Cloud engineer gets 2 years for wiping ex-employer's code repos
bleepingcomputer.com
bleepingcomputer.com
The access should have been cut off right away.
> The only reason this happened was because they failed to secure their own systems, it was bound to happen
Instead, parent said:
> IT also failed to put enough checks here
My emphasis on the "also".
Jail the guy, and let his story stand as a warning to implement proper IT and HR practices.
Think of it as if he had stolen money from them after being fired: there’s no question that the culpability would be his but also regulators and insurance would descend on the bank’s management asking why they lacked such basic internal controls for such very well-known risks. Most places will remove all forms of access as soon as the decision is made to fire someone because it’s the most likely time to have anything from theft to, in the US, a workplace shooting.
When shitty policies are part of the root cause, then yes, the victim also shares in creating an environment that allowed easy victimization.
You wouldn't secure your laptop in the front seat of a car in NYC or Chicago. Just as you are not to blame with the vandalization and theft of said equipment, you also could have did easy mitigations to hamper it.
People who shout "victim blaming" are also refusing to take responsibility for reasonable remediations that would have prevented the bad thing.
In my orgs, when HR TELLS US, in advance, we nuke the creds while they are discussing the term with HR. If HR doesn't tell us, then we have zero way of knowing to kill their account.
When they don't tell us, then termed users continue to have access... again... because we have no way of knowing to term the access.
I was able to recover it from OneDrives second recycle bin so nothing was lost, but I was livid. This employee was literally being fired because they were refusing to train anyone else on their work for "job security purposes", it's not like we didn't have warning this wouldn't be graceful.
They tell IT in advance and maintain the schedule and contact us to adjust or DRAMA. Lots and lots of drama.
Had I been in that situation, I would taken that garbage to my direct Super, which is usually the CFO. I would explain why this is such a horrific idea. They usually agree. If they don't, then I look for somewhere else to work, since I cannot keep PHI secure, when I cannot control who has what access and when.
I'm not going to be held responsible when others callous actions remove all the guardrails. No thanks.
In terms of higher-ups notification the "oh shit can you recover this" call came from the CEO
I don't know what happened to the manager. I can't imagine it ended well for them, pretty much that entire section of the org was on thin ice (acquisition that didn't want to absorb into the company) so I can't imagine it ended well. I know we didn't pursue legal action against the ex-employee, which pissed me off at the time, but I can see the logic in leaving it done and dusted.
The only PHI the company held was what HR had on it's the employees, so not at risk here.
I'm glad to know you didn't suffer for this. It happens so much in the tech world that most of us have installed creature comforts in the space under the bus. I've installed a nice recliner, a small, but tasteful lamp and a few good books to read, during my time under it.
Though I've heard it's quite common in large enterprises that are fragmented due to a lot of aqui-hires, for corporate HR to forget or miss people they supposed to fire and who still remain on the payroll, especially on the satelite offices where there's no on-prem HR and nobody really knows what's going on from central.
A friend of mine was theoretically fired along with his entire team but just not him because corporate HR forgot about him or something, so he still showed up at the office without his team and without any work to do, badged in and played videogames all day for almost a year while getting paid in full, until some other people started asking "hey, who's is this guy and what does he actually do here all by himself?", then they actually fired him, or more like paid him a generous severance package to leave voluntarily in silence and not tell anyone about HR's blunder.
Lucky bastard.
Not a silver bullet, but it covers a majority of these cases.
On the other hand, in a just world, continuing to show up would make it impossible for the company to try and claw back the money. He was available even if nobody asked anything of him.
I am more interested in how he was caught. There are many people around me who seemingly do nothing, he would just blend into the crowd. Were there layoffs or some other accounting of personnel that forced the issue?
It took 8 months for the store to realize this and fire his butt. In his case, it was a meeting. It was an All Hands, his timecard showed he was clocked in, but never appeared at the meeting.
He had to show up at work because he was never formally fired. If he hadn't showed up at work but still collect his paychecks then it would have been breaking the law and the company would have clawed back all paychecks. By showing up at work he was just fulfilling his contractual obligations, it wasn't his fault nobody gave him any work to do so he was legally entitled to collect paychecks while playing games and doing side projects at work.
> There are many people around me who seemingly do nothing, he would just blend into the crowd.
Not always the case. It might be a thing in large enterprises of US/Anglophone countries from what I noticed, but in German speaking countries it's not really common for people to show up at the office and do nothing all day, the efficiency and work ethic tends to be relatively higher, especially at smaller offices. So you stand out, people will gossip and eventually someone above will inquire about that guy without a team doing nothing.
Sure, you can lie to everyone around you about why you're still here without your team doing nothing so they stop asking questions, but lying can still be considered a felony here if the thing ends up in court and get you in actual legal trouble later as they will still find out eventually about you, so it's best to be honest and legally enjoy the ride while it lasts.
Milton has entered the chat.
I've worked at small (<1000 people) firms where there were at least 10 different entitlements systems and removing someone was a nightmare. I can 100% believe that this also happens at large companies (due to acquisition as you mention) too.
Here's an example of how Microsoft supports auto-provisioning from SAP Successfactors for this: https://learn.microsoft.com/en-us/entra/identity/saas-apps/s...
The budget to pay for it.
There has been pushback, but I'm always willing to walk away from jobs that insist on stupid.
