DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Tuesday: UK High Court will hear extradition appeal from alleged member of thedarkoverlord

Posted on October 21, 2019 by Dissent

It has been more than three years since a threat actor or group calling themselves thedarkoverlord (TDO) dramatically announced that they were hacking medical practices and demanding large amounts of bitcoin to not dump or sell patient data.

Nathan Wyatt
Nathan Wyatt aka “Crafty Cockney” in an undated photo provided to this site.

Tomorrow, one man allegedly associated with TDO will be hoping that his lawyers can successfully appeal a District Judge’s decision to extradite him to the U.S. His appeal will be heard by a panel of High Court judges.

Nathan Wyatt, a 38 year-old man from Wellingborough who is also known as “Crafty Cockney,” faces six counts in an indictment issued by a grand jury in the Eastern District of Missouri:

  • One count of conspiracy against the U.S. (18 USC 371 )
  • Two counts of aggravated identity theft (18 USC 1028)
  • Three counts of threatening damage to a protected computer (18 USC 1030)

The affidavit filed by DOJ lists five victim companies — four in Missouri and 1 in Atlanta. The affidavit links all five victims and extortion attempts to Wyatt in various ways. There is a lot of detail about the evidence the prosecution will be presenting at trial — IP addresses, email addresses, bank account information, phone numbers, and other information that they claim can be traced directly to Wyatt. Based on their detailed affidavit, Wyatt seems to have been stunningly sloppy in his operational security or overconfident as he allegedly used his unmasked personal details to register for accounts that were used to register for other accounts used as part of criminal operations. He left what appears to be a very compelling trail linking him to thedarkoverlord (TDO) activities. Of course, these are just unproven allegations at this point.

But even if Wyatt is not the brains/leader of TDO (and anyone who uses their own details and their fiancee’s personal details to set up bank accounts to receive extortion payments does not strike me as likely to be the brains of a criminal enterprise), the government appears to have built a convincing case that he was a conspirator in this organized hacking and extortion ring.

Wyatt’s appeal of the extradition ruling will likely focus on the argument that the crimes that he allegedly committed would have been committed in the U.K., even though their impact might be in the U.S. His solicitors will  likely also argue that because Wyatt has no ties to the U.S., but has children in the U.K. and a fiancee with whom he lives and co-parents, the interests of justice would be better served by having him stand trial in the U.K.

The DOJ’s filings, which are not public at this point, describe, but do not name the five victim entities, but here’s who I think the filings are describing:

  • Victim 1 is described, in part, as an entity in Farmington, Missouri. The description and dates of emails suggests that Victim 1 is likely Midwest Pain & Spine.
  • Victim 2 is described as a health records management firm. That one would be Quest Health Information Management Solutions. Of note, the government filing indicates that Victim 2 did pay ransom.
  • Victim 3 was described as having multiple locations in Missouri. That sounds like Prosthetic & Orthotic Care.
  • Victim 4 was described as a public accounting firm in St. Louis, whose owner’s first name is “David.” Although I never reported on this one publicly, it sounds like they are describing Smith Patrick LLC. TDO had informed me of that one and shown me some screenshots as proof. He had also tweeted something about this one but then removed the tweets.
  • Victim 5 is a medical clinic in Atlanta. For multiple reasons in the description of this victim, it seems clear that they are referring to the Athens Orthopedic Clinic case that I have reported on numerous times on this site.

These five victims are just a drop in the bucket for what TDO did while they were active (and I do not know if they are still active). We do not know how many other grand juries around the U.S. have also indicted Wyatt or what other charges he may face in the U.S.

The Eastern Missouri indictment does not indict any other individuals. If Wyatt is extradited and winds up facing a lot of time in a U.S. federal prison, will he flip on others?  TDO disappeared from public view in January 2019 after KickAss Forum shuttered its doors. Wyatt learned at the end of January that he would be extradited to the U.S. Is TDO’s continued disappearance since then connected to Wyatt’s extradition situation?

To be clear: Wyatt has not been charged with actually doing any hacking (at least not in this indictment). But he doesn’t have to be charged or convicted for actual hacking to face a lot of prison time. Think of Barrett Brown’s case to realize that conspiracy can be a serious matter.

One curious note:  Wyatt is being represented by Tucker Solicitors. That is a law firm that he is unlikely to be able to afford. In the past, Wyatt told this blogger that the royal family had retained those solicitors to represent him as they didn’t want the hacked pictures of Pippa Middleton coming out. This site could not confirm or refute Wyatt’s claim about that, but if he was telling the truth back then, is the royal family still paying Tucker Solicitors’ fees? DataBreaches.net reached out to the solicitors to ask them some other questions, but got no response at all, so that question hasn’t been put to them. [UPDATED Oct. 22:  Wyatt’s fiancee says that the royals are not paying the fees (see her comment below this post).

Tomorrow, the lawyers will argue their positions. The High Court panel can then issue a decision immediately or they may reserve judgment until a later date. It will be interesting to see what they decide and why.

Category: Breach IncidentsHackOf Note

Post navigation

← UK: Ex-Met detective loses court battle over payout for data breach
Major German manufacturer still down a week after getting hit by ransomware →

2 thoughts on “Tuesday: UK High Court will hear extradition appeal from alleged member of thedarkoverlord”

  1. K walker says:
    October 22, 2019 at 7:06 am

    The royal family are not covering the cost…
    This is fact.
    Tuckers were called by myself on the day he was arrested for this outside wandsworth prison.

    1. Dissent says:
      October 22, 2019 at 8:18 am

      Thanks for answering that.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks
  • Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • $28 million in Texas’ cybersecurity funding for schools left unspent
  • Cybersecurity incident at Central Point School District 6
  • Official Indiana .gov email addresses are phishing residents
  • Turkish Group Hacks Zero-Day Flaw to Spy on Kurdish Forces

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025
  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup
  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.