Someone forged my resignation letter
workplace.stackexchange.com
workplace.stackexchange.com
+ He could have been on holidays, or getting a child, but it is the death of his mother. Of course, we are gonna feel really bad for him. That's really good for the story.
+ The security of the system is such that on one hand a dongle is needed, but on the other hand someone can fake sending email through your account. This is apparently widely known by non-expert colleagues to just joke around, but not known by the security staff.
+ Technological "details" that do not seem to make sense such as SQL to make it sound like a true story to the uneducated.
+ The writer already assumes that we think he is lying. Hence, he comes up with the dongle story. We would already have been fine with his word that he just didn't send the resignation letter.
+ He physically shows up 6 weeks later without checking his email once (reply email). Of course the effect of the story is much stronger in that case. However, is it very likely not to check your email at least just before you show up at work 6 weeks later? [Edit: incorrect assumption, see @c8g.]
Then what would be motive of the person asking the question. It is a throwaway account.
+ A researcher who wants to see what the difference is between a fake story on Facebook versus one asked on StackOverflow? How could such an effect be properly compared?
+ No follow up comments on questions for some more info or thanking people that feel for him.
+ Using a very general name as nickname (although not English).
+ A throwaway account. Although it's understandable, because it is a personal story; if this would happen to me everyone would know.
It also interesting to see how good the story is. When people respond to this in the sense of "who did it?", they come up with the CEO. If he would have weaved in the name of one of his colleagues that used to joke around with fake email addresses, the story plot becomes weaker.
a work dongle is needed to read reply email and he said that he didn't bring it.
I would add the general style of the write up. It does not seem like a person being actually keen to receive an answer but is written like a tale. For example, notice the start of each paragraph: "Anyway"; "now maybe"; "the fact is". (That might be his personal way of writing as well, but it adds to the suspicious feeling)
And of course the fact that one can simply quit by Email, especially after having worked at a company for a long time seems highly unlikely, I would at least expect them to call you before moving on.
Nevertheless, it does pose a more general question. Given that in many workplaces the employer has access to your work email/account, how can one prove that he/she did not send a particular email?
Even though I only worked peripherally with digital forensics people, and I know a lot about how email/computers/networks work, I know enough to know that I could never get away with forging an email (especially not one where anything serious depended on it).
In a more broader way, how can one prove innocence if their company use the employee's credentials (ID/email/etc.) to drop the blame on them? Wouldn't it be the employees words against the employer, while at the same time the employer has the control over the data/evidence?
I mean, if this particular case is real, someone has performed a serious crime, risking years in jail, for a comparably trivial reason and small gain - it's not an indication that the perpetrator is likely to be risk-averse, meticulous and smart.
If we were looking at a forged email as a part of a sophisticated campaign for extracting secret information or defrauding very large amounts of money, then it would be likely that the forgery is done carefully by skilled people thoroughly removing all traces - but for a reason like this? not likely. Heck, digital "intelligence ops" by major governments sometimes leave traces due to some sloppiness or carelessness, it's very hard to be sufficiently thorough.
You don't, that's up to the police, prosecutors and forensics experts to handle.
The author implies that he's used the 'SQL' way of sending emails. Calling it 'SQL' sounds like a way of feigning ignorance of the details - and therefore giving a defense on future cross-examination.
I suspect he either used it personally to resign, or asked a colleague to, who has effectively been set up.
Also :
+ if it was holidays or a child he wouldn't have left in a rush : those departure should arguably be prepared in advance
+ "Technological details" are very vague and sounds like something he overheard but didn't understand or know how to use.
+ the throwaway account means nothing and could very well plead in his favour : he's not sure he wants to spend time attacking his company so he stays anonymous before taking a rushed decision.
+ not checking his email is consistent with not having the dongle !
Thanks for your counterarguments. I of course admit that my assumptions are assumptions and henceforth definitely not airtight. However, I just wanted to say that I would have never actually responded to that question itself with how I commented on HN, just to be safe.
Nevertheless I strongly believe in the presumption of innocence, even outside of court, as a general moral rule we owe to others.
Outrageous might of been a little strong though :)
It's only outrageous if you act on the suspicion.
> not known by the security staff.
They may just not care, or at least not make that a priority. If the dongle stuff was done just to comply to some norm or regulation, actual security could be perceived to be secondary.
