{"id":36488,"date":"2020-08-06T15:55:34","date_gmt":"2020-08-06T15:55:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/31463\/Arrested-Pen-Testers-Push-For-Good-Samaritan-Law.html"},"modified":"2020-08-06T15:55:34","modified_gmt":"2020-08-06T15:55:34","slug":"arrested-pen-testers-push-for-good-samaritan-law","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/","title":{"rendered":"Arrested Pen Testers Push For Good Samaritan Law"},"content":{"rendered":"<div class=\"wysiwyg\">\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-1024x614.jpg\" alt class=\"wp-image-106603\" srcset=\"https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-1024x614.jpg 1024w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-300x180.jpg 300w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-768x461.jpg 768w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-860x516.jpg 860w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-156x94.jpg 156w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-312x187.jpg 312w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-640x384.jpg 640w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231-1280x768.jpg 1280w, https:\/\/www.scmagazine.com\/wp-content\/uploads\/sites\/2\/2020\/08\/Dallas_County_Courthouse_Adel_Iowa_July_4_2013-e1596651529231.jpg 1500w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption>Coalfire pen testers Gary DeMercurio and Justin Wynn were arrested last September as they assessed the physical security of the Dallas County Courthouse in Iowa. (Stephen Matthew Milligan)<\/figcaption><\/figure>\n<p>Prosecutors dropped felony criminal charges against a pair of ethical pen testers arrested while assessing the security of an Iowa courthouse. But the the two men are not ready move on just yet.<\/p>\n<p>Coalfire employees Gary DeMercurio, managing senior, and Justin Wynn, senior security consultant, lobbied Wednesday at the virtual Black Hat conference for a Good Samaritan law that would protect their industry peers from the kind of overzealous prosecution they say they experienced for roughly five months, after a local sheriff <a href=\"https:\/\/www.scmagazine.com\/home\/security-news\/vulnerabilities\/pen-test-gone-awry-coalfire-staffers-arrested-for-burglary\/\">had them arrested<\/a> on Sept. 11, 2019 for alleged third-degree burglary. The two men picked a lock on the door of the Dallas County Courthouse in Iowa and entered the facility, triggering an alarm.<\/p>\n<p>Demercurio and Wynn had been contracted by Iowa\u2019s State Court Administration to evaluate the cyber and physical security of various buildings, but some Dallas County officials claimed the act was unauthorized because the county actually controls the courthouse property, yet was never notified.&nbsp;<\/p>\n<p>The charges were <a href=\"https:\/\/www.scmagazine.com\/home\/security-news\/cybercrime\/burglary-charges-dropped-against-coalfire-pen-testers\/\">later dropped<\/a> in late January 2020.<\/p>\n<p>SC Media spoke to DeMercurio and Wynn in advance of their conference presentation.<\/p>\n<p><strong>Why is now the time to recount your experience in such a major public forum?<\/strong><\/p>\n<p>Wynn: This is the first time we were able to go public with the story. During the entire time events were unfolding we were advised to remain silent on the process and the media just kind of took things by storm and we were never able to get our story out there. So this presentation, it\u2019s 40 minutes and it\u2019s basically just a condensed summary of the events that unfolded over those six months. At the end we wrap up [with] where we want to go with the industry and how we want to have more protection for the people doing this kind of work. And then a synopsis of the actions that the Iowa judicial branch took in response to this, which was a knee-jerk reaction \u2013 the opposite of what we want to see happen for proactive security testing.<\/p>\n<p><strong>Had you ever had a serious encounter with law enforcement before this?<\/strong><\/p>\n<p>Wynn: Pretty much anybody who\u2019s done this type of work, you run into law enforcement at some point, and usually the interactions go: Suspicion, they\u2019re curious why you\u2019re there and then you go through the validation process, the client gets the okay and then the police are waved off and that\u2019s as far as pretty much it\u2019s gone for anybody in the industry to date. And for Gary and I, personally we\u2019ve had squeaky clean records. I mean absolutely nothing involving law enforcement at all to this extent whatsoever.<\/p>\n<p><strong>There were cyber and physical security components to this particular security assignment, correct?<\/strong><\/p>\n<p>Wynn: Yep. This was a full-scope red team engagement, so we\u2019d been working on that project for probably about a month prior and that includes external, internal network penetration testing, wireless penetration, application [security\u2026 This] was the physical pentation portion of the testing, so that\u2019s why we were outside\u2026 One of the interesting things about that, too, was we were supposed to do the internal network penetration test afterwards. One of the [news] articles caught wind that we plugged a drone or a device in on site. We were following the rules of engagement. They wanted us to come on site, see if we could break in, and then plant that device for the follow-up internal network penetration test. So they really wanted to simulate a real-life adversary: \u201cCan somebody walk into our building, plant a remote access device, and then from there show us what they can do? And we\u2019ll follow up with the internal penetration test afterwards.