Tech CEO Sentenced to 5 Years in IP Address Scheme – Krebs on Security

By admin

Amir Golestan
PERSON

, the

40-year-old
DATE

CEO of the

Charleston
GPE

,

S.C.
GPE

based technology company

Micfo LLC
ORG

, has been sentenced to

five years
DATE

in prison for wire fraud.

Golestan
GPE

’s sentencing comes

nearly two years
DATE

after he pleaded guilty to using an elaborate network of phony companies to secure

more than 735,000
CARDINAL

Internet Protocol (IP) addresses from

the American Registry for Internet Numbers (ARIN)
ORG

, the nonprofit which oversees

IP
ORG

addresses assigned to entities in the

U.S.
GPE

,

Canada
GPE

, and parts of the

Caribbean
LOC

.

In

2018
DATE

,

ARIN
GPE

sued

Golestan
GPE

and

Micfo
NORP

, alleging they had obtained

hundreds of thousands
CARDINAL

of IP addresses under false pretenses. ARIN and

Micfo
NORP

settled that dispute in arbitration, with

Micfo
NORP

returning most of the addresses that it hadn’t already sold.


ARIN
PERSON

’s civil case caught the attention of federal prosecutors in

South Carolina
GPE

, who in

May 2019
DATE

filed criminal wire fraud charges against

Golestan
GPE

, alleging he’d orchestrated a network of shell companies and fake identities to prevent

ARIN
FAC

from knowing the addresses were all going to the same buyer.

Prosecutors showed that each of those shell companies involved the production of notarized affidavits in the names of people who didn’t exist. As a result, the government was able to charge

Golestan
GPE

with

20
CARDINAL

counts of wire fraud — one for each payment made by the phony companies that bought the

IP
ORG

addresses from

ARIN
GPE

.


Golestan
GPE

initially sought to fight those charges. But on just the

second
ORDINAL

day of his trial in

November 2021
DATE

,

Golestan
GPE

changed his mind and pleaded guilty to

20
CARDINAL

counts of wire fraud in connection with the phantom companies he used to secure the IP addresses. Prosecutors estimated those addresses were valued at

between $10 million and $14 million
MONEY

.


ARIN
PERSON

says the

5-year
DATE

sentence handed down by the

South Carolina
GPE

judge “sends an important message of deterrence to other parties contemplating fraudulent schemes to obtain or transfer Internet resources.”

“Those who seek to defraud

ARIN
PERSON

(or other Regional Internet Registries) are subject to costly and serious civil litigation, criminal charges, and, ultimately, a lengthy term of incarceration,” reads a statement from

ARIN
GPE

on

Golestan
GPE

’s sentencing.

By

2013
DATE

, a number of

Micfo
NORP

’s customers had landed on the radar of

Spamhaus
ORG

, a group that many network operators rely upon to stem the tide of junk email. Shortly after

Spamhaus
ORG

started blocking

Micfo
PRODUCT

’s IP address ranges,

Micfo
NORP

shifted gears and began reselling IP addresses mainly to companies marketing “virtual private networking” or VPN services that help customers hide their real IP addresses online.


Golestan
GPE

did not respond to a request for comment. But in a

2020
DATE

interview with

KrebsOnSecurity
ORG

,

Golestan
GPE

claimed that

Micfo
NORP

was at

one
CARDINAL

point responsible for brokering

roughly 40 percent
PERCENT

of the IP addresses used by the world’s largest VPN providers. Throughout that conversation,

Golestan
GPE

maintained his innocence, even as he explained that the creation of the phony companies was necessary to prevent entities like

Spamhaus
ORG

from interfering with his business going forward.

There are

fewer than four billion
MONEY

so-called “Internet

Protocol
LAW

version

4
CARDINAL

” or IPv4 addresses available for use, but the vast majority of them have already been allocated. The global dearth of available IP addresses has turned them into a commodity wherein each IPv4 address can fetch

between $15-$25
MONEY

on the open market.

This has led to boom times for those engaged in the acquisition and sale of IP address blocks, but it has likewise emboldened those who specialize in absconding with and spamming from dormant IP address blocks without permission from the rightful owners.


The U.S Department of Justice
ORG

says

Golestan
GPE

will serve

60 months
DATE

in prison, followed by a

2-year
DATE

term of court-ordered supervision. The

Micfo
NORP

CEO also was ordered to pay

nearly $77,000
MONEY

in restitution to

ARIN
ORG

for its work in assisting federal prosecutors.