> The writer already assumes that we think he is lying.
Not quite. He assumes we think he could be mistaken. ("[…] it could be conceivable […] that, in my grief, I remotely logged in, sent the email and forgot I did it"). Still a bit fishy, but not as much as you make it sound.
> is it very likely not to check your email at least just before you show up at work 6 weeks later?
That can be estimated, but not that if it were me, that would be a virtual certainty. I never check my work email outside of work. I go to work first, then I check my email.
> It is a throwaway account.
Of course it is. One does not want to tie a long term account (which may be tied to a meat-space identity) with negative stuff like that. The evidence by throwaway is practically nil.
> Not quite. He assumes we think he could be mistaken. ("[…] it could be conceivable […] that, in my grief, I remotely logged in, sent the email and forgot I did it"). Still a bit fishy, but not as much as you make it sound.
Not quite assuming that we think he's lying, but a very common tell for lies is that the lier is preempting challenges to weak points in the story.
A lot hinges on his location and the exact job, but it smells very fishy that he apparently is set up for remote access to email (so it sounds like a "regular" knowledge worker job where checking your email from not-the-office at times is not uncommon), but when leaving very suddenly, ie. with no time to hand over work to colleagues, as you'd normally do for planned leave, he wouldn't bring the dongle with him, to be able to check in and make sure his colleagues have what they need to move on without him.
Apply Occam's Razor to it. What's more likely; that some unknown person resigned on this guy's behalf or that he resigned and he's going with this b.s. story to save face or that none of this happened? One of the latter two is the most likely.
It's a pile of baloney.
It's fine to say "this is the internet and people invent stories" but to apply Occam's razor you need to actually come up with a motivation that would cause this guy to actually invent this story and post it online.
Why he chose to post is a separate issue. People have any number of motives for doing things, and what you believe to be reasonable explanations depends on how you think about human psychology. Personally I have seen enough people post lies online that I don't even worry about what the motives are anymore. I just look at what I think is more likely; is this story true or not? This story reeks to me. There's no way some unknown person resigned for him. Either he did it and regretted it or this whole story is made up. Both of those are way simpler than the claim that some unknown person logged into his secure email and that the company reacted so nonchalantly to him telling them he didn't do it. If someone hated him enough to write a fake resignation letter and risk their own career like that, he would know who it was.
Frankly it's one of the more obvious fake stories on HN in a while.
I think you should be careful to invoke Occam's razor like this though. It states: "Among competing hypotheses, the one with the fewest assumptions should be selected". You can't compare two hypotheses unless you express all of their respective assumptions.
It's not unusual for database servers to have functions available to send emails from stored procedures - it doesn't seem completely unlikely to me that someone could use something like this to send spoof emails.
This very much depends on the country, and local employment expectations. There's the old joke comparing US and European "out-of-office" auto replies:
US: "I am on holidays, but I'll check in with my email about every night. I can be reached at $PHONE_NUMBER for an emergency"
Europe: "I am on holiday. I will return in 4 weeks."
Even if some coworker had a grudge or a bone to pick with OP, they had to know that OP would return eventually and any CEO worth his salt would demand answers immediately. Specially considering the legal risks exposed here for firing someone on FMLA qualifying leave (assuming US).
Weigh that against a CEO who accepted a resignation and re-hired for the position based on a single email alone without so much as a follow up call. When OP returns seems lackadaisical about investigating. Seems fishy to me.
For instance, I live and work in Saudi Arabia right now, and there is a lot of red tape around firing Saudis in the workplace--even wages are partly determined by your country of origin.
This really seems like the CEO committing fraud to free himself of a problem he felt he had no other way to solve.
That is the part that smells to me too. I don't know any CEO, manager, or person otherwise responsible for employees, that would take a single resignation email as the one and only thing to start the paperwork and rehire a replacement.
The cynic in me, say that the CEO was unhappy with performance and/or the leave. Used his posistion to gain control and send the mail to get the ball rolling.
If it wasn't him, I would fully expect him to launch an investigations right then and there when it became apperant that someone spoofed an email. IT should have all the logs necessary to figure out where the email was send from.
But... what's the motive? Just to be in a different legal position than firing this person (ie, avoid paying unemployment or whatever)?
Forging his resignation probably saved a lot of money for the company...