\u201d<\/p>\n<p><strong>You were contracted to test state-run judicial assets by the State Court Administration, but it was the local county that pursued this case from a prosecutorial perspective. So what happened with the communication between these two level of government that couldn\u2019t have cleared this up in a day?<\/strong><\/p>\n<p>Wynn: From our point of view, it could have been. It really came down to a jurisdictional dispute. So one entity, the county, wanted to assert their authority and say this is the county courthouse and the state doesn\u2019t have authorization to conduct these sort of tests for that location. So that\u2019s really all it came down to \u2013 and that\u2019s why the legal dispute, that\u2019s why we got dragged through everything, was they were trying to sort that out.<\/p>\n<p>It felt like we were held on as collateral. There was really no need for us to be hooked into that process for five months. I mean it\u2019s kind of between state and country or at the least between Coalfire and whoever involved, but not individuals, not us, the guys just doing the work. [The county decided], \u201dEven though this is a free service for us to benefit our community and our citizens and our courthouse, the state shouldn\u2019t be paying for this kind of stuff. This is our grounds and so take them to jail.\u201d That how I look at it in my eyes.<\/p>\n<p><strong>The Supreme Court later this year will be looking at the Computer Fraud and Abuse Act to determine if violating a system or website\u2019 terms of service constitute a criminal act if the actor otherwise has been authorized access to it. The white-hat community is concerned that more protections are needed to ensure their own ethical pen testing and hacking is considered legal. What protections would you like to see instituted?<\/strong><\/p>\n<p>DeMercurio: The thing that we\u2019re trying to concentrate on is having a \u201cGood Samaritan\u201d law in place. So the good Samaritan law, as far as the research that we\u2019ve done and what we\u2019ve gone through, would supersede any terms of service as it relates to ethical hacking.<\/p>\n<p>If you\u2019re an ethical hacker \u2013 or a maybe a better term would be ethical pen tester \u2013 [and whether] you\u2019re performing a pen test physically or you\u2019re\u2026 social engineering or what have you, if you\u2019re performing a test in good faith for a customer who has hired you and you are within the scope of what you should be doing or what you believe that you should be doing, then you shouldn\u2019t have any repercussions\u2026<\/p>\n<p><strong>But you did face repercussions for your actions.<\/strong><\/p>\n<p>DeMercurio: We were given a scope, we felt that we were in that scope\u2026 Later on the state admitted that we were in scope, but prior to that, due to either personal reasons or political reasons or what have you, they tried to throw us under the bus and they tried to say we were out of scope \u2013 that we weren\u2019t performing the thing that we were supposed to perform. But later on after the judicial hearing, everything came out. Yes, indeed, we were doing exactly what we were supposed to be doing.&nbsp;<\/p>\n<p>\u2026[But] even if we misstep on the scope due to some confusion or lack of terms or something that\u2019s not really laid out perfectly, the general consensus is we\u2019re trying to do the right thing and we shouldn\u2019t be prosecuted as if we\u2019re criminals, because we\u2019re not\u2026 If we\u2019re doing what we should be doing after speaking with the customer, they shouldn\u2019t be able to come back and say, \u201cWell that\u2019s not exactly what we had in mind. Now we\u2019re going got try to send you to prison. If you\u2019re out of scope completely and you\u2019re not doing what you\u2019re supposed to be doing, that\u2019s a different story.<\/p>\n<p><strong>Explain a little more about how politics complicated this matter.<\/strong><\/p>\n<p>DeMercurio: [When] you start getting on the state and county level, not only do you have the laws and provisions that you\u2019re talking about in place, but you also have the politics that are involved as well. And whether or not they [the state] have the authority to enforce security in that [county] building is different in Iowa than it is in a different state. Whether or not you have the ability to go into that building after midnight, is that set by the county or is that set by the state? Typically it\u2019s set by whomever is employing the people within that building, which is what we were under the assumption of when doing this. However, the sheriff did not share that opinion and Iowa recently passed a law [that] the county owns\u2026 the property and [has] the control of the building. But that still doesn\u2019t answer the question of what do you do for state employees?\u2026 They wouldn\u2019t arrest a [state] judge if he came in there to get a computer, so why were we arrested? So again, you\u2019ve got all these legal questions and there\u2019s no answer for it because there was nothing ever written and it\u2019s something that\u2019s completely different than anything that\u2019s ever happened.<\/p>\n<p><strong>What has been the reaction of your peers in the industry as they\u2019ve followed this case? Have you had their support?