Connect with us

E-Business

Check Point Exposes Notorious Hacktivist ‘VandaTheGod’

Published

on

Kindly share this post

Check Point has shared research detailing its investigation to expose the real identity of a notorious super-hacker who has been responsible for attacks on 4 820 Web sites, the theft of the private data of around one million people, and the sale of stolen credit cards.

In addition, for the last seven years, official Web sites belonging to governments worldwide were hacked and defaced by this hacker, who identified himself as ’VandaTheGod’. The hacks push an anti-establishment message and were carried out, he claimed, to combat social injustices that the hacker believed were a direct result of government corruption.

He targeted governments in numerous countries, including South Africa, Brazil, the Dominican Republic, Trinidad and Tobago, Argentina, Thailand, Vietnam, and New Zealand.

He was certainly cunning, but not too clever, as a silly mistake on Facebook exposed him, and will likely seal his fate.

“The person behind the ‘VandaTheGod’ persona has used multiple aliases over the years, including ‘Vanda de Assis’ or ’SH1N1NG4M3’, and was highly active on social media, primarily Twitter,” says Check Point. “They would often share the results of those hacking endeavours with the public. A link to this Twitter account would sometimes even be added to the message VandaTheGod left on compromised Web sites, confirming that this profile was in fact managed by the attacker.”

Advertisement

Many of the tweets in this account were written in Portuguese, and the hacker claimed to be a part of the “Brazilian Cyber Army” or “BCA”, often displaying BCA’s logo in screenshots of compromised accounts and Web sites.

VandaTheGod didn’t only target government Web sites, but also launched attacks against public figures, universities, and even hospitals. In one case, he claimed to have access to the medical records of 1 million patients from New Zealand, which were offered for sale for $200.

While the majority of VandaTheGod’s attacks against governments were politically motivated, but closer scrutiny of his tweets shows he was also trying to achieve a personal goal: hacking a total of 5 000 Web sites, a goal that was nearly achieved, with 4 820 records of hacked Web sites linked to him.

The man behind the handle

VandaTheGod’s prominent role in several hacking groups, as well as his love of publicity, meant that he stayed in touch with others in the hacking community via numerous social media accounts, backup accounts in case of takedown, e-mail addresses, Web sites and more. Through the years, this activity left a long trail of information for Check Point to investigate.

Advertisement

For example, the WHOIS record for VandaTheGod.com revealed that the Web site was registered to an individual from Brazil, more specifically from Uberlandia, using the e-mail address [email protected]. In the past, VandaTheGod claimed to be a member of the UGNazi hacking group, and this e-mail address was used to register additional Web sites, such as braziliancyberarmy.com.

This wasn’t the only time the hacker got sloppy and shared details online that gave away valuable information about his identity. Another example, a screenshot that showed the compromised e-mail account of Brazilian actress and TV presenter Myrian Rios also shows an open Facebook tab with the name “Vanda De Assis”, and looking that name up led to a profile belonging to the attacker.

“While this profile did not share any details about the real identity of VandaTheGod, we were able to see many similarities between this and the Twitter accounts operated by the attacker, as the same content was often shared on both platforms,” says Check Point. “What was more interesting, however, was that this screenshot revealed the name of a user that we will identify here only by initials MR.”

At first Check Point was unsure if these were the hackers real initials, but upon further investigation, discovered a first name with these initials also appearing in several screenshots shared in VandaTheGod’s Twitter as the username of the machine used for this hacking activity.

Researchers tried to search Facebook for people named MR, but unsurprisingly, were presented with too many possibilities to fully explore. “Our breakthrough came when we searched for MR in conjunction with the city we previously observed in vandathegod.com’s WHOIS information: “UBERLANDIA”.

Advertisement

This still gave Check Point numerous Facebook profiles, but researchers were able to locate a single account, which contained an uploaded image endorsing the Brazilian Cyber Army. “At this point, we knew that we were on the right track. All that was left for us to do was to connect this individual’s account with one of the known VandaTheGod’s accounts. We were able to locate several cross-posts between the newly discovered profile and Vanda de Assis’s Facebook account,” the researchers say.