Crazy what people will do to just save a few bucks.
Ask yourself who had the incentive to leak that paragraph... And it sure as hell made me wonder why I had been "accidentally" sent the document in the first place.
edit: Worth noting, that this was a situation where the amount of money involved wasn't quite high enough to make it worth suing over. So really, it was just a dumb thing to do that didn't make any real difference - I wasn't going to realistically be able to get the money anyway. My best guess is this wasn't an "official" thing the client did, but rather a dumb spiteful mistake made by an individual at the company without the permission of anyone else, and who wasn't thinking about the situation objectively.
> It could’ve been a colleague because I know there is a backdoor way to send emails using someone else’s account via some sort of a SQL database thing. We used to do it as jokes but it was never used for something like this
That in particular is setting off my troll radar.
Anyone can send email from anyone, it's how the email protocol works, that bit is not surprising.
(Admittedly, the "SQL" part seems fishy)
- Someone acting maliciously would have to account for the possibility of the CEO simply picking up the phone and dialing the OP to check in.
- OP specifically mentions the CEO "told/showed me a resignation email". The OP specifically mentioning it was told as well as shown felt like a message from his subconscious mind that the CEO is guilty and had rehearsed how to prove his innocence.
- The CEO gave a definitive statement that another person was already in his position, rather than treat it as a serious issue of fraud and a hostile work environment.
- The OP professing "I don’t care that much about the job" makes me imagine a scenario where the CEO gets to let an unmotivated employee go (or at least one who could be replaced within ~2 months) and keep 6 months of paid leave.
Now, this company has a very strong "talk about it" culture, with super supportive management, etc. No bureaucracy or paperwork anywhere. Nevertheless, my boss was totally surprised that I wanted to talk about resigning. Pleasantly surprised I might add, but still: In his entire career, every employee who had left had written a letter and left it at that.
Why do it that way? Of course I understand if there's fundamental disagreements or deep unhappiness, it's a good way to keep emotions out of the way. But that wasn't the case here, and everybody I know who left that company left it on good terms.
I ask because I'm an employer now. I try to be a good and open-minded boss, and I'd much rather have someone tell me what's going on than receive a letter out of the blue. Is this wishful thinking?
People on a team understand they cannot fire team members, even if they are dickheads. They cannot change what they work on, or double their salary. That means there will be radio silence for the last few weeks or months when they are looking for a new job.
Employees also tend to think the employer already knows what the problems are. If the problems are not being addressed, they will think the employer does not think they can or should be fixed. Why bring up something the employer obviously must be aware of, but has done nothing about?
In my experience, the resignation announcement will, indeed, usually come out of the blue. For an observant manager, it may not become as a total surprise; there are some signs. But almost never will employees discuss with you about these things in earnest. There will be signs, but not forthright discussion.
does anyone know why resignation letters are
so popular in the first place?
My employment contract literally says "Your employment may be terminated either by you or by us by providing X weeks written notice" and while I could work to get that language changed, I don't imagine such a change would deliver measurable business benefits.I suspect many employment contracts are the same, lawyers having seen that clause in some 25-year-old textbook.
Basically leaving work is a formal change in status that deserves to be memorialized in writing, just as the initial contract should be in writing and any subsequent changes would. That doesn't mean I wouldn't also talk to my manager, but the letter is important too I think.
I've always told my boss briefly in person and followed up with a letter. The letter is necessary documentation. It provides proof the resignation occurred (or provides the starting point for a criminal investigation if forged).
The MD is still a good personal friend (he even hosted our wedding reception in his garden) and we've worked together on multiple projects since. The bad boss was let go shortly after I went, when it was looking like another senior developer was on the verge of quitting.
I guess the moral of the story is to never burn your bridges, no matter how bad the situation seems at the time. Plus, as a business owner myself now I'd much prefer the honest feedback so I could actually make improvements that might make other employees' lives more tolerable.
For important things, nothing beats a papertrail. Formal, written records of things can be very useful.
"The letter was a forgery, someone in your company is unethical, and you should find out who.
As far as I am concerned I am thinking of suing, but if you simply paid out my leave I would be satisfied, and finding the unethical employee will be on you."
And that's it. If the CEO is as honest as the question makes him out to be, this should be enough, and it's much simpler. If not, then you lost nothing, and can sue, get a lawyer, etc, as all the answers suggest.
