A hacker who exposed Verkada’s surveillance camera snafu has been raided


Tillie Kottmann, a 21-year-old hacker, has been raided by Swiss authorities and their devices seized, Bloomberg reports — days after helping to reveal how Silicon Valley security startup Verkada’s own security was so poor that that hackers were able to access over 150,000 of the company’s cameras to see the insides of schools, jails, hospitals, police stations, and Tesla factories.
The raid doesn’t have anything to do with Verkada, according to Bloomberg, but instead an “alleged hack that took place last year,” and interestingly, a Swiss authority pointed Bloomberg to the US Department of Justice for further questions. (The DOJ declined to comment.)
It’s not clear which hack the DOJ might be interested in, as Kottmann has been continually sharing leaked files from various companies for months, but one sticks out as likely: Kottman leaked a huge collection of secret documents and source code from chipmaker Intel last year, and Intel vowed to investigate. Bloomberg says it’s seen the search warrant, which mentions that the FBI was looking into the “theft and distribution of information including source code, confidential documents and internal user data.”
Kottmann has suggested in the past that they’ve been unfairly targeted for ethical hacking, particularly by Twitter, which suddenly chose to enforce its rules on ban dodging by suspending Kottmann’s account just a few days after the Intel leak in August 2020. Twitter originally suspended Kottmann for “distribution of hacked material” last June, according to screenshots they shared with me last year, and Twitter confirmed the second suspension was for violating the platform manipulation and spam policy that keeps users from dodging their bans by simply creating a new account. Following the Verkada disclosures, Twitter suspended Kottmann’s most recent account, too.
It’s leading some hacktivists to question platforms’ ability to silence hackers:
Why is Twitter so hostile to hacktivists?
Especially considering @dotMudge, whose FORMER glory days include being member of Cult of the Dead Cow, who some claim are responsible for giving us the word ‘hacktivist’ is their current Chief Information Security Officer? pic.twitter.com/yPIIvq9xYO
— punished donk (@donk_enby) March 12, 2021
(Hacker donk_enby, above, was the one who scraped 80 terabytes of videos from Parler, videos which were later extensively used to reveal what actually occurred during the Capitol Riot, including as evidence in Trump’s second impeachment trial.)
It may be a difficult line for platforms to draw. Yesterday, Microsoft-owned GitHub decided to take down a security researcher’s work that could have reflected poorly on Microsoft, because the proof-of-concept exploited the holes in Microsoft Exchange Server’s code that were used in the huge Hafnium hack. Microsoft’s argument was that the attack is still occurring and that the code could still be exploited, which does make sense on its face.
Kottmann (or, at least, someone using an account connected to a recently valid username of Kottmann’s, I’m still trying to confirm) declined to comment on the raid, saying that their previous statements had already resulted in Swiss press harassing their family. Kottmann told Bloomberg that their parents’ home was searched by Swiss police as well.
Kottmann also seems to still have access to a Mastadon account, one that’s currently warning readers to “assume all past communication with me to have been compromised” and “under US control.”
“do not talk to me about any illegal activities or crimes. i do not plan on doing anything illegal for the near future,” reads the current pinned post.
Tillie Kottmann, a 21-year-old hacker, has been raided by Swiss authorities and their devices seized, Bloomberg reports — days after helping to reveal how Silicon Valley security startup Verkada’s own security was so poor that that hackers were able to access over 150,000 of the company’s cameras to see the…
Recent Posts
- ChatGPT is a terrible, fascinating, and thrilling to-do list app
- Satya Nadella says AI is yet to have its Excel moment
- I have good news and bad news about Windows 11 24H2’s new update: it introduces nifty features and fixes… but also includes another ad
- Where to Stream 2025’s Best Picture Oscar Nominees
- The hidden costs of data subject access requests (DSARs) on privacy
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010