A rush to make registering deaths digital has made it simple for maliciously-minded hackers to have someone who is alive declared dead by authorities, an Australian computer security expert says.
Getting birth certificates for virtual babies was demonstrated to be even easier than killing off people in the digital world, because registering births online only involves doctors and parents.
Hackers at the infamous annual Def Con gathering in Las Vegas on Friday got schooled in how to be online killers.
“This is a global problem,” Australian computer security specialist Chris Rock said, as he launched a presentation titled I Will Kill You.
The process of having someone officially stamped dead by getting a death certificate issued typically involves a doctor filling out one form and a funeral home filling out another, according to Mr Rock’s research.
Once forms are submitted online, certificates declaring the listed person legally dead are generated.
A fatal flaw in the system is that people can easily pose as real doctors and funeral directors, Mr Rock demonstrated.
Doctors practising general medicine often do not bother setting up accounts at online portals for filling out information for death certificates.
An aspiring online assassin can step into that void, and borrow the identity of a doctor.
“Once you log on as a doctor, not only can you kill someone, you can actually birth someone,” Mr Rock said.
Given the time it takes for even a make-believe baby to grow into adulthood, he saw that as more tempting to crime gangs who could invest in the future by creating legions of virtual people for shady doings involving loans, stock trading or other activities.
“You could even make fake identities for your children, so when they grow up they have burner identities,” Mr Rock said.
Hackers can create doctor, funeral director identities: expert
The computer security expert began digging into the death industry only a year ago after Melbourne’s Austin Hospital declared 200 patients dead.
Setting up accounts requires a doctor’s name, address, and medical licence number.
A basic internet search will turn up that information, which is publicly available for the well-intended purpose of letting people check that physicians are legitimate before seeking care.
Drop-down boxes containing illness categories and online guides are available for filling in “doctor speak” on forms and avoiding medical causes or circumstances that might trigger needs for autopsies or investigations, Mr Rock’s demonstration showed.
Borrowing a funeral director’s identity to establish an online account for death certificates was shown to be simple as well.
Required information about legitimate funeral directors is posted on the internet, and one could even claim to work at a funeral home.
In Mr Rock’s demonstration, he made a website for a bogus funeral home and used that to back his application for an account as director. He got an automated call days later saying he was approved.
With both online accounts in place, deaths can be registered in the real world.
“You could kill anyone you want,” Mr Rock said after the presentation, “No one is off limits”.
A humour-infused list of scenarios included killing oneself off to get life insurance cash, or going after others for vengeance.
A target might not even know they were declared dead until doing something official such as trying to renew a passport or driving licence.