# Mexican Cartel Hacked FBI Agent's Phone to Hunt Down Informants

Source: https://www.youtube.com/watch?v=qU6ZQRSYusQ
Recap page: https://rapidrecap.app/video/qU6ZQRSYusQ
Generated: 2025-07-17T07:34:07.448+00:00

---
## Quick Overview

The Sinaloa Cartel hired a hacker to exploit an FBI agent's phone and Mexico City's camera system, gathering intelligence to intimidate or kill potential sources and cooperating witnesses in the "El Chapo" drug cartel case. This unprecedented targeting of an FBI agent was revealed through a cartel snitch. Additionally, Russian state-backed hackers employed a sophisticated phishing technique bypassing multi-factor authentication by tricking a British expert into generating and sharing an app-specific Google password. Separately, a former US Army sergeant attempted to leak top-secret military intelligence to China, but his amateurish attempts were unsuccessful, leading to his arrest and a potential 10-year prison sentence. Finally, tech support scammers are now hijacking Google search results with malicious ads that inject fake phone numbers into legitimate company help pages, tricking users into calling them and demanding gift card payments.

**Key Points:**
- The Sinaloa Cartel hired a hacker to compromise an FBI agent's phone and Mexico City's surveillance system, using the gathered intelligence to intimidate or kill informants.
- A cartel insider provided the FBI with information about the operation, revealing the extent of the cartel's cyber capabilities.
- Russian state-backed hackers successfully used a novel phishing technique to gain full access to a British expert's Google account by tricking him into generating and sharing an app-specific password.
- A former US Army sergeant with top-secret clearance attempted to leak classified military information to China, but his efforts were largely unsuccessful due to his lack of operational security.
- The sergeant's motive for attempting to leak secrets was a deep-seated disillusionment with the American government, rather than financial gain.
- Tech support scammers are now employing 'malvertising' by placing sponsored Google ads that inject fake phone numbers into legitimate company help pages, tricking users into calling them.
- The FBI recommends installing ad blockers to protect against these malicious search ads, which exploit the difficulty many users face in finding genuine customer support contacts.

![Screenshot at 0:00: A group of armed men in a jungle setting, with a 'C.D.S CARTEL DE SINALOA' logo overlaid, representing the cartel's involvement.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-00-00.png)

**Context:** In a series of recent cybersecurity incidents, major threats have emerged from unexpected corners. The Sinaloa Cartel has demonstrated advanced cyber capabilities by targeting a US federal agent, while Russian state-backed actors have refined their phishing tactics to bypass common security measures. Concurrently, a former US military intelligence officer attempted to betray his country by leaking classified information to a foreign adversary, highlighting insider threats. These events underscore the evolving and diverse landscape of cyber warfare and espionage, impacting both national security and everyday citizens.

## Detailed Analysis

A heavily redacted FBI report revealed that in 2018, the Sinaloa Cartel, Mexico's largest, hired a hacker to target an FBI Assistant Legal Attaché (ALAT) involved in the "El Chapo" drug cartel case. The hacker exploited the ALAT's mobile phone to access call logs and geolocation data, and also compromised Mexico City's extensive camera system (80,000 CCTV cameras) to visually track the agent and identify individuals they met. This intelligence was then used by the cartel to intimidate or kill potential sources and cooperating witnesses. The FBI learned of this operation from an individual connected to the cartel. In other cybersecurity news, Russian government-linked hackers developed a novel phishing technique targeting a prominent British expert on Russia. They sent a spoofed email from a fake US Department of State advisor, inviting him to an online meeting. The email cleverly CC'd non-existent state.gov addresses to appear legitimate. When the expert responded, the hackers sent a PDF instructing him to generate and share a Google app-specific password, which bypasses multi-factor authentication, granting them full access to his Google account. Google's Threat Intelligence Group later identified and blocked the attack. Furthermore, a former US Army sergeant with top-secret clearance, Joseph Daniel Schmidt, pleaded guilty to attempting to share military secrets with China. After leaving the military in 2020, Schmidt conducted extensive Google searches on defection, countries with negative US relations, and China's intelligence agencies. He emailed the Chinese Embassy in Istanbul, openly offering classified information and his SIPR token (a smart card for a private DoD network). He also contacted Chinese state media. Despite his efforts, Chinese authorities did not take him seriously, and he was eventually arrested upon his return to the US, facing up to 10 years in prison. Lastly, a new wave of "malvertising" is targeting unsuspecting users, particularly older generations. Scammers are placing sponsored ads on Google search results that appear legitimate, even using correct domains like help.netflix.com. However, clicking these ads redirects users to a copycat site where a fake phone number is injected into the search bar of the genuine help page. This tricks users into calling the scammers, who then demand gift cards to "fix" their issues. This tactic has been observed targeting major companies like Netflix, Bank of America, Microsoft, HP, and Apple, prompting the FBI to recommend installing ad blockers.

