Former Microsoft tester sent down for 9 years after $10m gift card fraud
- Reference: 1605015027
- News link: https://www.theregister.co.uk/2020/11/10/microsoft_fraud/
- Source link:
The defendant, Volodymyr Kvashuk, had been found guilty of all 18 offences with which he was charged, including wire fraud, money laundering and "access to a protected computer in furtherance of fraud" [2]earlier this year and was sentenced by US Washington district judge James L Robart yesterday.
Sentencing had been expected on 1 June, and Kvashuk was facing up to 20 years.
Kvashuk had been a member of a testing team for Microsoft's online store between August 2016 and June 2018, employed variously by a third party and Microsoft itself. The team was tasked with ensuring that the purchasing process was a smooth one and able to set up accounts for the purposes of testing.
Those accounts bypassed Microsoft's fraud checks because they were just for testing. The delivery of actual physical goods was blocked.
However, the complaint
[3]PDF
noted that "Microsoft did not anticipate that testers would make test purchases of digital currency... and thus no safeguards were put in place."Kvashuk made use of his role of tester, according to the complaint, to "fraudulently obtain over $10,000,000 in CSV [digital currency such as digital gift cards]". The scam saw Kvashuk make use of reseller websites to offload "at least some of the CSV to third parties", who could then redeem the codes and purchase items from Microsoft.
The thefts began small; Kvashuk initially stole smaller amounts totalling approximately $12k using his own account access. Things soon escalated, and the engineer made use of test accounts associated with other employees and a bitcoin "mixing" service to conceal the source of the funds flowing into his bank account.
Approximately $2.8m of bitcoin were transferred, which Kvashuk claimed "had been a gift from a relative," according to the Department of Justice.
As well as putting other Microsoft employees under suspicion, Kvashuk's scheme allowed him to live, albeit briefly, a high life. He drove a $160,000 car and lived in a $1.6m lakeside home.
At his trial, Kvashuk insisted that defrauding Microsoft had not been his intent. Indeed, he was working on a special project "to benefit the company" according to the US Department of Justice.
It took a jury five hours after the five-day trial to return the guilty verdicts.
As well as the nine-year sentence and $8,344,586.31 restitution
[4]PDF
he was sentenced to pay, there is every chance that the Ukrainian citizen will be deported at the end of his jail term. ®Get our [5]Tech Resources
[1] https://www.justice.gov/usao-wdwa/pr/former-microsoft-software-engineer-sentenced-nine-years-prison-stealing-more-10-million
[2] https://www.theregister.com/2020/02/26/microsoft_dev_fraud/
[3] https://regmedia.co.uk/2019/07/17/us_v_kvashuk.pdf
[4] https://regmedia.co.uk/2020/11/10/ms_kvashuk_verdict.pdf
[5] https://whitepapers.theregister.com/
Volodymyr Kvashuk -- Is that Russian for....
full load o' my cash?
Wow.
That's like 99.9999% of all money "spent" in Microsoft store.
He drove a $160,000 car
Flaunting your wealth is a good way to draw attention to yourself and get caught. A lowly employee pulling into the car park in a bigger & better car than the boss is a sign that something may be afoot.
Want to build a secure system?
Think like a criminal.
Unfortunately this wasn't built by such people.
You can't deny he really "tested" the system though.
He just got too greedy
Big company accounting rounds on 5 digit numbers for the most part. If something like this were carried out under the radar for years, it's very possible it would have slipped through the cracks. Showing up to work driving an insanely out-of-character car is probably the best way to get the forensic accountants on your scent. But especially in IT, and especially if you control both sides of an approval process, fraud can go undetected for years. There's tons of stories of regular old IT Joes stealing millions in equipment and eBaying it, all because no one was watching where the equipment went once bought.
Once you've tripped the fraud sensors, that's pretty much it. Those irregularities that would otherwise have gone through the system will start showing up everywhere and there's nothing an accountant/fraud investigator will stop at to hunt them all down.
Either be honest (best policy) or steal little, not big.
There's nobody I hate that much...
Microsoft gift cards, eh?