CEO of Cyber Fraud Startup NS8 Arrested by FBI, Facing Fraud Charges
forbes.com
forbes.com
- where are the contracts corresponding to revenue? Yeah they are SaaS focused on SMB but this is a financial product, there will be contracts, NDAs, etc
- if the majority of the customers are fake there is such little load on the system. How does engineering not figure that out?
- How does no one see an insanely low COGs when paying the cloud services bills, or the lack of allocated resources when looking in the management interfaces?
- Even saas Products with supposedly a no touch sales process still have sales people and sales engineers for key accounts. What are all the sales people doing if they’re not running trials?
- let’s say he hid all of this by having tens of thousands of $10 a month customers. How does your VP of sales not get totally freaked out that the overwhelming majority of revenue is coming from no touch sales? If that’s the case that radically changes your growth and go to market strategies. The entire go-to- market team should be wondering what is going on? Same with product management. Your roadmap would be completely different with a long tail of extremely low revenue customers.
- how does sales/client success not notice that no one is expanding? How they aren’t talking to small customers about expansions?
- How does no one notice a complete lack of analytics or actions being generated by all the supposed customers?
- product management is going to want to get feedback from all of these customers. They’re going to be looking in analytics tools or session replay tools like fullstory. They’re going to look at the accounts and users and do outreach to emails asking for meetings. Aren’t they going to notice all of those people are fake?
- support/client success is going to have insanely high customer to support person ratios. Where are all the support tickets for that many customers?
- Managing cash flow would be very hard. Finance is going to see all this revenue coming in and want to scale. The VCs are going to want to see money being spent on marketing activities etc. to further the growth. If there’s no corresponding revenue being spent to acquire customers but tons of revenue coming in that’s a giant red flag
Noone gives a shit when they're getting paid.
The other bank account had tens of millions in there thanks to the investment money.
The layoffs came once the board faced the truth of the matter and Adam Rogas suddenly resigned.
SMB, especially the small end of SMB, does not often have contracts. It's more subscription based. That said, there were 2 versions of the software running at NS8. One was the original software that Adam Rogas and a co-founder created early on. That version was rather "opaque" and reported growing customer numbers every month. The newer version of the software was controlled by the product dev team but still reliant on the original software in some key areas. Basically, everything was obfuscated well enough to confuse everyone to the point where answers of, "it's a limitation of the original software" were taken at face value.
- if the customers are fake there is no load on the system. How does engineering not figure that out?
There were real customers and the customer growth was happening, especially in 2020. The problem is that the customer base and growth was nowhere near what Adam Rogas was cooking up on the backend.
- How does no one see an insanely low COGs when paying the cloud services bills, or the lack of allocated resources when looking in the management interfaces?
COGs and other bills were kept relatively high. It's also why the company hired 200+ people, to make the story all the more believable.
- How does no one notice a complete lack of analytics or actions being generated by all the supposed customers?
Again, real numbers were difficult to gather for excuses given repeatedly by Adam Rogas and others charged with providing those numbers. I'm not saying that others were complicit in the scam, but that they were (at least) being fed the same excuses the rest were. Investments were never made to bring visibility to the customer metrics. Was this a red flag? Yes, but then why are investors giving NS8 so much money? It's hindsight 20/20.
- Managing cash flow would be very hard. Finance is going to see all this revenue coming in and want to scale. The VCs are going to want to see money being spent on marketing activities etc. to further the growth. If there’s no corresponding revenue being spent to acquire customers but tons of revenue coming in that’s a giant red flag
Right, so plenty of money was being spent across the board. There were 2 bank accounts according to the DOJ and SEC complaints. The account for "customer revenue" was solely controlled by Adam Rogas. The other account held the investment funds that paid all the bills. Is this super shady? Yep. And it seems there was an NS8 whistleblower who kicked off the initial SEC investigation and then the FBI getting involved as well.
And the CEO or others saying “oh yeah you can’t see all those customers and growth because they’re in this old legacy system that doesn’t report it” is an insane excuse to buy. Holy shit you mean to tell us that the majority of our most important revenue is coming from a legacy systems that we have zero insight into? And it’s continuing to grow? Why aren’t those people on the new system?
> “customer revenue” account controlled solely by the CEO
I cannot fathom a VP of Finance, let alone an outside accounting firm, that would be OK with this arrangement of accounts.