You know to many that type of language would be interpreted as a threat. You might also take into consideration the CEO may legitimately believe the company has done no wrong in this case. Not all people/companies respond to threats by getting scared, many fight back.
The allegation which is being made, is that the company accepted a fake/fraudulent letter. It will be highly unlikely that a company would openly admit to be such a victim, unless it was in their best interest.
> If the CEO is as honest as the question makes him out to be, this should be enough, and it's much simpler.
This is business, a CEO's job is to protect the business not kowtowing to someone who is threatening to sue.
When I was working at a previous company, my manager jumped on my PC and used it to send an email from my account to my colleague, while I was out on my lunch break. It was a joke, which I thought was highly unprofessional. I asked my colleague, and he said that he seen the manager use my computer. I confronted the manager and she owned up to it. I've asked her to explain, and her excuse was that I should have locked my PC and I didn't take it anywhere further. However, I could see how a more serious incident could happen, so I wouldn't be surprised if it was the CEO where hubris can run rampant at those levels. Usually companies would have audit logs of who and when the account was accessed, I would start looking there.
It was a security related company, and the general excuse was that the practice was intended as negative reinforcement to push everyone to have better security practices. I don't know if it was a good or bad culture to have. I can tell you that, to this day, I never leave my computer unlocked.
I can understand the security perspective, but strongly don't agree with the direction it then leads people → "your workmates can't be trusted".
That's rarely a productive thing to add to any high performance culture mix. :(
Pranks are cheap laughs, slapstick humor. It does not belong in a work environment.
Only way for people to ever learn
I'm not entirely certain what the legal status of this in the US, but I know of other jurisdictions (Costa Rica, for example), where employers are forbidden from scanning, logging or viewing personal email accounts or even personal email on work accounts/computers. Hell, they can't even make a back-up of your computer without your permission.
source: Constitutional Court Prohibits Employers from Accessing Computers Without Employee Permission: http://www.elmundo.cr/sala-iv-prohibe-accesar-computadoras-f...
Where I work such jokes are even encouraged by IT personnel to help workers to take security seriously. Of course, nothing harmful is allowed, it's on the lines of "I'll bring cake to everyone tomorrow", "free pizza for everyone", "I owe $10 to X" etc. It's fun and, unlike most security practices, it really works as old-timers lock their PC even when going to restroom and mostly newbies still fall for this.
Forgery is a crime - and I think sending an email from someones unlocked computer would fall under that if it was pressed in court.
If sysadmins have things set up that way, they can unlock a locked desktop and log in as the user; or even change the users account password and log in. Using these two methods as the example I would think no sane person would think it ok to log in and send an email as described. So why is it OK in this case, when a computer is left unlocked?
A normal person should feel guilty digging in another persons stuff - always; and the person who was violated should also be indignant. Period.
What if a boss or coworker had requested you to take care of something on their computer? Is the fact they gave you the access make it ok to look through their browser history while your there? If not, what exactly is and is not off limits during an 'authorized' entry event? And what is different if they left it unlocked instead?
Hope you can see how this opens a huge pandoras box.
Also, if people are not there to protect the team and coworkers, how can they trust each other when it is really important?? What will happen when there is an attacker from the internet forging things? How will you even know who is telling the truth then?
A professional will take care of the problem with a warning or a note. After so many repeat offenses, give the warnings more teeth, and/or start tracking them and provide punishments. Alternatively lock the desktops with an inactivity timer.
Just realized maybe you are trolling (or hoping you are!).
I know of companies that do this, and I totally agree with you. It's done under the guise of security, but is really just immature hazing. First, if I'm in an office environment with fellow employees why is locking my computer so important? Is it to stop the random person from stealing company secrets or impersonating me? If that's the case why wouldn't the other employees around my computer notice someone, since clearly they had to be close enough to notice if I left it unlocked.
Second, if I'm out in public theft is much bigger issue than locking the computer.
Finally, and something you touched on, is that now it makes it hard to differentiate between authorized and unauthorized. It's much easier to say using someone else's computer without their knowledge is grounds for termination 100% of the time.
There are many more important security practices that should be followed, more important than desktop locking, yet they don't attract the same kind of vigilante attention.
In my situation, it was blatant bullying, especially considering the inappropriate content of the email that was sent. The desktop locking was just an excuse. There was no other way you could frame this.
