Fired employee deleted servers, causing it to lose S$918,000
channelnewsasia.com
channelnewsasia.com
This is why you don't force employees or contractors to work through their final two weeks. Too little benefit, too much risk.
> After Kandula's contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.
Oh nevermind, it's far worse than just that!
It takes an IT team with skill and a management team that trusts them and their decision making to turn that kind of thing around. It's a similar story of a company that fails to have a working backup or disaster recovery: "everything has been fine and we can't justify the expense", when in reality it's a time bomb.
Those exist?
HR forgot they have to create a ticket for when they ask a contractor to leave early. IT has the account expire on the date the contract expires, but somebody needs to tell them that someone left.
Worked with a number of folks that caused much more than that just by mere accident. Not disgruntled or anything. Just “fat fingered” a command or had a momentary brain fart (deleted prod db instead of backup!).
Guy truly was incompetent and deserves everything coming to him.
- accessed the servers tens of times post employment from India
- returned to Singapore
- lived with another active employee of the company he was planning to attack
- had a script kiddie Google history
- made no efforts to cover his access
It's hard to read in any way but him wanting to be caught, although I'd love a more detailed article to clear up some confusion. It was cold blooded months after, and he moved back to the country where he could be convicted. Wild.
He could have thought that the organization was too corrupt and incompetent to track the attack. He might have been unaware of law enforcement investigation procedures, or jurisdiction risks.
It would be common for script kids to lack sophistication in forensics, legal risk analysis, and not really understand the magnitude of their crime.
Assuming there is no evidence that he was getting paid by a third party to do this, I think his defense could have argued he was a naive and immature prankster that didn't think they were doing real damage, not a hardened criminal intentionally causing damage for profit.
He only got 2 years. Seems light, for nearly a million dollars in damages, right?
A 2-year vacation with free food and housing and criminal advocacy, and then try again maybe with more professional approaches? The birth of a real pro!
Doesn't sound so bad honestly. He'll be 41 when he gets out, and ready to strike again! Maybe he'll get a big brain, and go straight into security consultancy, a la Mitnick! Either way, the kid just made his boldest career move! Wishing him all the best of luck!
When the company let him leave without invalidating his credentials, he developed the idea that he could act with impunity because the company was just completely incompetent on the security front.
The problem was that he acted without knowledge of modern forensics.
> The system that Kandula’s former team was managing was used to test new software and programs before launch. In a statement to CNA on Wednesday, NCS said it was a "standalone test system".
> As a result of his actions, NCS suffered a loss of S$917,832.
Wondering if these are CI/CD pipelines, and how the loss amount was calculated since these can be spun up again.
EDIT: I thought the "If I can't" portion read "If I can" in parent's comment. Disregard, sorry parent.
It's just creating "plausible deniability."
> or look internally to figure out what makes you think this way.
That's easy: Sarbanes-Oxley.
They could just not want to be even considered a candidate for blame.
For example, if I was ever asked to babysit someone, I would want them to install a camera pointing at me at all times, for my sake and their peace of mind.
I don't read any implied threat that they actually intend to or think they might do something harmful, just wanting a CYA in the same way the company wants one.
"If I can't get in, they can't blame me if something goes wrong down the road."
as
"If I can get in, they can't blame me if something goes wrong down the road."
That's the only interpretation that sounds threatening.
Yep, they confirmed it.
It's the same here. If I'm fired from a tech job, the company should do the right thing to protect themselves and lock me out right then and there. It's not because I -- the real me, not the hypothetical villainous me -- pose a risk to them. I wouldn't hurt an ex employer under any circumstances because 1) that's a bad thing to do, and 2) I don't want to be in jail. It's more that best practice dictates they do this. There's no benefit to them whatsoever in allowing me into systems I no longer have a legitimate need to access.
And again, this also protects me. If I'm long gone and something suspicious happens, talk to their current employees, not me. I don't want to access to their stuff, and I couldn't even if I wanted to.
Edit: Ah, honest mistake. I could see why you'd think that given the misreading.
Apparently they had setup their Exchange server poorly and I'd had access to any number of mailboxes (including the CEOs) and other folders that I wasn't supposed to have access to. I was completely unaware of this access, but was being directly accused of having access confidential information.
I insisted, truly, that I wasn't aware of the access and hadn't looked at anything confidential, but they tried to tell me they had proof that I had accessed email I shouldn't have. At this I got upset and demanded they show me this proof, which they couldn't do because they didn't have any, but I'm guessing they thought I had seen some stuff and they could get me to cave it if they pretended they had proof.
Anyways, I didn't get in any real trouble because I wasn't intimidated, but it damaged the relationship and I ended up quitting a few months later. Now I feel the same way as OP, I don't want to be in a position where someone can make a plausible accusation of misconduct, you could be totally honest and still end up railroaded just for being in the wrong place at the wrong time. CYA.
This is a failure of the company.
An inhumane offboarding would only encourage this.
Unless, of course, our interpretation of inhumane measures is very different.
Theyrevinhumane for more than just security
Literally just revoke the credentials. If you want to be extra, don't be surprised if you find your company source repos on the dark web, for Justice and Profit.
NCS sounds like a clown show based on this article. The administrator credentials should have been changed as soon as Kandula was let go. Ideally, these credentials shouldn't have ever been used and everyone should be acting as themselves with a elevated privilege step.
As for the $678k in damages, why didn't NCS have snapshots that they could have quickly restored? Sounds like their BCDR plans need to be reviewed and updated.
Moral of the story is don't do business with NCS.
full disk encryption is a thing. it's amazing how people who are otherwise technically competent leave such obvious incrementing evidence on computer
Related example: https://en.wikipedia.org/wiki/H._Beatty_Chadwick
https://veracrypt.eu/en/VeraCrypt%20Hidden%20Operating%20Sys...
Just actually get rid of the evidence. Throw your laptop into a shredder and buy a new one. At least get a new hard drive.
Or at least do a full wipe (including backups) and reinstall. "Here's my FDE key, but I erased everything after I left that place and I don't have their stuff anymore."
I discourage this behavior but there could be many cases when this could be useful.
It just keeps piling up!
https://boingboing.net/2013/09/11/how-the-feds-asked-microso...
Some good comments here:
https://old.reddit.com/r/sysadmin/comments/26vm25/why_is_the...
There's more resources on google and I remember attending a talk at either blackhat or defcon on why you shouldn't be using bitlocker.
1. You run rm
2. Your filesystem uses trim to mark the pages as invalid
3. The drive's garbage collector finds blocks containing invalid pages and consolidates valid pages into new blocks and marks the old blocks as invalid.
4. Then the drive resets the block to empty and marks it as available.
This improves write performance because SSDs can only write to empty pages (they cannot overwrite pages that have already been written, instead they'd have to first reset the page and then write a new page) so by proactively resetting pages, they have pages ready to be immediately written.But this also means that the blocks containing your deleted file will be proactively reset/emptied which means it will uncharge the cells which is equivalent to all the bits being `1`, thereby destroying the file.
> NCS is a company that offers information communication and technology services.
And more importantly, this:
> After Kandula's contract was terminated and he arrived back in India, he used his laptop to gain unauthorised access to the system using the administrator login credentials. He did so on six occasions between Jan 6 and Jan 17, 2023.
The company is not just ignorant, but massively incompetent.
You don’t fire someone without totally withdrawing every last shred of access they have. The fact that he was able to use a common, generic administrative credential shows that NCS fails epically at even the simplest of security.