HBGary Federal CEO Aaron Barr Steps Down

Embattled CEO Aaron Barr says he is stepping down from his post at HBGary Federal to allow the company to move on after an embarassing data breach. 

The announcement comes three weeks after Barr became the target of a coordinated attack by members of the online mischief making group Anonymous, which hacked into HBGary Federal’s computer network and published tens of thousands of company e-mail messages on the Internet. HBGary did not respond to telephone and e-mail requests for comments on Barr’s resignation.

In an interview with Threatpost, Barr said that he is stepping down to allow himself and the company he ran to move on in the wake of the high profile hack. 

“I need to focus on taking care of my family and rebuilding my reputation,” Barr said in a phone interview. “It’s been a challenge to do that and run a company. And, given that I’ve been the focus of much of the bad press, I hope that, by leaving, HBGary and HBGary Federal can get away from some of that. I’m confident they’ll be able to weather this storm.”

Anonymous conducted a preemptive strike on HBGary after Barr was quoted in a published article saying that he had identified the leadership of the group and planned to disclose their identities at the B-Sides Security Conference in San Francisco. By combining a SQL injection attack on HBGary’s Web site with sophisticated social engineering attacks, the group gained access to the company’s Web- and e-mail servers as well as the Rootkit.com Web site, a site also launched by HBGary founder Greg Hoglund. Ultimately, the group defaced HBGary’s Web site and disgorged the full contents of e-mail accounts belonging to Barr, Hoglund and other company executives. 

Though Barr and HBGary were the victims of the hack, the contents of the e-mail messages divulged plans that cast both in an unflattering light. HBGary counted many U.S. government agencies, including the Department of Defense, CIA and NSA as customers. The disclosure of e-mail messages from the company poses a major security risk to those organizations, as well as individuals who had corresponded with the firm.  The breach also raises troubling questions about the direction that HBGary and other Beltway firms have taken. Email exchanges published online revealed the firm to be at work on a variety of plans to do data mining and information operations on U.S. organizations and journalists on behalf of clients including law firms representing a large U.S. bank and the U.S. Chamber of Commerce. Most recently, the incident spilled into the mainstream, with comedian Stephen Colbert devoting a segment of his Colbert Report program on February 24 to the HBGary hack. 

  • Not Anonymous on

    "By combining a SQL injection attack on HBGary's Web site with sophisticated social engineering attacks"

    Uhm. WHAT?

    Sophisticated? I wouldn't call a couple of e-mails from a hijacked account asking to back-door a server "sophisticated".

    What the HBGary hack was:

    Basic SQL Injection
    Weak passwords
    Password Re-use
    SIMPLE social engineering

    Your basic molotov cocktail of fail.

  • blender61 on

    Crappy security measures aside, there is one thing you never want to do, become a security risk.

    Aaron Barr's ego and hubris clouded good judgment. That is really what brought him down.

    He is now toxic within the community and will probably never get clearance again. The burn notice is out. As well it should be.

    The outfall from his blatant stupidity is yet to be felt.

    If you want to commit career suicide, fall on your sword Don't invite everybody else into a room and then pull the pin.



  • testcase on

    One thing is for certain. If you 'cross the line', as Aaron Barr did, in the internet world, you will NEVER be forgotten. Simple self preservation of the organism really. Anonymous are like antibodies, once they spot a threat they eliminate it, if the contagion tries to invade again, it rejects it. Like antibodies, Anonymous will remember that disease for the rest of it's life, and since the internet is pretty much immortal...

    Aaron Barr, you have been shunned from the internet village, so have others in your companies (we know which ones in intimate detail). The data and story have been widely distributed... right down to untouchable CDs and thumb drives. You may resurface, but not only will you find it hard being trusted, you will find that any new unsuspecting employer will find out, quickly and in great detail, everything you did with HBGary.

    You have become the classic example of what happens to ANYONE who is found to use the internet as a vehicle for harm. If justice had been properly served and you had faced criminal charges, the internet wouldn't have been so hard on you. Justice would have been seen to be done. But since it doesn't seem to have even been considered, this is what you get. A lifetime sentence of shame from the internet village, if fact, your reputation will LONG outlive you.

    The lack of 'proper' justice in the HBGary story brings up a much larger question. The system that was planning on 'bringing down' it's own citizens is obviously corrupt to the core... all the way to the top. Thanks to you, Aaron Barr, we, the world, now know for certain exactly who and where the real bad guys are. Knowing that is half the puzzle, it's only a matter of time before we solve the whole thing.


    Just in the interest of accuracy, the "social engineering" attack did not ask for a password. They already had the cracked password file. Pretty sure the request was for a port to be opened through the firewall (ostensibly because Hoglund was in Europe using an untrusted network and needed access to the server).

    The person who carried out the attack did enough research to include pertinent details regarding Hoglund's recent activities that helped enhance the believablility of their ruse - so I'd give it a "moderately sophisticated" rating.

    This is just priceless. I remember reading the IRC chat log, where someone stated that this was the end of Barr's career. Barr, of course, completely dismissed this out of hand.

    As far as rebuilding his reputation, I don' t think that's going to be possible -- for years to come, a search for HBGary or Aaron Barr will bring up the entire affair. You can't walk away from bad publicity like this -- this incident will hang around his neck like an albatross until the day he dies.

    It doesn't matter what else he may have done or accomplished; this will be the defining moment of his career. He may have to find another, totally unrelated, line of work -- frankly, I can't see anyone in the intelligence or security communities ever trusting this guy again. After all, he's almost single-handedly responsible for one of the biggest security clusterfucks in recent memory.

