Who has filed a Section 205 Subpoena against an ISP

MagicDude4Eva

Banned
Joined
Apr 2, 2008
Messages
6,477
Reaction score
40
Location
Jo'burg
Has anyone been able to file a 205 against an ISP to obtain subscriber information? Currently going down this road (against MWEB) and it is unbelievable how ISPs harbor criminals (not just MWEB, but other DSL ISPs as well - but most cases are tracked back to MWEB nowadays). Quite a double standard when ISPs send out DMCA notifications on behalf of companies who have no jurisdiction (or legal grounds) in SA but then turn a blind eye on fraud committed on their infrastructure.

This will be an interesting case in the online ecommerce and will probe both RICA and ISPs. It's one thing to protect customer privacy and data, but it's another to tell an ISP that their customer commits fraud of a significant commercial value as dozes of cases of identity fraud.

If anyone has first hand experience with 205, post here or PM me - it does seem that abuse-departments at ISPs are just fluff...
 
an ISP is not going to ignore a court-issued document - the s205 process happens frequently and afaik the process is generally smooth

what, precisely, is the issue?
 
We had an issue last year where a person attempted to hack and disrupt services which we offered on Mweb servers. Mweb's legal department had no issue helping us at all.
 
@froot I remember the instance RiG servers where being attacked.. MWEB was quite helpful to myself and TwitCh! at the time
 
an ISP is not going to ignore a court-issued document - the s205 process happens frequently and afaik the process is generally smooth

what, precisely, is the issue?

Will disclose the finer details around the issue once the 205 has been filed and we have been able to lay proper charges against all involved. Without disclosing too much information: We know that a criminal uses MWEB's DSL services to sabotage our ecommerce platform and have informed them about the criminal activities performed by one of their subscribers (including a paper-trail of proof). While one does not expect disclosing customer information without a 205, I would expect the ISP to issue warnings or suspend the customers account or start an internal investigation - none of this has happened.

I think ISPs need to start becoming accountable for knowingly tolerating criminal activities of their customers without any recourse (until a 205 is produced). I guess it will play out like this:
- Serve 205 to ISP
- Get all sorts of fake personal information, but also get a valid landline number since it is ADSL
- Have to issue another 205 against Telkom
- Find out in the worst case, that the landline is someones unprotected Wifi router
- Lay criminal charges against that innocent person in order to seize equipment for forensics
- Find the person responsible or just give up

Win big: If your current MWEB IP happens to be 41-132-74-190.dsl.mweb.co.za - please contact me for a big surprise win - only valid for next 24 hours :whistle:
 
Last edited:
The ISPs will not respond to you but they will give the information to the investigating officer (SAP) who serves them the 205.
AFIK
BTW this whole process is covered in RICA
 
Last edited:
Has anyone been able to file a 205 against an ISP to obtain subscriber information? Currently going down this road (against MWEB) and it is unbelievable how ISPs harbor criminals (not just MWEB, but other DSL ISPs as well - but most cases are tracked back to MWEB nowadays). Quite a double standard when ISPs send out DMCA notifications on behalf of companies who have no jurisdiction (or legal grounds) in SA but then turn a blind eye on fraud committed on their infrastructure.

This will be an interesting case in the online ecommerce and will probe both RICA and ISPs. It's one thing to protect customer privacy and data, but it's another to tell an ISP that their customer commits fraud of a significant commercial value as dozes of cases of identity fraud.

If anyone has first hand experience with 205, post here or PM me - it does seem that abuse-departments at ISPs are just fluff...

Will disclose the finer details around the issue once the 205 has been filed and we have been able to lay proper charges against all involved. Without disclosing too much information: We know that a criminal uses MWEB's DSL services to sabotage our ecommerce platform and have informed them about the criminal activities performed by one of their subscribers (including a paper-trail of proof). While one does not expect disclosing customer information without a 205, I would expect the ISP to issue warnings or suspend the customers account or start an internal investigation - none of this has happened.

