years in federal prison. His expected release date is 2037.
USDOD's Story
11:06These are true stories from the dark side of the internet.
11:13I'm Jack Recider. This is Darknet Diaries. This episode is sponsored by ThreatLocker. The weird part about modern cyber attacks is how normal they look. The attacker logs in from Chrome uses PowerShell runs a remote admin tool
11:44your IT team already trusts. There is no custom malware no dramatic movie hacker moment just normal tools used in the wrong way. That's part of why ThreatLocker exists. ThreatLocker helps organizations control what software can run what it can do and how systems communicate. If attackers get credentials or land on a machine they'll have a much harder time moving through the environment because security teams are realizing something important. The problem isn't always unknown software anymore sometimes it's trusted software being used
12:15by the wrong person. If you want to see how ThreatLocker works go to ThreatLocker.com slash Darknet and book a demo today. That's ThreatLocker.com slash Darknet to book a demo. This episode is sponsored by my friends over at Maze. GitHub saw nearly a billion commits last year. This year with AI agents writing code they're on pace for 14 billion. Code is shipping
12:45faster than ever and its vulnerabilities are piling up just as quickly. Legacy SCA and SAST tools weren't built for this kind of scale. That's why Maze just launched Maze Code. They're using AI agents to investigate every vulnerability in your dependencies and in the code your team writes. The agents use context from your code and cloud to prove what's really exploitable in your environment not just theoretically risky. Then they go further catching the business logic flaws other tools miss
13:15and when something's exploitable they find the fix and send it straight to the right developer or your coding agent. Check out Maze at mazehq.com slash darknet that's Maze spelled M-A-Z-E mazehq.com slash darknet A few years ago a friend messaged me and said look out an APT just followed you on Twitter and I'm like what? He's like yeah the U.S. government is classifying this account as an APT
13:46an active persistent threat to the U.S. government I'm like whoa which account is this? He said oh the account name is USDOD USDOD as in Department of Defense and they're they're in APT and they're following me no no that's just their hacker name could be a group could be a solo person but they're calling themselves USDOD to be funny edgy and confusing so this began my relationship with the APT known as USDOD he was active in the hacking scene and would post what he's doing right there on Twitter
14:17and I started commenting on his post and he started commenting on mine and we laughed and we giggled and we started forming some kind of weird parasocial relationship through Twitter I always had a hard time getting a good read on him he contradicted himself a lot he seemed a bit young in the way he was talking it was really hard to figure out if what he was saying was true or just something he exaggerated or even made up I think a few times I caught him talking to himself even like you know just some weird gibberish that probably only he understood
14:47I asked him for an interview he said okay but then I realized his story's just beginning if I interview him now I'm sure there's going to be much more that comes so I just held off waiting for the story to ripen more and I think a year went by and I just watched him do more and more crazy stuff and it was hard to tell what was real and what wasn't but then he suddenly disappeared the account was banned and I never heard from him again turns out his story is much more
15:18crazier than I realized are you ready so let me give you an example of how strange he is a few years ago the reporters at databreaches.net did in fact interview him and this interview is all over the place like here check out this one story he told them back in 2012 the hacker known as USDOD was living in Brazil and said he went to New York for cancer treatment during his time there he fell in love with one of the hospital employees they became deeply involved with each other
15:50they started talking about how corrupt the hospital is so him being the little hacker that he was he decided to hack the hospital and expose the corruption she said she would help him and with an insider well it's super easy to hack into a hospital so she helped him get into the network and he took incriminating evidence that proved the hospital was corrupt he said he was going to take this to the media and tell reporters and expose the whole hospital and together they were going to make a big deal of this
16:20but the day before he was going to meet with the media she suddenly disappeared his attention shifted entirely to find her he became frantic depressed emotional to go from a deeply involved relationship with her to hacking into the hospital together to suddenly being alone in New York he was distraught he hired a private investigator to try to track her down but even the PI couldn't find her she vanished like a ghost so with no reason to stay in the US
16:50he returned to Brazil and never blew the whistle on the hospital and this made him extremely bitter with the US it's not entirely clear why he's mad at the US government over this but says this was the thing that made him upset at the US government maybe he thinks they made her disappear somehow or kept them apart I don't know but this is what I mean what a wild story to start with right he came to the US fell in love with a hospital worker found corruption in the hospital
17:22hacked the hospital went to expose it but then she vanished and he was left holding the smoking evidence that could ruin the hospital but decided not to publish it due to a heartbreak it sounds like a movie plot and who knows how much of that is true since it was just a story he told reporters anyway he says her disappearance gave him a personal vendetta against the US and this is what started his decade-long campaign to attack the US he says it wasn't politics
17:52which is just wild because you decided to become an APT because you were heartbroken okay I've heard stranger things on this show let's go
Luan's Hacking Career