I so agree. I saw things like this in the military. At that time it was tools...
Before aircraft takeoff and between shift changes; all tools must be turned in and accounted for. If one is missing all personnel for that shift and the one coming on have to go together for a tool search at every jet, vehicle, etc. This means every person searches as a team until it is found - this could be 50 or more people, 1/2 staying late from the previous shift! Depending on the supervisor they may also ground the aircraft squadron temporarily- ensuring that the pilots and admin staff also know who lost a tool.
It was extreme hazing - but at least I could assume that it was done for a good reason - true safety. If a jet starts up and a tool gets sucked into the engine bay people can die - not to mention the damage - it would be career ending for those found at fault.
Unfortunately like anything some joker I saw used it as an opportunity to harass someone they did not like. People could pocket a targets tool for a while, and turn it in anonymously at some point into the search when they felt enough damage had been done.
When I saw someone do that and justify it as a lesson - I decided that my integrity is more valuable. I have not regretted that particular decision yet.
I could see how a joke like this can accidentally turn into something harmful. Often these incidents are impulsive and the sender may not think twice about the implications.
That actually worked quite well as an "educative" tool.
I consider it a good method to keep everyone aware of computer security.
Secondly, advice about going to lawyer does not mean sue until it hits the supreme court. It means, get professional advice on the likely outcomes of the different actions. Such as what kind of settlements can you expect, are you like to win on procedural grounds etc... How to best proceed etc... and what outcomes are acceptable to you.
This kind of advice will give you an expected ROI on different approaches that are available to you. Upon which you make an "investment" decision on which approach will be the best for you (not always financial). Normally such a conversation won't take to long and will not be billed at the legal firms top rate.
[1]: https://www.generali.ch/en/privatkunden/haftung-recht/rechts... (which is the one I pay for)
The only acceptable answer.
If someone forged your email it becomes wire fraud thus criminal act under federal law. You should consult a lawyer now.
Getting a lawyer, at a minimum, means forking over a few hundred dollars just for some advice. Going beyond that we're talking hundreds to thousands more for the lawyer to merely write a letter. Going further beyond that, it then becomes the plantiff's "life work" to deal with the court system while paying many thousands to the lawyer for, AT BEST, an iffy outcome after months of drudgery, and yes, then face being effectively blacklisted in the local industry.
That said, there are some good reasons for people to get a lawyer but getting fired with a dirty trick (assuming the dubious story is even true) is rarely one of them.
This has not been my experience at all.
A few years ago I had a dispute over a commercial lease agreement with my landlord. I did all the research I could and wrote a short summary of my position on the matter, along with a few relevant citations. I made an appointment with an attorney and asked that she write a lease addendum that terminated the lease immediately and held harmless both parties, which included my reasoning for doing so.
I paid her $120 for her time to write the letter, and it was invaluable as leverage in negotiating with my landlord - there's a big difference between saying "I'm gonna sue!" and bringing a document to the meeting prepared by your attorney to resolve the disagreement.
Hiring an attorney doesn't have to cost a fortune - you just have to take steps to minimize the time they have to spend on your case.
If they are complicit - it makes a paper trail for others to discover. If they are not complicit then the CEO will get instructed to do the right thing.
All-in-all, the fact that he mentions he exploited security hole in his company and then calls it "SQL thing" screams at me: FAKE
Why? That doesn't surprise me at all. As a (Computer Science) student, there were a lot of jokes (e.g. connecting to other computers, and doing... stuff) involving scripts that most people just blindly copied, without understanding them at all. And I have seen the same last year during an internship.
He probably does not work in a 'right to work' state as the employer would not need to justify their action with a resignation letter.
https://en.wikipedia.org/wiki/Right-to-work_law
The scenario is odd - I understand dropping things to take care of a relative. But a 6-week interval is too great in this day. There should have been some further communication of intent.
It's all fun and games, until ...
If it happened with a script it should be easy to find out by looking at logs and/or header.
Though, seems hard to solve, especially if he is out of US/Europe.
Uh...or be the culprit.
Also, unless there's a personal vendetta, the biggest motive for someone doing this is someone that doesn't want to pay the expense of an employee on leave for awhile.
The company should have investigated if he did or didn't send the email
Most places would escort you out of the building for doing this.