Edit: To be clear I’m not trying to blame the victims. This is a terrible loss to all the employees who have been pouring so much of their efforts into the company. I just am having a hard time understanding how such a thing could happen. Maybe I’ve just been blessed to work in extremely transparent organizations.
> I cannot fathom a VP of Finance, let alone an outside accounting firm, that would be OK with this arrangement of accounts.
Right? Then again, EY audited everything and gave those fake bank statements the "thumbs up" as part of the last round of funding and due diligence on the part of the investors. Crazy.
https://markets.businessinsider.com/news/stocks/ey-chairman-...
There were real customers and the customer growth was happening, especially in 2020. The problem is that the customer base and growth was nowhere near what Adam Rogas was cooking up on the backend."
This doesn't really answer the question. The article states 40-90% of customers were fictional, as a cloud architect I would have to design based on the number of customers ++ and of course I would setup monitoring and alerting with auto scaling and it would be blatantly obvious that my utilization was not going up and that would turn into an engineering investigation.
Would it leed me to the idea that most of our customers were fake? probably not. They might not even request additional capacity, but as a architect that would lead me to ask questions. For example after an announcement or company meeting where they announce the number of new customers, I would wonder wtf? How is it that we haven't added any more capacity for all these new customers?
I would see some red flags and I would like to think I would be smart enough to start looking for something new but I haven't been in such a situation thankfully.
It's difficult to read about 200 ppl being laid off and the impact on them and thier family all bc of one stupid, greedy person.
Nothing like this ever happened, AFAICT
> I would see some red flags and I would like to think I would be smart enough to start looking for something new but I haven't been in such a situation thankfully.
"Brazen fraud" is not where Occam's Razor leads in this case. "Transparency growing pains" seems much more likely. Specifically - if working for this company I would raise concerns that there aren't KPIs being regularly tracked across all functions. I'm sure it's possible that some of the newly hired senior management was working on this.
Big data and a flawed system. They sell a service that is based off of using integrations. If you stop paying for the integrations, you should stop receiving the service. That in turn hurts their level of service offerings.
To be of any value, they have to monitor a ton of transnational data. So even if you quit paying, they still monitored your data and their modules were flawed that is still showed their acceptance score if you stopped paying.
Usually, the upper management teams are extremely lean. The business is broken up into different silos such that few people can see the big picture. Each is led to believe they are a tiny fraction of the overall revenue, giving them the impression that the bulk of the company’s revenue must come from another department where they have no visibility. As a bonus, this motivates siloed teams to feel like they need to catchup to the rest of the company, when in reality they might be the main driver of it. It helps to have separate offices and a culture of secrecy to prevent people from comparing notes.
The CEO positions himself as a controlling, micromanaging individual at the center of everything. This makes it possible for the CEO to intercept financials and other crucial numbers en route to people who might catch on.
The rest of the management staff might be filled with people too inexperienced to recognize that something is wrong. They might think the CEO is doing them a favor by giving them a golden opportunity to advance their career into an executive position at a rocket ship startup. They don’t know what they’re doing, but they think it’s okay because the CEO has taken them under his wing.
At scale it becomes difficult to do this without at least a few people being complicit, though. A fraudster usually has several close associates who can be trusted to be in on the fraud or at least look the other way for a while.
Here's an example: When Enron's CEO verbally attacked wall street analyst Richard Grubman for questioning Enron's accounting practices, Enron employees thought this was hilarious and adopted the insult as a sort of inside joke. They didn't consider Richard Grubman's position, they just took delight in 'their team' dunking on 'opposing team.'
The question I keep asking myself is, if not now, then when?
I wonder what happened after that? Could he continue working as if nothing special, just failing to raise money?
The industry has largely moved away from this structure for a variety of reasons. One of the problems is that traders start to try and undermine each other, since the only thing that matters is your personal pnl. Another problem is that traders can unknowingly all pile into the same investments, resulting in massive risk. This is part of the reason why the Great Recession was so bad.
https://www.newsday.com/business/columnists/help-wanted-carr...
Giving all of your employees two weeks unannounced vacation at random times is a disruptive way to run a company. It's certainly innovative but I wouldn't say it's HR "done right".
Yeah. That doesn't work. Forcing the same thing in a scheduled way may be a bit of an imposition but isn't unreasonable in general.
Large companies simply have different risks. If someone quitting randomly is a huge risk for your business you want to know about it ahead of time to mitigate it while they still work for you. 1 random week of vacation every ~3 years shouldn’t be a big deal, and discovering it was is valuable.
