Showing posts with label insider theft. Show all posts
Showing posts with label insider theft. Show all posts

Saturday, January 26, 2008

$7 billion rogue trader turns himself in

The $7 billion rogue trader has turned himself in to French authorities.

Nicola Clark of the NY Times just reported:

Jérôme Kerviel, a former trader at Société Générale, surrendered to the police on Saturday as investigators looked into what had caused the bank, one of Europe’s largest, to lose more than $7 billion.

When the story hit the wires, Kerviel's attorney stated that he would be available to speak with judicial authorities.

The $7 billion question for the authorities and the rest of us us:

The bank’s management has come under increasing pressure from French officials to provide a more detailed accounting of how Mr. Kerviel could have racked up such enormous losses by himself, over a year, without raising any red flags among either his supervisors or the bank’s internal auditors.

Many familiar with the situation are speculating that the recent problems with the stock market caused the losses to unexpectedly grow, which led to them becoming transparent.

NY Times story, here.

My original post on this (probably historical case), here.

Friday, January 25, 2008

The $7 Billion Fraudster


(Photo courtesy of Zorg at Flickr)

Jerome Kerviel -- who may have cost his employer somewhere around $7 billion -- might prove that no security system is flawless, especially when the person compromising it has been given access to it.

Molly Moore of the Washington Post reports:

For five years, Jérôme Kerviel toiled in the back offices of Societe Generale, learning the intricacies of the six-layer security system that France's second-largest bank used to protect its money, investors and customers from fraud, according to bank officials here.

Kerviel then made an unusual career move. He was promoted to trader -- becoming one of the very employees the security systems are designed to oversee and keep honest.
Of course, no exact details (they seldom are for obvious reasons) are being given as to how Jerome pulled this off, but he is being described as a "computer genius."

I did notice in the Washington Post article that Jerome was keeping two sets of books, which is an age-old method of committing white collar crime. Jerome was also voiding transactions to cover up questionable transactions, which is hardly a new method of fraud, either.

The trader maintained two sets of books, one in which he kept accounts of his successful investments, and a secret parallel book where he was "voiding his losing positions," Bouton said.

"He knew when controls were going to take place," Bouton said, because "over the years he had become an expert in controls." Bouton said Kerviel managed to outmaneuver six levels of controls and firewalls intended to detect and prevent fraud.
Most high tech fraud is based on tried and true (even historical) methods of deception. Too often, organizations rely on computerized detection systems that might be a little too predictable. This is especially true when dealing with someone, who has been given access to them and understands how they work.

All too often, organizations are sold one form of technical protection only to find out that in a given period of time, someone has figured out how to circumvent them. Once this occurs, they need to buy another system, which might be circumvented over time, also.

Human beings are very adept at figuring out how to circumvent (hack) systems. In fact, there seems to be communities of people dedicated to hacking whatever new technology comes out.

If Jerome was able to cost his employer $7 billion dollars, he has set a new record. The person, who set the previous record is mentioned in the Post artice, and even made a quote from prison:

If confirmed, the losses at the bank would be the largest ever caused by an individual trader. They are far higher than the $1.4 billion run up by trader Nick Leeson in the mid-1990s in Singapore. His fraud caused the collapse of the institution where he worked, Britain's 233-year-old Barings Bank.

Leeson, now living in Ireland after serving a prison sentence in Singapore, told the BBC that he was not shocked such a fraud had happened again, but that "the thing that really shocked me was the size of it."

Maybe we shouldn't be so shocked? Perhaps the problem is an over reliance on systems to prevent fraud without enough human interface? Computers only do what they are told to do and it takes a human being to circumvent them.

Technology is a wonderful thing and a great tool, but when it comes to protecting anything, common sense and the human factor need to be considered carefully, also!

The Washington Post article also has some interesting speculation on how this might have had an effect on global markets. The article can be seen, here.

Sunday, July 22, 2007

Disney learns (the hard way) that insiders can be the biggest threat to information security

In the world of data breaches, nothing is sacred, not even Disney. It has come to light that a subcontractor (Alta Resources, Inc.) had an employee, who sold credit card information to federal agents.

Jaikumar Vijayan, Computerworld reports:

A subcontractor working for a company that processes and fulfills orders for the Disney Movie Club sold credit card numbers and other account information belonging to an unknown number of customers to undercover law enforcement agents.

The May 2007 incident has prompted Disney to send out letters to an unspecified number of customers informing them about the breach.
Jaikumar tried to get Disney to comment, but in standing with data breach protocol, they declined to do so. He was able to get one of the letters sent out to the customers, who were breached.

The letter reassured the "compromised" by stating:

Law enforcement officials have informed us that there is no indication that your information was used to make improper purchases or sold to anyone other than federal law enforcement agents," Flynn said in his letter. "Nevertheless, in an abundance of caution, we have informed representatives of Visa, MasterCard, American Express and Discover of these events."

Given the wholesomeness of Disney, their customers could be considered lucrative targets for identity theft. Most of them probably have good credit.

Either, the person involved was caught right from the beginning, or he isn't talking.

