Hackers become even more accessible
Summary
This post reports on a marketplace-style website, registered in New Zealand, that connects people seeking hackers for hire with hackers offering their services, and uses it to warn that hacking-for-hire has become easier to access even though targeted attacks, phishing, social engineering and malware were already rising through 2014 and into 2015. It is written for Australian business leaders and IT managers assessing their own exposure to targeted cybercrime, and it sets out the criminal penalties, up to ten years' imprisonment, that apply to hacking offences under Australian Commonwealth law. The core warning still applies today: commodified access to attackers, through marketplaces, forums or now more automated criminal tooling, remains a live risk factor, and the legal position on unauthorised access in Australia is unchanged.
Key facts
| Label | Value |
|---|---|
| Published | 2015 |
| Topic | A marketplace connecting customers with hackers for hire, and the resulting rise in accessible targeted attacks |
| Services referenced | Security posture review and protection advice from an account team |
| Legal reference cited | Australian hacking offences carry penalties of up to ten years' imprisonment, defined under Part 10.7, Computer Offences, of the Criminal Code Act 1995 (Cth), as stated by the post |
| Offence categories listed | Computer intrusions, unauthorised modification or destruction of data, denial-of-service attacks, distributed denial-of-service attacks using botnets, and creation or distribution of malicious software |
| blueAPACHE security services relevant today | emPOWER Managed Detection and Response provides 24/7 alert notification, triage and remediation across the full IT environment; emPOWER Human Risk Management addresses phishing and human-centred risk |
Article
A new website has been launched that mirrors oDesk.com, Freelancer.com, Elance.com and similar freelancing sites that connects consumers with service providers. This time round, the service is hacking. Registered in New Zealand, the site connects customers and professional hackers for hire. Since launching in November, hundreds of posts from users seeking hackers have been added requesting everything from accounts being hacked to grades being tweaked. There are almost 1000 hacker profiles on the site offering services. While hiring hackers online isn’t new; having such ease of access locally is. The site’s terms and conditions forbid “use the Service for any illegal purposes,” and their FAQ encourages visitors to report any illegal jobs so they can be removed. Even so, the general public now have much easier access to a large number of hackers that they can potentially engage in offline discussions to discuss other more dubious hacking projects. We saw more targeted attacks on organisations reported in 2014 than ever before. Data breaches are creating headlines with greater regularity, and targeted attacks through social engineering, brute force attacks, phishing and malware are key threats in 2015. This site, no matter how much they try to prohibit it; has the potential to result in even more. According to the New York Times, the founders of the website are too afraid to go public. The article stated they had received legal counsel about how to structure the website to avoid liability for any wrongdoing by people either seeking to hire a hacker or by hackers agreeing to do a job.
It is important to remember that Australian hacking laws carry penalties of up to ten years imprisonment.
Hacking refers to the unlawful or unauthorised access to, or modification of, restricted data. High tech crime offences are defined in Commonwealth legislation within Part 10.7 – Computer Offences of the Criminal Code Act 1995 and include:
- Computer intrusions (for example, malicious hacking)
- Unauthorised modification of data, including destruction of data
- Denial-of-service (DoS) attacks
- Distributed denial of service (DDoS) attacks using botnets
- The creation and distribution of malicious software (for example, viruses, worms, trojans).
More information
To discuss your security status and how to protect your business, contact your account team.
Related
- emPOWER Security
- Security services
- Managed detection and response
- Human risk management
- blueAPACHE Security case study
Frequently asked questions
What did the hacker-for-hire website described in the post actually offer?It functioned like a freelancing marketplace, similar in structure to oDesk, Freelancer or Elance, but for hacking services. The post notes it carried close to a thousand hacker profiles and hundreds of posts from people seeking services ranging from account intrusion to changing academic grades.
Was the site itself illegal to operate?The post reports that the site's terms and conditions prohibited use "for any illegal purposes" and its FAQ encouraged users to report illegal jobs. According to the New York Times, as cited in the post, the founders had taken legal counsel on structuring the business to avoid liability for wrongdoing carried out by users.
