AI Summary
5 min readIn 1988, a homeless man named William Woods working at a hot dog stand in Albuquerque had his wallet stolen by a co-worker, Matthew Kierans. The wallet contained Woods' birth certificate and Social Security card. Over the next three decades, Kierans used those documents to completely erase his own criminal past and assume Woods' identity—getting a driver's license, a marriage license, a $100,000 IT job at the University of Iowa, a house, and a car. The real William Woods, meanwhile, drifted through day labor and scavenging, never filing taxes or opening bank accounts. When Woods finally discovered the fraud in 2019 and went to a bank to report it, the bank manager called the police on him for identity theft. Kierans, who had 31 years of supporting documentation, easily proved he was "William Woods." The real Woods was so furious and confused in court that he was declared mentally unfit, spent five months drugged in a psychiatric hospital, and then served a year and a half in prison—forced to call himself Matthew. Only after his release did a University of Iowa investigator perform a DNA test, proving Woods was telling the truth. Kierans was sentenced to 12 years in federal prison. This story sets the stage for a deeper look at how identity theft works at scale today.
The Hacker Who Became an APT
Continue reading the full summary in the app — free to try.
Read Full Summary →Free • No credit card required
Never miss an episode of Darknet Diaries
Get every new episode summarized in your inbox — free, ~5 minutes to read.
No spam. Unsubscribe anytime.
What you'll learn
- 1 (01:00) **The William Woods Identity Theft Case** - A homeless hot dog stand worker named William Woods has his wallet stolen by coworker Matthew Kierans in 1988, setting off a 31-year identity theft nightmare.
- 2 (13:36) **Introducing the Hacker USDOD** - Jack begins a relationship with a strange hacker who calls himself USDOD (mocking the Department of Defense) and is classified as an APT by the US government.
- 3 (18:04) **USDOD’s First Major Breach: The US Military** - A Russian associate asks USDOD to help collect military data for an AI platform called “Tulip.”
- 4 (20:25) **USDOD Breaches the FBI’s InfraGard** - USDOD targets InfraGard, the FBI’s tip line for critical infrastructure companies.
- 5 (23:14) **The Hacker is Identified** - The US government identifies USDOD as Luan Barbosa, a Brazilian citizen. Brazil does not extradite its citizens, so Luan feels untouchable and continues his rampage.
- 6 (23:49) **USDOD’s Hacking Formula and a New Goal** - Luan’s method: find data dumps, impersonate someone with access, and profit.
- 7 (26:50) **Introducing Salvatore Varini Jr. (Sal)** - Sal is a failed actor and former sheriff’s deputy who starts a data broker company called National Public Data.
+ Full timestamped outline available in the app
Show Notes
This is the story of the hacker known as "USDoD". When he was young he had a vengeance on the US, and this lead him down a road of continual data breaches, until he hacked into National Public Data, which is when his spree went one step too far.
Sponsors
Support for this show comes from ThreatLocker. ThreatLocker is a Zero Trust Platform that gives organizations control over what can run and what users and devices can access. It combines prevention with real time detection and automated response, helping security teams stop unauthorized activity and quickly contain compromised machines. Learn how ThreatLocker can strengthen your defenses at threatlocker.com/Darknet.
This show is sponsored by Maze. Maze uses AI agents to triage and remediate cloud vulnerabilities by figuring out what’s actually exploitable, not just what’s theoretically risky. They remove the noise, prioritize vulns that matter, and manage remediation, so your team stops wasting time on meaningless vulns. Visit MazeHQ.com/darknet for more information.
This show is sponsored by Sentry.IO. Sentry wants to help you monitor your environment for problems. They do error tracking, stack tracing, debugging, all so that your developers can diagnose, fix, and optimize the performance of their code. This makes it so developers ship more reliable code faster. Learn more at sentry.io.
Sources
Full list of sources on the show page: https://darknetdiaries.com/episode/177/
More from this podcast
Darknet Diaries →