...Including the IT guy who was responsible for killing everyone's access credentials...
All of us that were laid off watched the company-wide zoom where the CEO tried to blame everyone who had been laid off as dead weight. They managed to get the other IT guy to kill our credentials the following week.
Then they laid the other IT guy off before anybody had sent in their work laptops or other work equipment because the CEO decided that if the offices were going to be closed indefinitely we didn't need an IT guy. The company had to write off more than $1 million in assets that were never returned, including a number of very expensive, very new RED cameras.
A lot of times, IT's "failures" are just the failures of management.
I’m also surprised the secret service was involved. I wonder if they suspected foreign involvement or considered it a matter of national security because it was an attack on banking infrastructure?
The Secret Service started out as an anti-counterfeiting service, expanded into VIP protection, general national financial system security, and for a while general cybercrime, though the latter (outside of where it touched on the other Secret Sevice functions) fell away.
“We also protect the integrity of our currency and investigate crimes against the U.S. financial system committed by criminals around the world and in cyberspace.” https://www.secretservice.gov/about/overview
> impersonated other bank employees by opening sessions in their names
https://docs.github.com/en/repositories/creating-and-managin...
>Accessed FRB's GitHub repository and deleted the hosted code
Did he get extra time for grok references? It’s just an odd thing they added to the list.
Some men just want to watch the world burn.
Ugh, it could be anyone of us!
Section (a)(5)(A): knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer
And this is why you have one laptop for work, and one for personal stuff, and never use your work laptop as your personal laptop.
It seems like companies either have a strict USB policy, or don't. If they allow USB drives, it feels odd to me to fire someone over a drive containing porn. What if it was a genuine mistake of confusing two drives or something? Or a genuine drive that happened to just contain something copied by accident.
But if OP was say, copying, streaming, or uploading the files, then that seems like a more clear violation than what the article states.
I can see some firms afraid of porn but distributing leaflets about safe fentanyl use, lol.
I saw a VP keep their job after a drunken accident at a corporate function where they broke their leg.
The crazy thing is, it wouldn't surprise me if they did this on purpose to capitalize in the future. How else can they get $529,000 to copy git repos from a backup back up onto GitHub?
Unless maybe they have no backups in which case, how is it possible that a banking institution could have code that lasted 50+ years without backups. Also the damages without backups would likely be more than $529,000 because they just lost the entire history of their apps.
This line gave me a chuckle
> As alleged, Brody left a few "taunts" in the code that he unleashed on FRB. In particular, he is alleged to have used the word "grok," which the government explains is a misspelling of "grock," which, in turn, means to understand.
What is this, 2005?
We typically allow exceptions for those that have a common need to use a flashdrive and cannot leverage the typical network for access to the data.
That being said, we prefer not to create these exceptions, for reasons just like this, but it's not always our choice.
My interest is in what kind of grand mal idiot thinks throwing pr0n on a work computer is a good idea!?!?
A naive guy that maybe doesn't think everything he does on the computer is recorded.
It's not about if you are being monitored, it's more about you don't know when/if you are being monitored and how, so why risk it over garbage like pr0n?
I know this, because I've been asked to monitor a number of fellow emps in my career (SysAdmin/Support) and there are just too many bases to cover, so why even bother?
There's simply no way he couldn't afford some beater laptop.. (pun intended..lol)
I doubt sneaker-net will die anytime soon. There's literally nothing simpler, faster, more reliable and universally compatible for short distance file transfers than a USB drive.
Sabotage is sabotage. Just because it was done with a computer is of little point here, other than the specific law to target.
Kind of like how working in software dev as a contractor typically nets you more raw money than working in a comparable role doing a similar job for someone else. However, as a contractor you are responsible for paying for things like health insurance yourself. As a hired employee, you will typically have those things provided to you by your employer, but you will get paid less in raw money, because those things get priced into your salary (sidenote: which your employer probably has a discount rate for anyway, so even if it was paid out to you in cash and you paid your own insurance, you would have had net less money, so it is kind of a comparative win-win for both sides here).
For me personally as an employee, I would rather my employer be able to fire me for watching porn on my work equipment or be able to go after me for intentionally sabotaging company’s infra. Because I do not plan on doing either of those things, so just having that extra money in exchange for not being able to do those things unpunished is the easy choice, personally.
Except that’s not really true throughout most of Europe. Yes firing someone for sucking at their job might be more expensive. All the other stuff? Not really, as long as you can prove it
I am not from EU, so I was mostly going off the comment in this thread that was lamenting how “terrible” employment in the US due to employees being easily fireable for watching porn on employer-provided equipment. What you said makes it sound way more reasonable.
There are loads of cases like that in the EU. Going to prison I never heard of, but depending on jurisdiction, I assume it's also a possibility if the damage is large enough and affected other parties not just the business of your employer.
Better workers' rights protect you from employer abuse, but don't absolve you from responsibilities of your own actions at work.
You're going to navigate the legal system in India or China because some kid you hired for cheap decided to vandalize your codebase and database? Good luck.
Like, is that supposed to be a brag that in EU it is nearly impossible to fire an employee for watching porn on the employer-provided work equipment? If anything, I would consider firing them for being so stupid as to not consider one of many easily accessible alternatives that they almost certainly had access to, like a smartphone (just hopefully not an employer-provided one).