Legal Narrative: G2LeadsToSales vs. TimeFree Solutions

A comprehensive case analysis for attorney review

7. Server Hacking Incident

On or about January 14, 2025, a significant security breach occurred involving the web server that housed the proprietary software which automated G2LeadsToSales' operations. This incident represents not only a serious cybersecurity violation but also raises troubling questions about potential involvement by Andrew Johnson.

The server logs provide compelling evidence of a sophisticated attack. Beginning on January 13, 2025, the authentication logs show multiple failed login attempts from various IP addresses, indicating a coordinated attempt to gain unauthorized access to the system. These attempts continued into January 14, when a successful root login was recorded from IP address 75.112.135.235 at 22:19:52. Additional successful root logins from the same IP address were recorded on January 15, 2025, suggesting continued unauthorized access to the system.

The timing and nature of this breach are particularly suspicious when considered alongside other events. According to public records from Christian County, Missouri, Andrew Johnson took out a mortgage on his home on December 23, 2024, approximately three weeks before the hacking incident. A modification to that mortgage was recorded on January 22, 2025, just one week after the breach. This timeline suggests a potential connection between Andrew Johnson's financial activities and the unauthorized server access.

During the breach, the attackers accessed a database containing information that would be of significant value to very few people other than myself and Andrew Johnson. After extracting the desired data, the hackers altered the database contents, potentially to conceal their activities or to damage the operational integrity of the system. The technical sophistication of the attack suggests the involvement of professional "hackers-for-hire," which are available through various online platforms but typically require substantial payment—a service that Andrew Johnson may have been able to afford following his recent mortgage transaction.

Further evidence of suspicious activity appears in the server logs from January 20, 2025, which show multiple successful root logins from IP address 168.92.245.90. These logins, occurring less than a week after the initial breach, suggest ongoing unauthorized access to the system, potentially to monitor or further manipulate the business data.

The nature of the data accessed is particularly telling. The database contained proprietary business information that would have limited value to random hackers but significant value to someone seeking to extract business intelligence or gain competitive advantage in the lead generation industry. Given Andrew Johnson's position as the only other party with direct interest in this specific business data, and the correlation between his financial activities and the timing of the breach, there is strong circumstantial evidence suggesting his potential involvement.

This unauthorized access represents a potential violation of the Computer Fraud and Abuse Act, which prohibits unauthorized access to protected computers to obtain information. If Andrew Johnson is indeed connected to this breach, it would constitute not only a civil violation but potentially a criminal offense, particularly if the purpose was to misappropriate trade secrets or damage business operations.