Skip to main content

Oh great, now scalpers are selling government appointments

Everyone knows about scalpers and their nefarious tricks, especially after their practices hit another gear amid the pandemic. But whereas previously these ne’er-do-wells were mostly limited to PC components and ridiculously expensive sneakers, they appear to have branched out in Israel to hoarding government appointments and selling them for profit.

According to cloud service company Akamai Technologies, the problem started when the Israeli Ministry of the Interior found itself with a massive backlog of 700,000 passport applications, which came about due to the lifting of pandemic restrictions on movement and the resultant travel boom.

Recommended Videos

To speed up the processing of all those people hungry for sightseeing, a team of independent software developers created a free appointment scheduling system called GamkenBot that would automatically book passport application appointments for those on the waiting list.

GamkenBot was made freely available to the public. Unfortunately, that gave bad actors the opportunity to nab it and modify it, allowing them to override its original purpose and scoop up every single available appointment for themselves.

The roguish malcontents then opened a Telegram group and started offering the appointments to the public — for a fee, of course. They even had the nerve to offer discounts if you bought two slots at once, even though the appointment system is meant to be entirely free.

You thought it was just passport applications?

A close-up of a MacBook illuminated under neon lights.
Image used with permission by copyright holder

It gets worse. Akamai notes that the same Telegram group has been selling appointments to “the Population Authority, Israel’s Electricity Corporation, the National Insurance, Israel Post, the Ministry of Transportation, and more.” In other words, the malicious actors’ greedy tentacles have spread to all manner of Israeli institutions, extracting cash from people who shouldn’t have to pay at all.

Akamai also suggests it could even pose a national security threat were the same thing to happen to other services. For instance, what if hospital procedures were similarly shut down and restricted, or if the registration of bus and truck drivers were halted? The country could potentially grind to a halt.

The original (well-meaning) developers tried to thwart their adversaries by implementing a CAPTCHA system, but this was bypassed in only a few days, suggesting the attackers had the means (or at least the motivation) to overcome this barrier. After all, the monetary rewards apparently speak for themselves.

If this whole sorry saga serves any purpose, it’s as a reminder that, despite GPU stocks returning to normal and prices dropping across the board, scalpers are still alive and well. If there’s money to be made, you can be sure they will try to rip people off as best they can.

Alex Blake
Alex Blake has been working with Digital Trends since 2019, where he spends most of his time writing about Mac computers…
This gorgeous Mac mini hub exacerbates the power button placement problem
M4 Mac mini with Satechi hub on a desk.

Satechi, known for its high-quality tech accessories, is updating its Mac mini hub for the new M4 model. Like previous hubs, it allows Mac mini owners to expand their storage and ports while preserving airflow, wireless signal, and performance. It looks awesome, but this time, the design highlights the problematic nature of the new Mac mini's placement of its power button.

With previous Mac mini models, the power button was at the back, making it easily accessible even when it was in a Satechi hub. The new button placement on the bottom of the PC, however, may prove even more annoying for anyone who wants to buy this accessory.

Read more
Proton VPN vs. Mullvad: Which is the best open-source VPN?
Proton VPN Plus and Mullvad websites appear in a split-screen on a PC monitor.

Open-source software is exploding in popularity and even virtual private networks (VPNs) share code for transparency. With over 100 million open-source developers contributing to the community, there’s an improved chance to find bugs and patch vulnerabilities.

Proton VPN and Mullvad are among the best VPNs available, and both are open-source solutions. You can browse the code used in Proton VPN and Mullvad on GitHub to check that there isn’t any secret logging or undisclosed data collection.

Read more
Some older D-Link routers are vulnerable to attack
D-Link Omna 180 Cam HD

A few legacy D-Link routers can be vulnerable to Remote Code Execution (RCE) attacks since the company refuses to send any updates to patch them up, claiming they have reached end-of-life, as recently posted on its announcement page.

The vulnerability is a serious issue since it allows hackers to take control from anywhere in the world and use a stack buffer overflow. This attack sends more data than the buffer size can handle, potentially corrupting critical information like the return address. Thus, hackers can take control of your PC. However, the company did not detail how the threat works, possibly not informing the hackers too much about the issue.

Read more