    This is one for the textbooks -- like the Tylenol poisonings in the early 80s. The way Johnson & Johnson handled the Tylenol poisoning incidents is now taught in business schools as the classic example of how to handle a crisis situation.

    On the other hand, HBGary and Aaron Barr will be taught as object lessons -- i.e. what NOT to do.
  • TerraHertz on

    I have a dream.... of a 'world without forum shills'. Where every man's opinion counts, without having to wade through thousands of lying, deceptive, soulless fascist-government-paid minions.

    The HBGary hack gives me hope that one day this may come to pass.
    To explain, recall the revelations of the USAF tendering for web 'Persona Management Software.'
    Original was here: https://www.fbo.gov/spg/USAF/AMC/6CS/RTB220610/listing.html but is now gone of course.
    Archived copy in pdf here: http://www.seankerrigan.com/docs/PersonaManagementSoftware.pdf

    Now the really interesting thing to me is who's listed under the 'Interested Vendors' List tab on that page. Quite a few groups that should all be in gaol come the revolution, but this one in particular:
    Email: ted@hbgary.com
    Phone: 916-459-4727 ext 118

    Now suppose HBGary ended up providing that Shill-management system. And they were involved with installation and operation. And then Anonymous fanged all the files from HBGary's servers...

    I dream that one day, a database of all the paid shills, all their online nics, the forums they routinely pollute, their real names, home addresses and salary details, will turn up on rapidshare or somewhere. Another real, honest-to-god unfiltered leak disaster for TPTB. Another CRU emails hack.
    Unlike the fake Wikileaks, who wouldn't know how to leak a big pile of incriminating data all at once, intact and unredacted if their lives depended on it.

    Maybe this time it came very close to happening. Maybe... it actually still will, when Anonymous is done searching through the gigabytes of HBGary files they got.

  • Tangerine Bolen on

    “I need to focus on taking care of my family and rebuilding my reputation," Barr said in a phone interview. "It’s been a challenge to do that and run a company. And, given that I’ve been the focus of much of bad press, I hope that, by leaving, HBGary and HBGary Federal can get away from some of that. I’m confident they’ll be able to weather this storm.”

    Um, no, Mr. Barr, and HB Gary Federal. If you broke the law, you will "weather the storm" in jail. Honest, decent, hardworking Americans will see to it.

    We have had enough of this. We WILL pursue justice for the criminal activities you and others have perpetuated against Americans and against democracy.

    Decent people of the world: Join us at RevolutionTruth.org. We are professional, respectful, hardworking, people from around the world who have had enough of the lies, the corruption, and the pathology that runs rampant behind thick veils of institutional and corporate legitimacy. We have had enough of being manipulated and mislead for the sick, special interests of a few. Of being denied access to accurate information that has a profound effect on each of our lives - such as information used to start unjust wars, or information about what our banking and finance industries are actually up to. 

    We are good people. We like facts and critical analysis. We have great hope for each other and for this planet and for effectuating positive change. We support legitimate democracies. We are peaceful. And we are building a global community and global campaign to put an end to the madness against Wikileaks and the rampant corruption that is now a sickness threaded through our systems. We are better than this. We deserve better than this. And we WILL make our world a better place for all. We will do so in part by ensuring access to accurate information - and to truth. Information, not manipulation. Common people, working together to change our world. That is our goal. Join us.

    Poetic justice to say the least. Unfortunately, this is just the tip of the igeberg. HBGary and their ex-leader are examples of the entire system, not exceptions like the other companies make them out to be. This is far from over.

    To Anonymous,

    I can't say that I agree with all of the decisions you've made regarding who should be targeted, but this choice was excellent.
    I can think of several other companies and individuals who deserve at least equal for reasons even more evil than the ones you've uncovered. Google "terminator technology" and you'll have all the reasons you need.

    For any and all of you who think that this wasn't a sophiticated mode of social engineering...well you may be correct.  I think that's more an interpretive issue than anything else but regardless, if you want to see what Greg Hoglund thought was "F**king brilliant" in regard to social engineering, check out the link.


    Note: this is a full HTML markup display of an email written by Hoglund.  A warning popup will ask you if you wish to proceed.  If you want to proceed to the anon' searchable wiki and locate this email in its plain text version, search for an email with the subject line "RE: You can't protect stupid" without the quotes.

    You guys are idiots if you think this is finished. Senior Barre' under new creds got picked up by his buddy/benefactor at MANTECH.  Most likely to continue the same type of work.  This is only phase 1... , A guy I know over there called me and said you wouldnt believe who we just hired....  search the emails and see if you can figure out who the mystery buddy is..

    You sleep with a dog, don't be suprised you wake up with ticks...

    As much as Aaron Barr is an idiot, he also got a family. Gloating over someone's failure is reprehenssible and shows total lack of character.

    Karma is a Bitch...

    First off this was not a sophisticated attack. HBGary had very poor security practices(vulnerable website, weak password, policy, and identity verification). Barr pushed a very bad position and in turn got bit for it. If they used the practices they sell then this attack would have failed miserably and would chock up a nice defeat for Anon. The social engineering part amuses me the most. 

    A lot of blame has to be put on the administrator for Rookit.com. The fact that he didn't pick up on this child's poor grammar and the suspicious requests she was making is just pathetic.  Most IT people would have picked it up on this and challenged the person. At the very least ask the person to contact them via phone. It doesn't matter how high up in the company you are.


    Just two cents.