### Mexican Cartel Cyber Espionage

- The Sinaloa Cartel hired a hacker in 2018 to target an FBI Assistant Legal Attaché (ALAT) during the "El Chapo" drug cartel case
- The hacker exploited the ALAT's mobile phone to obtain call logs and geolocation data
- The hacker also accessed Mexico City's 80,000-camera surveillance system to track the ALAT and identify contacts
- The cartel used this intelligence to intimidate and/or kill potential sources and cooperating witnesses
- The FBI discovered this operation through a cartel informant.

### Russian Phishing Innovation

- Russian state-backed hackers targeted British expert Keir Giles with a sophisticated phishing email impersonating a US Department of State advisor
- The email used legitimate-looking CC'd state.gov addresses that were non-existent or configured not to send delivery failure notifications, enhancing its credibility
- The attack leveraged a little-known Google App Passwords feature, tricking the victim into generating a 16-digit code that bypasses multi-factor authentication and grants full account access
- Google's Threat Intelligence Group (GTIG) identified and blocked the attack, attributing it to Russian state-backed actors.

### US Army Sergeant's Failed Espionage

- Former US Army Sergeant Joseph Daniel Schmidt, with top-secret clearance, attempted to leak military secrets to China after leaving the service in 2020
- Schmidt conducted extensive Google searches on defection, countries with negative US relations, and China's intelligence agencies
- He openly emailed the Chinese Embassy in Istanbul and Chinese state media, offering classified information and his SIPR token
- Schmidt's motive stemmed from a disillusionment with the American government, stating he learned "terrible things" while in the Army
- Despite his efforts, Chinese authorities did not engage with him, and he was arrested upon returning to the US, pleading guilty to attempting to share military secrets.

### Malvertising and Tech Support Scams

- Malicious Google search ads, or "malvertising," are redirecting users to fake websites or injecting scammer phone numbers into legitimate help pages
- These ads appear highly credible, often using the correct domain names in the sponsored listing
- Clicking the ad leads to a URL that bakes the scammer's phone number into the search query of a genuine help center page, making it appear as the official contact
- Scammers then trick victims into calling these numbers and demanding payment, often in the form of gift cards, to "resolve" their technical issues
- This tactic targets major companies like Netflix, Bank of America, Microsoft, HP, and Apple, exploiting the difficulty many users face in finding legitimate customer support numbers.

![Screenshot at 0:00: A group of armed men in a jungle setting, with a 'C.D.S CARTEL DE SINALOA' logo overlaid, representing the cartel's involvement.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-00-00.png)
![Screenshot at 0:32: A highlighted section of an FBI report detailing how the cartel hired a hacker who offered a 'menu of services related to exploiting mobile phones and other electronic devices'.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-00-32.png)
![Screenshot at 0:44: A street view of the US Embassy in Mexico City, where the hacker observed people and identified targets, including an FBI agent.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-00-44.png)
![Screenshot at 1:31: A large control room with multiple screens displaying CCTV feeds, representing Mexico City's extensive surveillance system that the hacker accessed.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-01-31.png)
![Screenshot at 2:46: An email from 'Claudie S Weber' (impersonating a US DoS advisor) inviting Keir Giles to a 'Private Online Conversation', highlighting the phishing attempt.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-02-46.png)
![Screenshot at 3:41: The cover page of a seemingly legitimate PDF document titled 'Joining External Gmail Users to US DoS Guest O365 Tenant', used by hackers to trick the victim.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-03-41.png)
![Screenshot at 4:30: A Google account pop-up showing a 'Generated app password', illustrating the dangerous app-specific password feature exploited by the hackers.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-04-30.png)
![Screenshot at 5:57: An email from 'Joe Schmidt' to the Chinese consulate, openly stating his identity, top-secret clearance, and desire to share information learned in the Army.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-05-57.png)
![Screenshot at 7:24: Two mobile phone screenshots showing Google Maps directions from Beijing Daxing International Airport to the 'Ministry of State Security of the People's Republic of China', indicating Schmidt's travel and intent.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-07-24.png)
![Screenshot at 9:17: A screenshot of the Netflix Help Center page with a highlighted search bar containing a scammer's phone number, demonstrating the search hijacking technique.](https://ss.rapidrecap.app/screens/qU6ZQRSYusQ/00-09-17.png)