I know firefighters often work 72 hour straight shifts. For a similar reason, I know being a firefighter isn’t the right career for me.
I suspect some jobs need to optimize days off for things other than employee happiness. For trading specifically, they can generally make up for it with above average pay.
And even when they end up raking in the bucks, for the shareholders it's nothing compared to what it could have been.
https://grizzlyreports.com/research/
Some interesting stuff here.
The company of course refuted the research with some vague stuff about APIs having encryption so the data would be wrong. This was back in June and the stock seems to be still going along strong... http://gsx.investorroom.com/2020-06-03-GSX-Refutes-Grizzly-R...
I once had a (majority-share) cofounder CEO who, when the company hit success, became extremely controlling with the books and investor relationships. There was no way for the rest of the cofounders - let alone engineering - to know what was actually going on or what the true state of health of the company was. I (and the other cofounders, and the senior engineering staff) walked away. Big life lesson.
With lazy enough investors, it wouldn't surprise me that a CEO/owner could compartmentalize enough information that the employees and investors might have totally different understandings. The CFO would be suspect, though.
I wonder what happened after that, how did you leaving affect the company
You'd think some folks working from there would wonder "Hey, does anyone KNOW anyone else working at the other factories, because we're only making X per day..."?
Wirecard opened a fake Bank Branch from a Philippines Bank in Singapore, had the EY guys walk in there and "verify" the Billion dollar balance on the computer screen.
The company was audited twice, but the auditors tied the fraudulent bank statements to the fraudulent financial statements (woops).
> In any case, it will be interesting to see what consequences there are for board members that appear to have failed in their basic responsibilities.
Full cooperation with the SEC can get you a long way, especially if you're one of the victims of fraud.
I guess if an audit couldn't catch this, you have the wrong auditor. This is exactly what audits are for.
Update: filing Is here: https://www.justice.gov/usao-sdny/press-release/file/1317641...
Relevant Passage: “As part of its due diligence process, the Audit Firm had an employee (the “Auditor”) conduct a physical site visit at NS8’s offices in Las Vegas, Nevada. The Auditor was directed by a more senior Audit Firm employee to have someone from NS8 log in to the online portal for each NS8 bank account, display the current account balance, and download monthly bank statements for fiscal year 2019.”
“Based on my interview with a member of the NS8 finance department (“Finance Employee-1”), I have learned, among other things, that on or about March 11, 2020, Finance Employee-1 and ROGAS met with the Auditor in ROGAS’s office. The purpose of that meeting was for ROGAS and Finance Employee-1 each to log into the online portals for the bank accounts to which they had access (for ROGAS, the Revenue Bank Account) and download monthly account statements for the Auditor. During that meeting, Finance Employee- 1 logged into the online portal for the Expense Bank Account -- to which Finance Employee-1 had access -- and downloaded monthly account statements. Finance Employee-1 understood that ROGAS was doing the same for the Revenue Bank Account during the meeting”
Engineering would be the most distant from customers, I guess, but even they must've noticed how few bugs were coming in.
Hard to believe it wasn't found out earlier.
If you cannot respond - totally fair :)
Your comment makes little to no sense.
Maybe you should think about that a little bit more if you really feel sorry.
And everyone who should do something about it having their heads buried?
A. Misplaced sand.
d. As part of its due diligence process, the Audit Firm had an employee
(the “Auditor”) conduct a physical site visit at NS8’s offices in Las Vegas,
Nevada. The Auditor was directed by a more senior Audit Firm employee to have
someone from NS8 log in to the online portal for each NS8 bank account, display
the current account balance, and download monthly bank statements for fiscal
year 2019.
e. Based on my interview with a member of the NS8 finance department
(“Finance Employee-1”), I have learned, among other things, that on or about
March 11, 2020, Finance Employee-1 and ROGAS met with the Auditor in ROGAS’s
office. The purpose of that meeting was for ROGAS and Finance Employee-1 each
to log into the online portals for the bank accounts to which they had access
(for ROGAS, the Revenue Bank Account) and download monthly account statements
for the Auditor. During that meeting, Finance Employee-1 logged into the online
portal for the Expense Bank Account -- to which Finance Employee-1 had access
-- and downloaded monthly account statements. Finance Employee-1 understood
that ROGAS was doing the same for the Revenue Bank Account during the meeting.
f. Late in the evening on or about March 11, 2020, the Auditor emailed another
employee as follows: “Attached please find the bank statements and
screenshots that I observed [Finance Employee-1] and Adam [ROGAS] download this
afternoon.” Attached to that email, among other things, were the
Fraudulent Bank Statements for the Revenue Bank Account for the period from
January 2019 through February 2020.In the audits I've seen, the standard procedure to get the same information would require the company to authorise the auditors so that they could get a written confirmation of the funds directly from the bank or whoever holds the assets or debt. You would not trust the account statements that the company gives you, you would get the same (hopefully) account statements yourself. Accepting that watching a company employee log in some site is equivalent to getting an official confirmation from that outside third party is .... interesting. The whole point of an audit is to verify if everything that the company shows you is actually true instead of looking at what they show you and believing it.