<\/strong><\/p>\n<p>Wynn: I think industry-wide people were very concerned\u2026 Going back to the good Samaritan law, I mean, if [a pen tester] \u201cfat fingers\u201d an IP address and then you test the wrong client,&nbsp;&nbsp;you don\u2019t want to go to jail for that, nor should you because you\u2019re doing that in good faith.&nbsp;&nbsp;You\u2019re not trying to break into the other organizations, so I think everyone is very concerned.<\/p>\n<p>We had absolutely phenomenal support from the industry. The infosesc family came together and rallied for us. They put on AwarenessCon [a physical and virtual event designed to expose people in the region to the merits of offensive pen testing] in that small town in Iowa where we got arrested, and everyone was very proactive in reaching out to us and offering support through the entire time. So that was wonderful to see it really made us feel part of the community.<\/p>\n<\/p><\/div>\n<section class=\"post-tags\">\n<h2>Topics:<\/h2>\n<p> <a href=\"https:\/\/www.scmagazine.com\/tag\/legal-action\/\" class=\"button -secondary\">Legal Action<\/a> <a href=\"https:\/\/www.scmagazine.com\/tag\/legislation\/\" class=\"button -secondary\">Legislation<\/a> <a href=\"https:\/\/www.scmagazine.com\/tag\/network-security\/\" class=\"button -secondary\">Network Security<\/a> <\/section>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/31463\/Arrested-Pen-Testers-Push-For-Good-Samaritan-Law.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":36489,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[603],"class_list":["post-36488","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinehackergovernmentusa"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Arrested Pen Testers Push For Good Samaritan Law 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Arrested Pen Testers Push For Good Samaritan Law 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-08-06T15:55:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/08\/arrested-pen-testers-push-for-good-samaritan-law.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"614\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Arrested Pen Testers Push For Good Samaritan Law\",\"datePublished\":\"2020-08-06T15:55:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/\"},\"wordCount\":1733,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/arrested-pen-testers-push-for-good-samaritan-law.jpg\",\"keywords\":[\"headline,hacker,government,usa\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/\",\"name\":\"Arrested Pen Testers Push For Good Samaritan Law 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/arrested-pen-testers-push-for-good-samaritan-law.jpg\",\"datePublished\":\"2020-08-06T15:55:34+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/arrested-pen-testers-push-for-good-samaritan-law.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/arrested-pen-testers-push-for-good-samaritan-law.jpg\",\"width\":1024,\"height\":614},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/arrested-pen-testers-push-for-good-samaritan-law\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,government,usa\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackergovernmentusa\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Arrested Pen Testers Push For Good Samaritan Law\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Arrested Pen Testers Push For Good Samaritan Law 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/","og_locale":"en_US","og_type":"article","og_title":"Arrested Pen Testers Push For Good Samaritan Law 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-08-06T15:55:34+00:00","og_image":[{"width":1024,"height":614,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/08\/arrested-pen-testers-push-for-good-samaritan-law.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Arrested Pen Testers Push For Good Samaritan Law","datePublished":"2020-08-06T15:55:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/"},"wordCount":1733,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/08\/arrested-pen-testers-push-for-good-samaritan-law.jpg","keywords":["headline,hacker,government,usa"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/","url":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/","name":"Arrested Pen Testers Push For Good Samaritan Law 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/08\/arrested-pen-testers-push-for-good-samaritan-law.jpg","datePublished":"2020-08-06T15:55:34+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/08\/arrested-pen-testers-push-for-good-samaritan-law.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/08\/arrested-pen-testers-push-for-good-samaritan-law.jpg","width":1024,"height":614},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/arrested-pen-testers-push-for-good-samaritan-law\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,government,usa","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackergovernmentusa\/"},{"@type":"ListItem","position":3,"name":"Arrested Pen Testers Push For Good Samaritan Law"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/36488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=36488"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/36488\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/36489"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=36488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=36488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=36488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}