Read and summarize the reading “United States v Gorshkov Detailed Forensics and Case
Study; Expert Witness Perspective” (posted with this assignment). Focus on section 4, 5
and 6.
For section 4, make a table of which tools they (both the hackers and FBI) used and what
kind of analysis they made and what they found in each step (sub-sections in the reading).
At the end of the summary, write a paragraph about what you have learned from the
reading that is not covered in class.
United States v Gorshkov was a large complex investigation resulting in the conviction of
over 20 charges for Russian hackers. Around the time of 1999 to the year 2000, Russian
hackers Alexey Ivanov, and Vasily Gorshkov, committed a variety of wrong doings.
Ultimately, a forensic investigation involving the use of honeypot deployment, undercover
operations, remote data retrieval, and computer forensic analysis put the hackers in jail.
Originally, an Internet Service Provider known as Speakeasy had its system compromised.
Speakeasy was under attack, and credit card information had been taken from the company
as well. When Speakeasy denied hackers job opportunities, the hackers opted to shut down
some of their systems. Speakeasy wasn’t the only company targeted, as the likes of others
such as EBay and Yahoo faced attacks as well.
Through more and more attacks, the names “Subbsta” and “Suidroot” kept appearing.
Eventually, Substa extorted and Internet Service Provider in Los Angeles named CTS by
requesting shell accounts. The FBI found that these actions took place and CTS ended up
cooperating with them. Several investigations took place after cooperation from the CTS
and what the investigators saw was a pattern. The hackers would begin with computer
intrusion, data theft, and end with attempted extortion. They were also able to see that
activity was occurring in Russia. The linked suspect between multiple companies that were
attacked was Alexey Ivanov. Knowing that Alexey wanted a job, the FBI tricked him into
coming for a job interview with his peer Gorshkov, in the United States. Before they came
to America they tried a “test hack” while the company Invita had a honeypot ready to gain
information. The attack was consistent with what investigators had seen.
The original expert witness who was conducting a forensic examination would eventually
prove unable to testify. As a result, a new expert who would perform a variety of tasks
came about. The expert started with evidence gathering, than analysis, and ultimately