Crime ‘Your Cock Is Mine Now:’ Hacker Locks Internet-Connected Chastity Cage, Demands Ransom


'Your Cock Is Mine Now:’ Hacker Locks Internet-Connected Chastity Cage, Demands Ransom

Turns out giving an internet-connected device control of your penis may not be the best idea ever.

By Lorenzo Franceschi-Bicchierai
11.1.21

A hacker took control of people's internet-connected chastity cages and demanded a ransom to be paid in Bitcoin to unlock it.

"Your cock is mine now," the hacker told one of the victims, according to a screenshot of the conversation obtained by a security researcher that goes by the name Smelly and is the founder of vx-underground, a website that collects malware samples.

In October of last year, security researchers found that the manufacturer of an Internet of Things chastity cage—a sex toy that users put around their penis to prevent erections that is used in the BDSM community and can be unlocked remotely—had left an API exposed, giving malicious hackers a chance to take control of the devices. That's exactly what happened, according to a security researcher who obtained screenshots of conversations between the hacker and several victims, and according to victims interviewed by Motherboard.

A victim who asked to be identified only as Robert said that he received a message from a hacker demanding a payment of 0.02 Bitcoin (around $750 today) to unlock the device. He realized his cage was definitely "locked," and he "could not gain access to it."

"Fortunately I didn’t have this locked on myself while this happened," Robert said in an online chat.

"I wasn’t the owner of the cage anymore so I didn’t have full control over the cage at any given moment," another victim who goes by the name RJ told Motherboard in an online chat. RJ said he got a message from the hacker, who said they had control of the cage and wanted a payment to unlock it.

These hacks show once again that just because you can connect something to the internet, it doesn't mean you have to—especially if you then don't take care of securing the device or its connection. It's incidents like these that make some people think the Internet of Things is just a marketing term for the Internet of Hackable Things, as we call it, or even the Internet of Shit, as others call it.

Qiui, the China-based manufacturer of the device, which is aptly called Cellmate, did not respond to a request for comment.

Alex Lomas, a security researcher at Pentest Partners, who audited the Cellmate device, confirmed that some users received the extortion messages, and said this highlights the need for better security practices.

"Almost every company and product is going to have some kind of vulnerability in its lifetime. Maybe not as bad as this one, but something," Lomas said in an online chat. "It’s important that all companies have a way for researchers to contact them, and that they keep in touch with them."

As usual, be careful what devices you trust with your data or, in this case, with your genitals.
 
Anyone who bought not just a regular chastity cage but a deluxe internet connected, app requiring model deserves to have their junk held hostage for Bitcoin.

Once upon a time fuzzy handcuffs or a flog were the wildest things you'd find in the bedroom. Why you would need an IoT cock cage is beyond me.
 
I can't be the only one to read the thread title in the TF2 Soldier's voice, right?
Cyberpunk we didn't need, but deserved nonetheless. In some 10-12 years, people will hack each other's internet-connected genitals with implants to give random boners/orgasms or dysfunctions.
Or make it self-destruct. The sky is the limit.
 
Didn't we already have this article? Or was that just the vulnerability and now the guy's actually got his dick held ransom?
I think there was an article highlighting its existence, and here we are at the logical conclusion.

We all laugh now, but any “internet of things” tech has identical vulnerability. Imagine waking up one day to find your fridge is holding your eggs and orange juice ransom.
 
Back