Attacks/Breaches
4/3/2008
03:58 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Random Search Stops $600 Million In Trade Secrets Bound For China

The feds have indicated a software engineer who was flying to China with confidential technical documents, a thumb drive, four external hard drives, 29 recordable compact discs, and a videotape.

A former software engineer for a telecommunications company based near Chicago was indicted for allegedly stealing trade secrets worth an estimated $600 million and trying to take the documents to China.

The FBI said Wednesday that Hanjuan Jin of Schaumburg, Ill., a naturalized U.S. citizen who was born in China, was stopped at Chicago's O'Hare International Airport on Feb. 28, 2007, in a random search.

According to an affidavit filed by FBI special agent Michael R. Diekmann, Jin was traveling on a one-way ticket to Beijing at the time. She declared that she had $10,000 in U.S. currency in her carry-on luggage. Customs and Border Protection officers found about $30,000 in cash.

According to Diekmann, this prompted officers to further inspect Jin's luggage, whereupon they found several technical documents labeled "[Company A] Confidential Property," Chinese documents, a European company's product catalog of military technology written in English, a personal laptop computer, a thumb drive, four external hard drives, 29 recordable compact discs, and one videotape.

A search of the thumb drive and hard drives, conducted with Jin's consent, revealed numerous documents marked "[Company A] Confidential Property." Initially, Jin told customs officers she worked for Company A. In a subsequent interview with law enforcement agents, Jin said she was on medical leave from Company A. She later said she worked for Company A and Company B at the same time. Company B is a Chicago-area company that competes with Company A.

Diekmann's affidavit and the indictment do not name either Company A or Company B.

Schaumburg-based Motorola is one of several telecommunications companies that Jin might have worked for. Asked to confirm or deny whether Jin had ever worked for Motorola, company spokeswoman Paula Thornton said in an e-mail," We are not able to do so, as Motorola does not comment on questions associated with pending prosecutions or ongoing governmental investigations."

Nortel also maintains an office in Schaumburg. A Dallas-based spokeswoman for the company said she'd never heard the name Hanjuan Jin.

Another possibility might be American Telecommunications Corp. When called, the person answering the phone declined to make a media contact available and hung up.

Jin was released, though customs agents retained the documents marked confidential and her computer equipment. She was again stopped at O'Hare on March 1, 2007, while traveling on another one-way ticket to Beijing.

Following a subsequent search of her home, Jin was arrested on March 7 based on a criminal complaint brought by Patrick J. Fitzgerald, the U.S. attorney for the Northern District of Illinois. She was released on $50,000 bond.

If Jin is convicted, each of the three counts against her carries a maximum penalty of 10 years in prison and a $250,000 fine.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Must Reads - September 25, 2014
Dark Reading's new Must Reads is a compendium of our best recent coverage of identity and access management. Learn about access control in the age of HTML5, how to improve authentication, why Active Directory is dead, and more.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5485
Published: 2014-09-30
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVE-2012-5486
Published: 2014-09-30
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVE-2012-5487
Published: 2014-09-30
The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVE-2012-5488
Published: 2014-09-30
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVE-2012-5489
Published: 2014-09-30
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
In our next Dark Reading Radio broadcast, we’ll take a close look at some of the latest research and practices in application security.