They are also saying that CVV/CVC codes were not compromised. CVV/CVC codes are three-digit codes added to a payment card as an extra layer of security.

I went to the site and didn't see CVV/CVC codes being asked for after pretending to buy some merchandise from them? Granted, I didn't click "buy," which would have sent my credit card information to them, but I completed the rest of the steps.

Not all merchants ask for this code, when someone makes a purchase, or payment over the Internet.

It amazes me how optimistically data breaches are presented.

In an Orlando Sentinel article about the breach, officials at Disney were quick to point out they had been "independently certified by under the Payment Card Industry Data Security Standard."

PCI data security protection standards are being pushed on merchants right now -- but as long as one dishonest person is given access, or is tricked into doing so -- no amount of security is going to protect information.

PCI data security protection standards are a step in the right direction, but need to be combined with other sound practices to protect businesses from being compromised.

PC World article, here.

Update: NetworkWorld's Buzzblog is quoting a Orlando Sentinel story that David Haltinner of Wisconsin has been charged in the case. They also have a link showing a copy of the official letter, here and a letter from a customer, claiming their card, which was on file with Disney had fraudulent purchases ($8,000.00 worth) put on it.

The writer of the letter did try to report this, but was told that it probably didn't tie into this breach. Finding the point of compromise in a credit card fraud case is difficult to say the least. Perhaps, this is why the recent GAO report on data breaches claims very little fraud is being tied into the compromises they studied?

With all the entities being compromised only revealing as little as they have to, there is a lot of plausible deniability.

The Buzzblog got the customer notification letter from someone at Attrition.org, who tracks data breaches on their site, here.

Thursday, May 17, 2007

Equifax hires ID Thief

These days, identity theft is being used for more than to commit financial crimes. A woman in Georgia (Tonia Leach) discovered her identity was stolen after an inquiry showed up on her credit report from a temp agency and Equifax. The still not identified impostor used the woman’s identity to obtain employment at Equifax.

When I say the impostor used the identity for more than committing financial crimes, I didn’t mean the victim wasn’t left with a lot of financial liability, as a result of this occurence.

WSBTV.com (Georgia) reports:

The woman also opened credit cards in Leach’s name. Leach even got a bill from the IRS. Leach said her life has been turned upside-down.

When the creditors call, they call me at 6, 7, 8, 9, every hour of every day. They will call you because they want their money. It was horrible, said Leach.

Equifax, one of the big three credit reporting agencies made the following statement:

We can confirm that an individual posing as Ms. Leach was employed with Equifax for less than a year, beginning in early 2006. There were no indications with the identification information that she provided or through the work history or the credit report that this was a stolen identification.

Equifax also claims, the impostor didn’t have access to sensitive information, but the article doesn’t say exactly what she did, or if there was any sensitive information accessible where she worked?

After all, this person seems very adept at stealing information and it’s possible, she could have found ways to steal it, using other people’s access. Access codes and passwords are frequently compromised by dishonest employees, who intend to steal, or commit other misdeeds.

If you are interested in how easy it is to get all the documents necessary to pose as someone else, I did a post about Suad Leija, who has shared a lot of information on this subject:

Paper weapons (counterfeit documents) enable more serious crimes than illegal immigration and identity theft

With the amount of stolen identities, backed up by easily available counterfeit documents, we can expect to see more people obtaining employment using someone else's information.

Most identity theft experts recommend you check your credit report at least once a year. It's a good idea to pay attention to what inquiries have been made and be wary if you don't recognize, who has been making inquiries into your credit.

Tom Fragala at MyTruston, who is a fellow blogger, provides an easy to use method to check to see if you are a victim of identity theft. Checking to see if you are a victim is always free and you only pay if you choose to use his recovery services. The recovery services are cheaper than anything I've seen out there, thus far.

MyTruston is also "privacy friendly," which means you don't have to give up your personal information to be stored in someone else's database. Identities are stolen from databases, pretty frequently.

You can link to MyTruston, here.

WSBTV.com story, here.

Monday, April 16, 2007

Social Security employee causing $2.5 million in credit card fraud reveals how easily information is stolen from within

Recently, I blogged about a former IRS employee, who committed $330,000 of retail refund fraud (basically shoplifting) in nine states. This morning, I read about a former Social Security Administration employee, who caused an alleged $2.5 million in credit card fraud by providing detailed information on victims to an external identity thief.

Sharon Gaudin at Information Week writes:

The indictment alleges that Batiste conspired with her cohort Craig Harris and others by agreeing to access the Social Security Administration's computer system to run search queries for Harris.

Harris, a 50-year-old Los Angeles resident, pleaded guilty in September to conspiracy and unlawful possession of a means of identification. Harris, who faces a maximum sentence of 10 years in prison, is scheduled to be sentenced on July 17.

The government contends that Harris would give Batiste some identifying piece of information about someone -- either a name or Social Security number -- and Batiste would then query the government system to pull up enough other identifying information to put the person's identity at risk.

Information Week article, here.

According to the article, the arrest was the result of the work of the Economic Crimes Task Force, which includes both federal and local assets in Southern California.

