When you should know it's criminal, "just following orders" isn't a great defense.
> but I do hope they at least recognize and think about how their actions enabled this whole mess.
They should get lawyers. And be prepared to sing like canaries.
When you should know it's criminal, "just following orders" isn't a great defense.
> but I do hope they at least recognize and think about how their actions enabled this whole mess.
They should get lawyers. And be prepared to sing like canaries.
That's even true in the military if you're given illegal orders. It's called the "duty to disobey".
It's not enough that employees "should" know what's illegal and what's not in an exchange -- companies need to be held criminally negligent for employing people who don't know.
If my boss came to me and said, “continue showing customer funds sent to our “sister” investment company in the staff dashboards” I wouldn’t find that suspicious. I would probably push back and say that might be confusing unless we separate out that amount and rename the total to something that denotes part of this value is with our sister company. But I would assume design incompetence and not fraud.
But then again if I was just one of a handful of devs that worked with the company I would probably find it suspicious, as I would confidently know that nowhere else in the codebase do we support a close integration with our sister investment company and should therefore know we shouldn’t treat them any differently.
Also the modification to exempt the investment company from risk rules does seem suspicious, unless again you believed there was an integration somewhere and believed investment risk mitigation rules were handled on the other platform or something.
But that's why software "engineers" have quotes around "engineer"