Alexandre Cazes
   HOME

TheInfoList



OR:

AlphaBay was a
darknet market A darknet market is a commercial website on the dark web that operates via darknets such as Tor and I2P. They function primarily as black markets, selling or brokering transactions involving drugs, cyber-arms, weapons, counterfeit currency, ...
operating at different times between September 2014 and February 2023. At times, it was both an
onion service Tor is a free overlay network for enabling anonymous communication. It is built on free and open-source software run by over seven thousand volunteer-operated relays worldwide, as well as by millions of users who route their Internet traff ...
on the
Tor network Tor is a free overlay network for enabling anonymous communication. It is built on free and open-source software run by over seven thousand volunteer-operated relays worldwide, as well as by millions of users who route their Internet traffic ...
and an I2P node on
I2P The Invisible Internet Project (I2P) is an anonymous network layer (implemented as a mix network) that allows for censorship-resistant, peer-to-peer communication. Anonymous connections are achieved by encrypting the user's traffic (by usin ...
. After it was shut down in July 2017 following law enforcement action in the United States, Canada, and Thailand as part of Operation Bayonet, it was relaunched in August 2021 by the self-described co-founder and security administrator DeSnake. The alleged original founder, Alexandre Cazes, a Canadian citizen born on 19 October 1991, was found dead in his cell in Thailand several days after his arrest, with police suspecting
suicide Suicide is the act of intentionally causing one's own death. Risk factors for suicide include mental disorders, physical disorders, and substance abuse. Some suicides are impulsive acts driven by stress (such as from financial or ac ...
.


History

AlphaBay reportedly launched in September 2014, pre-launched in November 2014 and officially launched on December 22, 2014. It saw a steady growth, with 14,000 new users in the first 90 days of operation. In October 2015, it was recognized as the largest online darknet market according to Dan Palumbo, research director at
Digital Citizens Alliance The Digital Citizens Alliance is a United States non-profit organization focused on internet safety issues. It releases reports focused on malware, credit card theft, online drug sales to teens, piracy, and overall Internet consumer safety. In ...
. Non-standard services included customizable digital contracts around building reputations. In May 2015, the site announced an integrated digital contracts and escrow system. The contract system allows users to make engagements and agree to provide services in the future, according to the terms of the
contract A contract is an agreement that specifies certain legally enforceable rights and obligations pertaining to two or more parties. A contract typically involves consent to transfer of goods, services, money, or promise to transfer any of thos ...
. By October 2015, AlphaBay had over 200,000 users, and a claimed 40,000 sellers. At the time of its demise in July 2017, AlphaBay had over 400,000 users, and around 300,000 listed items on their website. In addition to
bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
, AlphaBay implemented support for
Monero Monero (; Abbreviation: XMR) is a cryptocurrency which uses a blockchain with privacy-enhancing technologies to obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses trading Monero, transaction amount ...
in August 2016. It also accepted
Ethereum Ethereum is a decentralized blockchain with smart contract functionality. Ether (abbreviation: ETH) is the native cryptocurrency of the platform. Among cryptocurrencies, ether is second only to bitcoin in market capitalization. It is open-s ...
.


Site breaches

In April 2016, AlphaBay's
API An application programming interface (API) is a connection between computers or between computer programs. It is a type of software interface, offering a service to other pieces of software. A document or standard that describes how to build ...
was compromised, leading to 13,000 messages being stolen. In January 2017, the API was once again compromised, allowing over 200,000 private messages from the last 30 days and a list of usernames to be leaked. The attack was from a single
hacker A hacker is a person skilled in information technology who achieves goals and solves problems by non-standard means. The term has become associated in popular culture with a security hackersomeone with knowledge of bug (computing), bugs or exp ...
who was paid by AlphaBay for the disclosure. AlphaBay reported that the exploit had only been used in conjunction with this attack and not used previously.