Agree with the other comments, the auditor should get the reports independently or use their own laptop to login/get the report.
I don't find that ironic at all. Having worked in the security space for a long time, it seems like the best people in the business are the ones who would be great at committing the crimes if not for their own morality.
Someone with a weak sense of morals could easily turn to evil.
There's a three part documentary series here (Swedish): https://www.svtplay.se/guldfeber-stolderna-pa-kungliga-myntk...
It reminds me of all those bogus security/antivirus apps on the Google Play store that harvest more user data than any virus ever could.
https://www.law360.com/articles/1311477/giuliani-allies-char...
Initial meeting-> NDA -> some due diligence -> letter of intent/term sheet (depending on the transaction) -> 30-45 days of very deep due diligence.
So was the investigation disclosed to Lightspeed and they decided to invest anyway? Who on earth would invest with someone currently under investigation for a scheme to defraud investors? And if it wasn’t disclosed, why not? Did that not come up at all during due diligence?
Wirecard's long-time auditor!
If your CEO is actively siloing all financial and customer information, your entire company needs to speak up and get on the same page. Don't let this happen to you.
The fake financial statements were publicly released: https://www.justice.gov/usao-sdny/press-release/file/1317641...
FWIW, I would wait on returning any money (or saying anything at all, really) + talk to a lawyer with experience in bankruptcy (their's + yours).
My guess is you can keep all/most of the $. They were fraudulent to you + the company is now evaporating. Sounds like you still need to pivot, but at least you can do so with $ in the bank and no black marks.
In most cases, your finance team (internally) will be the one to pick up on the fact that stuff doesn't make sense.
They won't be able to tie the invoices to subsequent payment to get an accounts receivable schedule to show who still owes what.
They won't be able to get the stripe reports / merchant clearing disbursement reports to agree to the GL clearing accounts.
It's also rare for the CEO to have the only access to bank statements. Fraud risks are often higher in finance team, as they are the ones who catch problems elsewhere, but can be hard to catch problems with them.
This make me wonder how experienced the startups accounting team was.
Or are there other startups they've invested in that just haven't been found out yet? If I was one of their LP's I'd be asking some hard questions.
It seems to me like this company's base value proposition, that is, for any company's monetary transactions with customers, give that transaction a risk assessment score based on whatever data about the customer is available.
That, in its simplest, most elemenatary, most basic form, is a good value proposition.
Companies would find value in software which could deliver that proposition (a related idea that comes to mind is if PayPal decoupled their fraud prevention software, and sold that software to businesses separately, then that software would deliver an equivalent value).
So the base value proposition of this company (assuming their software actually works) -- is a valid one.
What seems to have done this company in, however, (if the article is to be believed) is accounting fraud, which may have been preceeded by lack of customers, lack of revenue or expected revenue.
It's always an interesting question to me (correlation vs. causation-wise) if lack of sales triggers accounting fraud, or if accounting fraud just sort of happens on its own...
You know, here's an idea for the FBI or other related investigative agencies -- you could, based on previous cases, create a list of "risk factors", each of which would count towards an overall "risk score" -- of something being seriously wrong at a company.
Such factors would include, but not be limited to: How much debt a company has to investors, how much revenue is it making relative to that debt, what is its growth rate, what is the age of the CEO, what industry is it in, etc., etc.
Grab all of that data, from all companies, run it through a machine learning algorithm, get a "risk score" for each and every company, then if you have nothing better to do (free time between other investigations), start investigating the companies with the highest "risk scores". <g>
You know, you might call it "Cyber Fraud Detection Software" -- for large companies... <g>
Then if that works well in the U.S. -- give the software (for free!) to all other countries!
Also, the same set of ideas and Machine Learning -- could be used to track wasteful government spending (foreign and domestic), or wasteful spending of so-called charitable organizations...
The possibilities are truly endless!