Finally, Check Point located shared photos of the same surroundings from different angles, specifically, the poster’s living room. This confirmed that both the MR and VandaTheGod accounts were being controlled by the same person.

Kindly share this post

Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

Microsoft to Unveil Next-generation AI Chip in September

Published

on

Kindly share this post

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon ​as next month, The Information reported on Monday, citing ‌people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and ​Amazon in scaling up its in-house chip efforts as ​it seeks to reduce its reliance on Nvidia’s costly ⁠processors.

Google began recognizing revenue from direct sales of its custom ​AI chips, called Tensor Processing Units, in the quarter ended June, ​while Amazon has also seen growing adoption of its processors, including its Trainium chips.

Microsoft has been in talks with chipmaker TSMC to secure manufacturing ​capacity for more than 300,000 units of the chip for ​delivery in 2027, according to the report. It is also looking to significantly ramp up ‌production ⁠and persuade major cloud customers such as Anthropic to adopt the chip.

Microsoft ultimately ​aims to ⁠secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity ​negotiations with TSMC could constrain its plans, according ​to the ⁠report.

Advertisement

It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.

Microsoft packed the chip with a significant amount of ⁠SRAM, ​a type of memory that can provide ​speed advantages for AI systems handling large numbers of user requests.

 

Kindly share this post
Continue Reading

E-Business

X Replaces Revenue Sharing wit New Creator Rewards Programme

Published

on

Kindly share this post

X has announced plans to discontinue its Revenue Sharing programme and introduce a new Original Content Rewards programme to reward creators for producing original content on the platform.

X Replaces Revenue Sharing wit New Creator Rewards Programme

The social media company announced the changes at the weekend in a post on its X Creators handle, saying the new programme would reward creators who contribute original content.

“Today, we’re introducing the Original Content Rewards Program, a new way to reward creators who bring original ideas, expertise, reporting, creativity, and commentary to X,” the company said.

X said it would stop accepting new enrolments into the Revenue Sharing programme from Friday, while existing participants would continue earning until September 7, 2026.

“Starting today, we’re no longer accepting new enrollments into Revenue Sharing,” it said.

Advertisement

According to the company, existing Revenue Sharing participants will receive three final payouts, with two scheduled for August 14 and August 28, while the final payment for earnings accrued through September 7 is expected around September 11.

X said existing Revenue Sharing participants would begin getting access to apply for the new programme from September 8, subject to meeting its eligibility requirements.

The first payout under the Original Content Rewards programme will be made on August 28, 2026, while existing Revenue Sharing creators who enrol in the new programme from September 8 will receive their first payment on September 25.

Under the new programme, eligible creators will earn from qualified impressions generated by their original content, with payments made every two weeks.

X defined qualified impressions as unique impressions from Premium users on the Home Timeline feed, where at least 50 per cent of a post is visible.

Advertisement

On the other hand, “The following are excluded from qualified impressions: impressions from the same account counted more than once per post; paid, promoted, or artificially generated impressions; and fraudulent impressions,” it said.

To qualify, creators must be at least 18 years old, live in a country where the programme is available, maintain an account in good standing and have either a personal or vusiness account.

They must also subscribe to X Premium, Premium+ or Premium Business, have at least 500 verified followers and record at least 500,000 Home Timeline impressions from verified users within the previous 90 days.

X said creators must also regularly post original content to remain eligible.

“We want to recognize creators who break news, share expertise, tell stories, create entertainment, and contribute meaningful perspectives to the conversation,” the company said.

Advertisement

The platform said original content could include threads, videos, memes, graphics, illustrations, reporting, analysis, commentary and reactions that add meaningful value to existing conversations.

It said creators who use content produced by others would need to add meaningful commentary, context, analysis, humour or creative transformation for such posts to qualify.

“Building on existing conversations is a core part of X, but simply reposting someone else’s content is not enough,” it said.

X said minor edits such as cropping, filters, borders, watermarks, speed adjustments or simple text overlays would generally not qualify as meaningful transformation on their own.