News coverage

On March 28, 2015, AlphaBay Market made the news for selling stolen
Uber Uber Technologies, Inc. is an American multinational transportation company that provides Ridesharing company, ride-hailing services, courier services, food delivery, and freight transport. It is headquartered in San Francisco, California, a ...
accounts. Uber made a statement regarding a potential data breach:
"We investigated and found no evidence of a breach. Attempting to fraudulently access or sell accounts is illegal and we notified the authorities about this report. This is a good opportunity to remind people to use strong and unique usernames and passwords and to avoid reusing the same credentials across multiple sites and services."
In October 2015, the London-based
telecommunications Telecommunication, often used in its plural form or abbreviated as telecom, is the transmission of information over a distance using electronic means, typically through cables, radio waves, or other communication technologies. These means of ...
company TalkTalk sustained a major hack. The stolen data was put for sale on AlphaBay Market, which led to the arrest of a 15-year-old boy. TalkTalk
CEO A chief executive officer (CEO), also known as a chief executive or managing director, is the top-ranking corporate officer charged with the management of an organization, usually a company or a nonprofit organization. CEOs find roles in variou ...
Dido Harding Diana Mary "Dido" Harding, Baroness Harding of Winscombe (born November 1967) is a British businesswoman and life peer who served as chair of NHS Improvement from 2017 to 2021, and as interim chief executive of the UK Health Security Agency (UK ...
issued the following statement:
"TalkTalk constantly updates its systems to make sure they are as secure as possible against the rapidly evolving threat of cyber crime, impacting an increasing number of individuals and organisations. We take any threat to the security of our customers' data extremely seriously and we are taking all the necessary steps to understand what has happened here."
In August 2017, AlphaBay was revealed as a possible venue by which one of the perpetrators of the 2017 Jewish Community Center bomb threats may have sold a "School Email Bomb Threat Service." This individual, Michael Kadar, made 245 threatening calls to schools and community centers. Criminologist David Decary-Hetu noted this event as notable for being the first example of criminal services being sold over a darkmarket. He said, "All the cases I have heard of so far turned out to be law enforcement trying to find people of interest," making this case unique in his experience to that point.


Seizure and shutdown

By July 2017, AlphaBay was ten times the size of its predecessor
Silk Road The Silk Road was a network of Asian trade routes active from the second century BCE until the mid-15th century. Spanning over , it played a central role in facilitating economic, cultural, political, and religious interactions between the ...
(which was busted in October 2013), had over 369,000 listings, 400,000 users, was facilitating US$600,000-$800,000 of transactions per day, and had reportedly built a strong reputation. However, a series of elementary
operational security Operations security (OPSEC) is a process that identifies critical information to determine whether friendly actions can be observed by enemy intelligence, determines if information obtained by adversaries could be interpreted to be useful to th ...
errors led to its downfall: * About the time the service first began in December 2014, Cazes used his
Hotmail Outlook.com, formerly Hotmail, is a free personal email service offered by Microsoft. It also provides a webmail interface accessible via web browser or mobile apps featuring mail, Calendaring software, calendaring, Address book, contacts, and ...
address ''pimp_alex_91@hotmail.com'' as the 'From' address in system-generated welcome and password reset emails, which he also used for his
LinkedIn LinkedIn () is an American business and employment-oriented Social networking service, social network. It was launched on May 5, 2003 by Reid Hoffman and Eric Ly. Since December 2016, LinkedIn has been a wholly owned subsidiary of Microsoft. ...
profile and his legitimate computer repair business in Canada. * Cazes used a
pseudonym A pseudonym (; ) or alias () is a fictitious name that a person assumes for a particular purpose, which differs from their original or true meaning ( orthonym). This also differs from a new name that entirely or legally replaces an individual's o ...
, Alpha02, to run the site which he had previously used (e.g., in carding and tech forums) since at least 2008, and variously advertised this identity as the "designer", "administrator" and "owner" of the site. * When Cazes was arrested, he was logged into his laptop performing an administrative reboot on an AlphaBay server in direct response to a law-enforcement-created artificial system failure; furthermore, encryption was wholly absent on that laptop. * Cazes' laptop reportedly contained an unencrypted personal net worth statement mapping all global assets across multiple jurisdictions, conveniently leading police to complete asset seizure. * The servers were hosted at a company in Canada directly linked to his person. * The servers contained multiple constantly open (unencrypted) hot cryptocurrency wallets. * Cazes' flashy use of proceeds to purchase property, passports and luxury cars and frequent online boasting about his financial successes, including posting videos of himself driving luxury cars acquired through illegal proceeds, not only revealed his geographical location, but also made denying connection to the service impossible. * Assets acquired through proceeds were held in a variety of accounts directly linked to Cazes, his wife and companies they owned in Thailand (the jurisdiction in which they lived), as well as directly held personal accounts in Liechtenstein, Cyprus, Switzerland and Antigua. * Cazes' statements about the goal of the site — "launched in September 2014 and its goal is to become the largest eBay-style underworld marketplace" — helped to legally establish intent.