I think ISPs need to start becoming accountable for knowingly tolerating criminal activities of their customers without any recourse (until a 205 is produced). I guess it will play out like this:
- Serve 205 to ISP
- Get all sorts of fake personal information, but also get a valid landline number since it is ADSL
- Have to issue another 205 against Telkom
- Find out in the worst case, that the landline is someones unprotected Wifi router
- Lay criminal charges against that innocent person in order to seize equipment for forensics
- Find the person responsible or just give up

Win big: If your current MWEB IP happens to be 41-132-74-190.dsl.mweb.co.za - please contact me for a big surprise win - only valid for next 24 hours :whistle:

Hi MagicDude4Eva

I would like more information with regards to what you are saying and provide it to our abuse team to look into more.

Have you mailed our abuse team already? If yes, from what email address did you send the mail? We already have your account details from previous communications.

We would like to assist you with regards to this.
 
Hi MagicDude4Eva

I would like more information with regards to what you are saying and provide it to our abuse team to look into more.

Have you mailed our abuse team already? If yes, from what email address did you send the mail? We already have your account details from previous communications.

We would like to assist you with regards to this.

Thanks - we have been in contact with your Abuse department and we have received feedback from Richard today that the user's account has been terminated. This has assisted us greatly since that specific case was ongoing for 3 weeks without any real prompt action. I do hope that your team has proper data-retention policies in place, as we will still go ahead with criminal charges and the 205 - would be a pity if those records are then not available any more.

The reason why I believe the ISP's "hiding" behind the 205 is nonsense is the following:
- You can only file criminal charges at SAPS if loss/damages can be substantiated - so this means only commercial loss and does not factor in reputation, staff hours etc.
- If the damages/loss are below 50K then the case needs to be handled at your friendly SAPS station (and police already struggles with the concept of fighting murder and rape)
- If the damages are above 50K then it goes to commercial crimes unit, which will reluctantly look at it unless it is really above 150K.
- Neither commercial crimes unit or SAPS is equipped to understand cyber-crime
- So after having to convince SAPS that this is a serious issue, one will wait 24 hours for a case number and then for however long to get a 205

The above makes it very easy for cyber-criminals - they are guaranteed a window of opportunity of several weeks if one follows the legal requirements...

Thanks MWEB for the help - strange though that nothing has come about it the two weeks prior to it, despite having provided proof to your abuse department.
 
Thanks - we have been in contact with your Abuse department and we have received feedback from Richard today that the user's account has been terminated. This has assisted us greatly since that specific case was ongoing for 3 weeks without any real prompt action. I do hope that your team has proper data-retention policies in place, as we will still go ahead with criminal charges and the 205 - would be a pity if those records are then not available any more.

The reason why I believe the ISP's "hiding" behind the 205 is nonsense is the following:
- You can only file criminal charges at SAPS if loss/damages can be substantiated - so this means only commercial loss and does not factor in reputation, staff hours etc.
- If the damages/loss are below 50K then the case needs to be handled at your friendly SAPS station (and police already struggles with the concept of fighting murder and rape)
- If the damages are above 50K then it goes to commercial crimes unit, which will reluctantly look at it unless it is really above 150K.
- Neither commercial crimes unit or SAPS is equipped to understand cyber-crime
- So after having to convince SAPS that this is a serious issue, one will wait 24 hours for a case number and then for however long to get a 205

The above makes it very easy for cyber-criminals - they are guaranteed a window of opportunity of several weeks if one follows the legal requirements...

Thanks MWEB for the help - strange though that nothing has come about it the two weeks prior to it, despite having provided proof to your abuse department.

Thanks MagicDude4Eva, appreciate the feedback.
 