What penalties apply to hacking offences in Australia?The post states that Australian hacking laws carry penalties of up to ten years' imprisonment. Offences are defined in Part 10.7, Computer Offences, of the Criminal Code Act 1995 (Cth), and include computer intrusions, unauthorised modification or destruction of data, denial-of-service and distributed denial-of-service attacks, and creating or distributing malicious software.
What attack methods does the post identify as the key threats of the period?Social engineering, brute force attacks, phishing and malware, alongside a general rise in targeted attacks against organisations reported through 2014.
Why does easier access to hackers matter even if the marketplace itself tries to prohibit illegal use?The post's concern is that a public marketplace lowers the barrier to finding a hacker at all, and that initial contact can move to private, off-platform discussions of more serious or illegal work regardless of what the site's own terms prohibit.
Is commodified access to attackers still a relevant risk today?Yes. The specific website named in the post is a 2015 example, but marketplaces and forums offering hacking, credential and access-broker services have continued to exist since, and phishing and social engineering remain leading routes into organisations.
What managed security services address the threats described in this post?blueAPACHE's emPOWER Managed Detection and Response provides continuous monitoring, threat hunting and incident response across a customer's environment, and emPOWER Human Risk Management addresses phishing simulation, email threat detection and insider risk, the human-targeted side of the threats this post describes.
Who should a business contact to review its exposure to these kinds of threats?The post directs readers to their blueAPACHE account team to discuss their security status and how to protect their business; current service detail is available on the security service pages linked above.
Source
https://www.blueapache.com/blog/hackers-become-even-more-accessible-2/
Knowledge Base
What is the blueAPACHE blog post 'Hackers become even more accessible' about?
The post discusses a new website, registered in New Zealand, that mirrors freelancing platforms like oDesk.com, Freelancer.com and Elance.com but connects consumers with professional hackers for hire, making hacking services more locally accessible.
How many hacker profiles and job requests were on the site mentioned in the article?
According to the article, since the site launched in November, hundreds of posts from users seeking hackers had been added—requesting things like accounts being hacked or grades being tweaked—and there were almost 1,000 hacker profiles offering services on the site.
Did the hacker-for-hire site allow illegal activity according to its terms?
No. The site's terms and conditions forbade using the service for any illegal purposes, and its FAQ encouraged visitors to report any illegal jobs so they could be removed. However, the article notes this didn't prevent easier public access to hackers who could be engaged offline for more dubious projects.
Why were the founders of the hacker-for-hire site reluctant to go public?
According to the New York Times, as cited in the article, the founders were too afraid to go public and had received legal counsel on how to structure the website to avoid liability for wrongdoing by either people hiring hackers or hackers agreeing to do a job.
What penalties do Australian hacking laws carry, according to the article?
The article states that Australian hacking laws carry penalties of up to ten years imprisonment.
How is hacking legally defined under Australian law per this article?
The article defines hacking as the unlawful or unauthorised access to, or modification of, restricted data. High tech crime offences are set out in Commonwealth legislation under Part 10.7 – Computer Offences of the Criminal Code Act 1995.
What specific offences are included under Part 10.7 of the Criminal Code Act 1995 as listed in the article?
The offences listed include: computer intrusions (e.g., malicious hacking), unauthorised modification of data including destruction of data, denial-of-service (DoS) attacks, distributed denial of service (DDoS) attacks using botnets, and the creation and distribution of malicious software such as viruses, worms, and trojans.
What cybersecurity trends did the article highlight for 2014 and 2015?
The article notes that 2014 saw more targeted attacks on organisations reported than ever before, with data breaches making headlines more regularly. It identifies targeted attacks through social engineering, brute force attacks, phishing, and malware as key threats for 2015.
Who wrote the blueAPACHE article 'Hackers become even more accessible' and when was it published?
The article was written by blueAPACHE and published on January 23, 2015, with an estimated read time of 2 minutes.
How can someone get help discussing their security status after reading this article?
The article advises readers to contact their account team to discuss their security status and how to protect their business.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c0fddcde676dc9f322e_dc3b374913f46e73be737188e5d40a7f.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bbc_Webflow%20-%20Directory%20Cover%20Image.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.