Timeline

Law enforcement took at least one month to obtain a US warrant, then over one month to obtain foreign warrants, prepare for and execute searches and seizures in Canada and Thailand: *Early May 2017: Law Enforcement verifiably active on the site since at least this period. *1 June 2017: Warrant issued by United States District Court for the Eastern District of California for racketeering, narcotics trafficking, identity theft and access device fraud, transfer of false ID, trafficking in illegal device making equipment, and conspiracy to commit
money laundering Money laundering is the process of illegally concealing the origin of money obtained from illicit activities (often known as dirty money) such as drug trafficking, sex work, terrorism, corruption, and embezzlement, and converting the funds i ...
. *30 June 2017: Warrant is issued for Cazes' arrest in Thailand at US request. *5 July 2017 **Canadian police raid ''EBX Technologies'' in Montreal, Cazes' Canadian company and the reported location of the physical servers, as well as two residential properties in Trois-Rivières. **Cazes is arrested in Bangkok at his dwelling at Phutthamonthon Sai 3 Road in Thawi Watthana district which is searched by the Royal Thai Police, with the help of the FBI and DEA. *12 July 2017: Cazes' suspected suicide by hanging while in custody at Thailand's Narcotics Suppression Bureau headquarters in Laksi district, Bangkok, was reportedly discovered at 7AM. He was due to face US extradition. *16 July 2017: Cazes' wife was reported as having been charged with
money laundering Money laundering is the process of illegally concealing the origin of money obtained from illicit activities (often known as dirty money) such as drug trafficking, sex work, terrorism, corruption, and embezzlement, and converting the funds i ...
. *20 July 2017; U.S. Attorney General
Jeff Sessions Jefferson Beauregard Sessions III (born December 24, 1946) is an American politician and attorney who served as the 84th United States attorney general from 2017 to 2018. A member of the Republican Party, he previously served as United Stat ...
announces shutdown of the site. *23 July 2017: Narcotics Suppression Bureau chief is interviewed and suggests that more suspects will be arrested soon.