The reason why I believe the ISP's "hiding" behind the 205 is nonsense is the following:
- You can only file criminal charges at SAPS if loss/damages can be substantiated - so this means only commercial loss and does not factor in reputation, staff hours etc.
- If the damages/loss are below 50K then the case needs to be handled at your friendly SAPS station (and police already struggles with the concept of fighting murder and rape)
- If the damages are above 50K then it goes to commercial crimes unit, which will reluctantly look at it unless it is really above 150K.
- Neither commercial crimes unit or SAPS is equipped to understand cyber-crime
- So after having to convince SAPS that this is a serious issue, one will wait 24 hours for a case number and then for however long to get a 205

The above makes it very easy for cyber-criminals - they are guaranteed a window of opportunity of several weeks if one follows the legal requirements...
sounds more like you have a problem with a non-functioning criminal justice system. i hear your frustration with the situation and it could perhaps have been handled better but consider that customer expect ISPs to protect their privacy and not take action unless there is a verified justification for doing so. An ISP is not a law firm / court which can make decisions about whether something is illegal or unlawful and then decide for itself whether to do something / what to do.
 
Currently busy with a 205 against Telkom. Docket was opened in June already ... some folk from the SAPS Commercial Branch arrived today to confirm our statements and get more info etc. Yep, almost 3 months later :(

They say that Telkom is seemingly the most forgiving with this 205 process - even though it might take a while to get an answer from them.
 
It is always helpful to notify the ISP of your intention to serve a section 205 subpoena so that they can preserve the data. Don't expect them to disclose anything to you before the subpoena arrives though.

I always find that its worthwhile to speak to a human on the phone when you're dealing with an important issue. Its easy to miss an email in the 1000s of abuse notices that arrive at most ISPs each day.
 
While one does not expect disclosing customer information without a 205, I would expect the ISP to issue warnings or suspend the customers account or start an internal investigation - none of this has happened.

Just to put my 2c in. Would you really want the ISP to do these things? It kinda tips the criminal off doesn't it? It is a bit like the person who identifies a rapist to the police then going and telling the rapist that the police are onto him.
In my mind it would be better for the ISP to just provide the information to the authorities and then only on their instruction to close the account.
 
Just to put my 2c in. Would you really want the ISP to do these things? It kinda tips the criminal off doesn't it? It is a bit like the person who identifies a rapist to the police then going and telling the rapist that the police are onto him.
In my mind it would be better for the ISP to just provide the information to the authorities and then only on their instruction to close the account.

Yes - I rather remove the tools from the criminal to avoid further damage. The criminal has already left a digital footprint which provides sufficient evidence. I guess the biggest problem will always be that the authorities are not capable of acting swiftly and one has to almost side-step the legal framework to protect customers.
 
I am a bit puzzled, MWEB suspended the criminal's account and it's now back in action - 41-132-252-83.dsl.mweb.co.za

This is pretty much the reason why the whole 205 issue will fail, unless you can obtain a blanket 205 which is impossible. Tick-tocking away on SAPS and the 205...
 
I am a bit puzzled, MWEB suspended the criminal's account and it's now back in action - 41-132-252-83.dsl.mweb.co.za

This is pretty much the reason why the whole 205 issue will fail, unless you can obtain a blanket 205 which is impossible. Tick-tocking away on SAPS and the 205...

They reuse IP's ?

Probably some one else.
 
@MagicDude4Eva
I've seen IP's being reused by different people within two days of another.
Are you however saying that the same IP has been used to attempt to disrupt your services again?
 
So since the 7/9 the user has used 5 different IP addresses (41.132.252.83, 41.132.74.190, 41.133.14.235, 41.132.182.190, 41.135.28.177). Since the user's account was terminated on the 14/9, the same user came back on the 17/9 with IP (41.132.252.83). This is a bit of a mystery - how can a criminal register for another MWEB DSL account (especially since there is no prepaid option, and I would have thought that subsequent attempts would be flagged).
 
Are you sure it is the same user? Is the user still doing the same stuff to try and disrupt your website services?
 
Top
Sign up to the MyBroadband newsletter
X