Last October, I wrote about a task force in Southern California responsible for catching a lot of insider related (employee) identity theft. My post is still up, but the link to the LA Times article is now down and nothing else can be found about it on Google.

I suppose insider problems aren't as newsworthy as large scale data-breaches, involving highly skilled hackers. The reason for this might be that they are embarrassing to the organization involved, and they don't help sell expensive (computer related) security fixes.

In fact, a trusted insider, can normally get past all the above referenced security fixes, simply because they have access.

And if you think about it, retail, restaurant and clerical employees have access to a lot of information. It's a lot easier to bribe, or even place a person inside an organization to steal information than hack it from the outside.

Trust me, it's going on in the business (and it appears) civil service worlds, daily.

Perhaps, all the experts, should take a closer look at this problem and how to control it.

Here's a previous post, I wrote on this subject, where the Secret Service is doing this:

Secret Service is Studying the Problem from Within

LA County has a hot line to report government employees committing fraud. The information to contact it can be found, here.

The FBI has also set up a place, where anyone can report public corruption, here.

A lot of large companies have a dedicated hot line to report internal problems, or you can ask to speak to someone in their security department. Smaller businesses normally don't have these resources, but most owners would be highly interested if someone working for them was stealing.

It's not good for business!

In some instances (not all), there are financial incentives for reporting insider dishonesty.

If you are worried about safety issues, I always recommending doing this, anonymously.

Saturday, August 26, 2006

Secret Service is Studying the Problem from Within

The USSS (Secret Service) is studying how dishonest "insiders" can pose a large problem to organizations.

Here's what they say about it in their press release:


The report released today focuses on the people who have had access to and have perpetrated harm using information systems in the banking and finance sector, which includes credit unions and financial institutions. The findings underscore the importance of organizations’ technology, policies and procedures in securing their networks against insider threats, as most of the cases showcased in the report were perpetrated by insiders with minimal technical skills. Various proactive practices are among the suggestions offered by the report.

“With the potential for cyber crime and network intrusion expanding rapidly around the globe, the importance of cooperation with our partners in the private sector is greater than ever,” said Secret Service Director W. Ralph Basham. “The Insider Threat Study is a solid example of the role the Secret Service and its partners can play in understanding threats and helping to prevent serious crimes such as network intrusions, identity theft and financial fraud.”
Link to press release, here.

Link to full study, here.

I have no doubt that individuals and even people planted as "insiders" pose a serious threat to the safety/security of any organization. Information is worth a lot of money and getting an asset on the inside makes stealing it, pretty easy.

There is a report by the Privacy Rights Clearinghouse, I quote often, which shows that the reason for a lot of data breaches is never discovered, here.

I wonder if any of them were inside jobs?

Saturday, March 18, 2006

Information Breaches, the Human Factor

According to the Privacy Rights Clearinghouse, millions of identities have been compromised recently. In fact, it's impossible to quote an exact figure anymore because new reports of breaches are surfacing weekly. In their chronology, they list several occurrences as being caused by a dishonest insider, but in reality how much more of this could be happening?

One of the recent stories was about Ernst and Young getting some laptops stolen. Several other breaches are listed as a result of stolen computers. The question is how did the people, who stole them determine which ones to steal and what information would be on them?

Many other breaches are listed as a result of "hacking." Hacking is a big word and brings visions of teenagers breaking into systems from afar. BUT is it possible, that some of the hacking occurring today might be the result of insider information obtained by the hackers?

A recent study by Taleo research found that background screening at many companies is inadequate. The results of this study are pretty interesting:

27 percent of organizations experienced a major problem, workplace fraud (10%), employee theft (10%) or workplace violence, with an employee who was screened in, but ended up having a criminal record that was not found.

57 percent of survey respondents believe that their organization should be doing a better job of screening employees prior to being hired.

Only 19 percent consider their current background check process very effective at weeding out candidates that do not meet the criteria for employment at their company.

Two-thirds of organizations do not conduct ongoing background checks on employees.

Only 29 percent have ever run an audit of their current screening provider to determine the quality of their screenings.

Of course, in the real world of data breaches, it seems that those, who have been breached, are extremely reluctant to reveal very many details.

AND there is another problem, which is the number of illegal immigrants out there in the work force. Depending on who you quote, they number in the millions and the trafficking is done by organized criminal gangs. Many of these immigrants owe lots of money to these gang members and already use fake, or stolen identities to work. How many of them might be repaying their debts by stealing information?

Here is a document from CERT, which shows the implications of organized cyber crime:

Organized Crime and Cyber-Crime: Implications for Business

There is no doubt this is trend is growing and will continue to be a problem. Whether these organizations approach insiders for information, or plant them from within with fake identities; they can steal a lot of what is a very profitable commodity in the world marketplace, or information.

Another potential problem is outsourcing financial and computer services to other countries, where the security standards are not up to par. In fact, this might even make some of these firms more attractive targets for the criminal element. I wrote about this in a previous post:

What are the Security Implications of Outsourcing

Until some of the organizations, who have been breached are held more accountable, we will probably never know the true scope of "insider involvement."