Relaunch

AlphaBay was relaunched as early as 8 August 2021. Details of the new operation surfaced after a conversation between ''
Wired Wired may refer to: Arts, entertainment, and media Music * ''Wired'' (Jeff Beck album), 1976 * ''Wired'' (Hugh Cornwell album), 1993 * ''Wired'' (Mallory Knox album), 2017 * "Wired", a song by Prism from their album '' Beat Street'' * "Wired ...
'' and a user with the same verified
public key Public-key cryptography, or asymmetric cryptography, is the field of cryptographic systems that use pairs of related keys. Each key pair consists of a public key and a corresponding private key. Key pairs are generated with cryptographic alg ...
as a former site administrator for AlphaBay. Using the alias DeSnake, the former vendor and self-described co-founder of the original AlphaBay now claims to operate the marketplace, placing a higher emphasis on
operations security Operations security (OPSEC) is a process that identifies critical information to determine whether friendly actions can be observed by enemy intelligence, determines if information obtained by adversaries could be interpreted to be useful to th ...
than the previous administration, stating "there is no overkill" regarding the site. As part of the site's relaunch, multiple new features have been advertised and new rules announced. Notable among new features are AlphaGuard (which allegedly prevents users from losing funds even if seizures on all servers occur at the same time), an automatic system to resolve disputes between buyers and sellers, exclusive use of
Monero Monero (; Abbreviation: XMR) is a cryptocurrency which uses a blockchain with privacy-enhancing technologies to obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses trading Monero, transaction amount ...
wallets, and the offering of
I2P The Invisible Internet Project (I2P) is an anonymous network layer (implemented as a mix network) that allows for censorship-resistant, peer-to-peer communication. Anonymous connections are achieved by encrypting the user's traffic (by usin ...
mirrors. Concerning rules, items newly prohibited from sale include
COVID-19 vaccine A COVID19 vaccine is a vaccine intended to provide acquired immunity against severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2), the virus that causes coronavirus disease 2019 ( COVID19). Knowledge about the structure and fun ...
s,
firearms A firearm is any type of gun that uses an explosive charge and is designed to be readily carried and operated by an individual. The term is legally defined further in different countries (see legal definitions). The first firearms originated ...
, products containing the narcotic
fentanyl Fentanyl is a highly potent synthetic piperidine opioid primarily used as an analgesic (pain medication). It is 30 to 50 times more Potency (pharmacology), potent than heroin and 50 to 100 times more potent than morphine. Its primary Medici ...
, pornography, and "hitman services". Furthermore, there is a ban on discussions of any public or private information related to the governments, organizations, or people of
Russia Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
,
Belarus Belarus, officially the Republic of Belarus, is a landlocked country in Eastern Europe. It is bordered by Russia to the east and northeast, Ukraine to the south, Poland to the west, and Lithuania and Latvia to the northwest. Belarus spans an a ...
,
Kazakhstan Kazakhstan, officially the Republic of Kazakhstan, is a landlocked country primarily in Central Asia, with a European Kazakhstan, small portion in Eastern Europe. It borders Russia to the Kazakhstan–Russia border, north and west, China to th ...
,
Armenia Armenia, officially the Republic of Armenia, is a landlocked country in the Armenian Highlands of West Asia. It is a part of the Caucasus region and is bordered by Turkey to the west, Georgia (country), Georgia to the north and Azerbaijan to ...
, and
Kyrgyzstan Kyrgyzstan, officially the Kyrgyz Republic, is a landlocked country in Central Asia lying in the Tian Shan and Pamir Mountains, Pamir mountain ranges. Bishkek is the Capital city, capital and List of cities in Kyrgyzstan, largest city. Kyrgyz ...
. This has led to loose speculation that there is a connection between the site operators and the governments of these nations. In early February 2023, the market went into lockdown, preventing users with
2FA Multi-factor authentication (MFA; two-factor authentication, or 2FA) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more distinct types of evidence ...
verification from logging in. Accounts affected included all of the site staff and vendors. As admin team member TheCypriot explained in a
Reddit Reddit ( ) is an American Proprietary software, proprietary social news news aggregator, aggregation and Internet forum, forum Social media, social media platform. Registered users (commonly referred to as "redditors") submit content to the ...
post, the site went into partial lockdown due to one of its canaries not being signed in time by DeSnake. They did not reappear to rectify the problem and have not been heard from since. With its owner missing and staff unable to sign the canary to lift the lockdown themselves, Alphabay de facto ceased operations. While a number of theories about the disappearance have been proposed, none have been substantiated with evidence.


References


Further reading

* * * * * * {{Portal bar, Internet, Anarchism, Thailand Internet properties established in 2014 Tor onion services Carding (fraud) Internet properties disestablished in 2017 Defunct darknet markets