News: 1710899106

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Australian techie jailed for accessing museum's accounting system and buying himself stuff

(2024/03/20)


An Australian IT contractor has been sentenced to 30 months jail for ripping off the National Maritime Museum.

The nonprofit museum celebrates Australia's maritime heritage – a matter of some import for the island nation, which therefore attracts government funding.

Among the museum's exhibits is a retired destroyer, the HMAS Vampire. Which we mention because the convicted contractor had no qualms about tapping the Museum's financial veins to nourish his lifestyle.

[1]

As [2]explained yesterday by the Australian Federal Police (AFP), the man "used his role as a contract IT support worker to access the Museum's accounts payable system and illegally change bank account details to his own."

[3]

[4]

The convicted techie used his access to the Museum's financial systems to obtain financial details of several individuals and businesses recorded. He then used those details to make to purchases to the tune of over AU$66,000 ($43,000).

Almost a third of his haul went on what the AFP described as "high-powered IT equipment" – we’re guessing either crypto mining or gaming kit – and also managed to spend over AU$15,000 ($10,000) on mechanical work and upgrades to his four wheel drive vehicle.

[5]

The Museum noticed the man's transactions and called the Feds, who put the Command Cybercrime Operations team on the case, leading to a March 2023 arrest. The man was sentenced last Friday to 30 months inside, and will serve at least half that time as the Local Court judge set a non-parole period of 15 months.

[6]Uber Australia to pay $178M to settle cabbies' class action

[7]Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack

[8]Australian spy chief fears sabotage of critical infrastructure

[9]Interpol's latest cybercrime intervention dismantles ransomware, banking malware servers

The man may not be the only Australian tech contractor in trouble this week: local infosec outfit Dvuln trawled LinkedIn for workers known to hold Australian government security clearances, and found two scary things.

One was that some mention projects they're working on, making their social media profiles valuable open source intelligence about those projects and possible targets to learn more about them.

The other was that over half of folks who list themselves as holding clearances are named at Have I Been Pwned – the database of credentials present in data leaks. Those seeking credentials to access sensitive Australian government systems therefore have an obvious place to start their explorations. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfptaEHegN1th4caYXZ--gAAAUA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.afp.gov.au/news-centre/media-release/it-contractor-sentenced-cybercrime-and-fraud-offences-after-swindling

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfptaEHegN1th4caYXZ--gAAAUA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfptaEHegN1th4caYXZ--gAAAUA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfptaEHegN1th4caYXZ--gAAAUA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/03/18/uber_australia_class_action_settlement/

[7] https://www.theregister.com/2024/03/14/nissan_oceania_100k_affected/

[8] https://www.theregister.com/2024/02/29/asio_threat_assessment_2024/

[9] https://www.theregister.com/2024/02/02/interpols_latest_cybercrime_intervention_dismantles/

[10] https://whitepapers.theregister.com/



Circular reasoning

KalF

Checking a known breached service (linkedin, pick your recent data breach occurrence) to see if users have had their data breached seems a bit redundant. It's the kind of lazy analysis companies do in order to come up with a headline reason why their staff are better than the randoms on a social network. Anyone using linkedin for longer than a few moments has had their profile exfil'd. Whether that is an actual problem depends on whether they are vulnerable to cred stuffing. Just saying someone appears on HIBP is weak research.

However putting clearance on your profile is a bit off. Clearance is for a specific purpose/role and does not carry to a new role. Hiring only those with current clearance is illegal (AGSVA site explains this quite clearly). And yet recruiters and employers do it all the time anyway. Which is why some are motivated to put their clearance in their profiles. Since what really matters to an employer should be whether clearance is attainable, perhaps candidates should put their citizenship and whether or not they have been to the big house?

I never make these lists

Anonymous Coward

And I’m glad.

ABA files are fun

johnrobyclayton

Most companies in Australia will generate ABA files that they send to the bank.

The ABA files contain the details of the payments they want to make to their creditors.

Quietly replacing the bank account numbers with different account numbers is an easy hack. ABA files are fixed format text files.

Also easy to detect. Just need to check with your payees that they have received expected payments and then check with the banks for payments that have gone missing.

Then look for Application Support staff that might have been sticking their fingers in the cookie jar.

Re: ABA files are fun

An_Old_Dog

Just need to check with your payees that they have received expected payments

No need to 'check'. They'll let you know sharpish. *Ring-ring-ring* "Hello, ABC Corp, Accounting, Jennifer speaking."

"XYZ Co,, Accounts Receivable, Gerald here. Where's our fookin' money?!! "

Blackjack

Oh wow that was dumb, it is a museum expense account, any kind of personal buy must have stuck like a sore thumb.

Not How it Worked

An_Old_Dog

The fraudster didn't buy his stuff and charge it to the museum. He changed things around so that instead of the museum sending money for certain payments to, say, DEF Co., it instead sent the money to the fraudster's personal bank account.

Usually these sorts of fraudsters don't arrange things so the skimmed funds go directly to their personal accounts, but instead, go to accounts of shell companies which they have created. This guy was lazier/more-stupid than most.

Will you loan me $20.00 and only give me ten of it?
That way, you will owe me ten, and I'll owe you ten, and we'll be even!