18:02let's see where this goes he joined dark web communities met criminals from far off places Russians Iranians North Koreans and learned more about hacking techniques from them he trained up by breaking into small companies that made easy targets he started making a name for himself among the hackers in the hacker community unknown to the rest of the world though until one day when he was approached by an associate a Russian who claimed to be developing some kind of AI platform named Tulip the Russian
18:32needed help asked DOD hey can you help us collect military data it would be useful for Tulip and I want to clarify whenever I say USDOD in the story I'm always talking about this hacker from Brazil that's the name he was going by so USDOD accepted the job and over the next six months some Russian folks he partnered with were able to build an exploit for an unknown vulnerability in the US army IT platform called the Program Executive Office Enterprise Information
19:03System PEO while the Russians did that USDOD discovered that a way into this network could be to impersonate one of the developers who made it so he discovered who developed PEO and started working on getting closer to them he tried getting access through the developer using social engineering techniques and this strategy worked humans are always the weakest link and it was a pincher move attacking the system from two sides together the Russian hackers and USDOD were able to steal source code
19:34and get different databases from agencies that use PEO agencies like the Department of Defense's Strategic Command Central Command Special Operations Command and Defense Technical Information Center and Army Specialist Operations Center the defense contractor Lockheed Martin too the Russians took what they wanted from the deal and USDOD got to take credit for the breach in three days in February 2022 he leaked lists of full military emails and passwords to the dark web and that is how he got the hacker name USDOD
20:05by breaching the Department of Defense and publishing tons of military emails talk about an entrance onto the hacker scene and it was here when the US considered him a threat you don't attack the military like that and expect them to ignore you they were working hard to figure out who USDOD was USDOD didn't stop there he went on a roll after that his next target was InfraGuard this is basically the tip line to the FBI if you have an important business you can register for an account in InfraGuard and then you can report incidents to the FBI
20:35directly and fast think critical infrastructure companies like gas companies dams water treatment facilities or banks that might need to contact the FBI quick to take action on an incident that's what InfraGuard is and that was the site that USDOD was trying to attack it's normal for companies to apply to join InfraGuard so USDOD figured why not try to apply himself but his plan was to steal someone's identity who would qualify to be accepted and submit them to join so first
21:06he looked around for a finance company that would qualify then he looked up the CEO's name got his personal information probably just bought it off the dark web and USDOD filled out an application on their behalf put in the CEO's information that he knew and just faked the rest InfraGuard replied back there's some errors on your forms these parts need fixing so he's like okay and so DOD fixed him and sent it back again and a few weeks later he got another reply his application was accepted
21:37and just like that he was in the InfraGuard system not quite hacking his way in but faking his way in he tricked the FBI that he was someone else and once there he saw that you could talk to other members so he started chatting them up and they thought he was a genuine CEO but then he started poking around the site trying to test the database or servers to see if there's something weak here and he found that the site has an API which is basically a way to query the database but he uses a different authentication mechanism and while he was examining the API
22:08he discovered that you can ask it for all the members contact information and it would give it to you like a big phone book basically but you had to be a member to see everyone else's details nobody knew about this huge vulnerability maybe because nobody who belonged to InfraGard would ever think to attack the site like this it was a perfect opportunity USDOD asked a friend to write him a Python script to grab the data then he used it to steal every InfraGard member's contact information 80,000
22:39CEOs executives and security officers and again he posted it all for sale on the internet and it was around here when he started following me on Twitter so you can see why they thought of him as an APT he was advanced enough to sneak into FBI's InfraGard and persistent to attack the US government again and again and definitely a threat advanced persistent threat title acquired which means the US government would be actively investigating him more now
23:09than ever and I'm not sure how they figured it out but they figured out his name and his name was Luan Barbosa he's from a small city in Brazil but Brazil doesn't extradite their own citizens so I think the US government had a hard time figuring out a way to take him down but despite being actively investigated by the feds his vendetta was just getting started he thought he was untouchable taunting the feds and anyone else I mean his Twitter photo
23:40was just a picture of the cutest kitty you ever saw he found a certain formula for hacking which was working surprisingly well for him step one search through data dumps on the dark web for someone he can impersonate to help him reach his target step two impersonate that target or use their account to get in step three profit using this formula USDOD or Luan broke into Cybersecurity Defense Center at NATO and a
24:10Washington DC club for politicians and the aerospace company Airbus and their 3,000 vendors in two or three years Luan breached so many US government and government related organizations that he was planning on building a business out of it a full-on company selling military intelligence he had some pretty wild access and information and he knew that people around the world would want to have this or buy it from him so why not make a business out of stealing this and selling it to get his
24:41business off the ground though he needed a steady supply of people to impersonate people with military connections and enough of their information to do it right he was buying identities from places on the dark web but this process had friction I think what he was doing was looking to see who worked