It also warned that content copied or substantially reproduced from another creator, content downloaded and re-uploaded from X or another platform without being the original author’s, automated content, disinformation and misleading content would be ineligible.

Advertisement

The company said accounts that violate the programme’s requirements could be temporarily or permanently removed from it, depending on the severity of the violation.

It added that creators would be responsible for ensuring they had the necessary rights, permissions or licences to use content created by others.

“Original content is content you personally create that reflects your own voice, perspective, expertise, or creativity,” X said.

The company said the new programme was intended to reward creators who make the platform more valuable by bringing original ideas and perspectives to its conversations.

“The Original Content Rewards Program is designed to reward the creators who start them, shape them, and move them forward,” it said.

Advertisement

Kindly share this post
Continue Reading

E-Business

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

Published

on

Kindly share this post

National Information Technology Development Agency (NITDA) has introduced so-called Nigeria’s Certified Cloud Register, regulatory framework developed under the agency’s National Sovereign Cloud Initiative to determine which cloud providers are authorized to handle sensitive data, such as banking records.

NITDA Introduces Cloud Certification Boost Data Localisation Compliance

In effect, from October, NITDA requires banks, fintech companies and other regulated organisations to source cloud infrastructure providers from a national register of certified firms approved to host sensitive financial and government data.

The Certified Cloud Register, is expected to strengthen data sovereignty, improve regulatory oversight and support the implementation of the Central Bank of Nigeria’s (CBN) data localisation policy, which takes effect on January 1, 2027.

Under the framework, banks, fintechs, government institutions and other regulated entities will be able to verify whether cloud service providers, data centre operators, managed service providers and Artificial Intelligence (AI) infrastructure companies have met NITDA’s certification requirements before entrusting them with critical digital workloads.

The initiative is expected to provide regulated institutions with a standardised process for selecting cloud infrastructure providers that satisfy Nigeria’s technical, security and regulatory requirements.

Advertisement

According to NITDA, the framework establishes “a common national standard, an independent assessment process and a public register of approved providers that banks, fintechs and government institutions can rely on when selecting cloud infrastructure partners.”

The register is expected to become a key compliance tool ahead of the CBN’s directive, which requires all payment transaction data generated within Nigeria to be stored and processed locally, effective from January 1, 2027.

The policy applies to deposit money banks, microfinance banks, mobile money operators, payment service providers, switching companies and other financial institutions.

The certification regime is also expected to reshape Nigeria’s cloud computing ecosystem, making regulatory approval a major requirement for cloud providers seeking to handle sensitive data for regulated industries.

Figures cited by NITDA showed that Nigeria’s 10 largest banks spent about N177.91 billion on information technology in the first quarter of 2026, representing a 31 per cent increase over the corresponding period last year.

Advertisement

A sizeable portion of the investment currently supports cloud infrastructure hosted outside Nigeria, a trend the new certification framework is expected to address by encouraging greater utilisation of compliant local infrastructure.

NITDA said the certification programme will apply the same technical and regulatory standards to indigenous cloud providers and international hyperscale operators, creating a level playing field for all companies seeking to provide cloud services to regulated sectors.

The agency also disclosed that more than 85 per cent of Nigerian businesses currently rely on cloud services, with the majority using infrastructure hosted outside the country.

It said the new framework is aimed at improving confidence in Nigeria’s digital infrastructure while promoting local capacity and enhancing oversight of critical national data.

Speaking on the objective of the initiative, Kashifu Inuwa Abdullahi, director-general of NITDA, said the programme is designed to strengthen Nigeria’s position in the global digital economy rather than exclude foreign technology companies.

Advertisement

According to him, the initiative is intended “to redefine the terms under which Nigeria participates in the global digital economy rather than isolate the country from international technology providers.”

The Certified Cloud Register forms part of broader efforts by the Federal Government to deepen digital trust, strengthen cybersecurity and ensure that critical financial and public sector data are managed in line with Nigeria’s evolving data governance and sovereignty objectives.

Kindly share this post
Continue Reading

Trending