News: 1616517189

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Outsourced techie gets 2-year sentence after trashing system of former client: 1,200 Office 365 accounts zapped

(2021/03/23)


A California federal court has sentenced a "vengeful" techie to two years in the clink after he deleted 1,200 Microsoft user accounts belonging to a client.

Deepanshu Kher, a Delhi-based employee of an unnamed IT outsourcing firm, was tasked with helping a company (also unnamed) in the coastal city of Carlsbad, California, migrate its Office 365 environment.

[1]

According to court docs, he was flown into California in 2017 "to assist with the migration." Dissatisfaction with Kher's work led to him being pulled from the project by January 2018, and some months later he was terminated by his employer.

The Department of Justice said that two months after his June 2018 return to India, the 32-year-old decided to exact "revenge" by breaking into the systems of his former client and deleting as many Office 365 accounts as he could find, nuking 1,200 (80 per cent) of a total 1,500.

[2]

[3]

An autumn day on the streets of surfing town Carlsbad City, in California

The DoJ noted the verdict from district court judge Marilyn L Huff, which said Kher had "perpetrated a significant and sophisticated attack on the company, an attack which was planned and clearly intended as revenge."

In the short term, this meant that work at the company ground to a halt, with employees unable to access their emails, contacts lists, calendars, documents, or Microsoft Teams.

Kher's actions also resulted in ongoing IT woes that lasted for three months, with employees unable to fully rebuild their contacts list, access previously available shared folders, and receive meeting invites or cancellations. Commenting on the incident, the firm's beleaguered IT veep said: "In my 30-plus years as an IT professional, I have never been a part of a more difficult and trying work situation."

The IT consultant was arrested in early 2020 after flying into the US oblivious of the existence of a warrant, thus avoiding a potentially lengthy extradition process. He entered a guilty plea

[4]PDF

in October last year.

IT plonker stuffed 'destructive' logic bomb into US Army servers in contract revenge attack [5]READ MORE

In addition to two years of hard porridge, Kher was sentenced to three years of supervised release, and ordered to pay a $567,084 penalty – the same amount paid by his former client to clean up his mess.

"This act of sabotage was destructive for this company," said acting US attorney Randy Grossman in a [6]statement . "Fortunately, the defendant's revenge was short-lived and justice has been delivered."

"The FBI was able to identify, arrest, and prosecute [Kher], despite the fact that he committed this harmful [act] while outside the United States," added Suzanne Turner, special agent at the FBI's San Diego Field Office.

[7]

"This case shows the commitment, expertise, and reach of the FBI in working cyber intrusion cases. We encourage companies to develop a relationship with the FBI and local law enforcement prior to a cyber security incident and incorporate us into incident response plans." ®

Get our [8]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YFoeqGALOhWLq8rA1GCS@wAAANY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YFoeqGALOhWLq8rA1GCS@wAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[3] https://regmedia.co.uk/2021/03/23/shutterstock_carlsbadw.jpg

[4] https://regmedia.co.uk/2021/03/23/guilty_plea.pdf

[5] https://www.theregister.com/2017/09/22/it_contractor_logic_bombed_army_payroll/

[6] https://www.justice.gov/usao-sdca/pr/it-contractor-sentenced-two-years-deleting-carlsbad-company-s-microsoft-user-accounts

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YFoeqGALOhWLq8rA1GCS@wAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://whitepapers.theregister.com/

Doctor Syntax

a $567,084 penalty – the same amount paid by his former client to clean up his mess.

To whom was the penalty to be paid? I'd have expected the unnamed outsourcing company to have been required to have made good the costs in the first instance so it should have been owing to them.

No excuse for the criminal... or the company

ecarlseen

So many companies assume that because their systems are cloud-based that they don't need separate backups. This should have been a straigthforward restore operation - still very damaging and deeply inconvenient, but not a half-a-million-dollar problem. Also left unanswered is how the criminal was able to get access to delete these accounts. With 2FA required for admins, the most likely explanation is that the client or contracting company was sloppy with access control. This is extremely common with outsourced IT work - lots of password sharing with few controls and audit trails, and passwords aren't changed even when a disgruntled employee leaves. I strongly doubt that it was some sort of "sophisticated attack."

The early bird who catches the worm works for someone who comes in late
and owns the worm farm.
-- Travis McGee