Risk
11/2/2009
07:15 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Bank IT Worker Charged In $1.1 Million Fraud

A computer technician has been indicted for stealing the identities of 150 Bank of New York employees, as well as for grand larceny and money laundering.

Adeniyi Adeyemi, 27, of Brooklyn, New York, was charged last week in a 149-count indictment for allegedly using his position as a computer technician to steal the identities of over 150 employees of the Bank of New York Mellon and to subsequently defraud charities, non-profits, and other organizations for more than $1.1 million over an eight year period.

The crimes with which Adeyemi is charged -- grand larceny, identity theft, money laundering, scheme to defraud, computer tampering, and unlawful possession of personal identification information -- allegedly took place between November 1, 2001 and April 30, 2009.

According to the Manhattan District Attorney's Office, Adeyemi worked as a computer technician at the Bank of New York on 1 Wall Street and at other bank locations around Manhattan. While in the bank's employ, he is alleged to have stolen the personal information of dozens of bank employees, mostly from the bank's information technology department.

A spokesperson for the Manhattan District Attorney's Office was not immediately available to confirm how long Adeyemi worked for the bank.

Over the eight year period, Adeyemi is alleged to have used the identities of other bank employees to open brokerage accounts at various institutions, including E*Trade, Fidelity, Citi, Wachovia, and Washington Mutual, and to have used those accounts to store and transfer money stolen from charities and non-profits.

Adeyemi's ability to access the bank accounts of charities and non-profits was made easier than it might otherwise have been because such organizations often make their bank account information available online to facilitate donations, the District Attorney's Office said.

The list of affected organizations includes: Goodwill Industries of Greater New York and Northern New Jersey, Iris Ministries, the Kalgidhar Trust, the Sudanese American Community Development Organization, Ravi Zacharias International Ministries, AFK Foundation, the American Community School at Beirut, the Jacksonville Humane Society, American Friends of Birdlife International, the International Association of Women Judges, the Space Generation Advisory Council, and the American Association for Clinical Chemistry.

Adeyemi allegedly stole $128,000 from the IT employees whose identities he'd stolen. The District Attorney's Office claims that Adeyemi changed his former colleagues' online bank account contact information, hijacked their accounts and wired money out -- in increments below $10,000 to avoid triggering mandatory reporting to the US Treasury -- to the dummy accounts he had established at various brokerages. He allegedly bought about $100,000 in US Postal Service money orders, which he used to pay living expenses and to send money overseas, primarily to Nigeria.

Adeyemi was placed under Secret Service surveillance "when suspicious Internet activity traced back to wireless Internet connections in Adeyemi's apartment building, and mail connected to the fraud was delivered to the various apartments within the building," the District Attorney's Office said.

An April 30, 2009 search of Adeyemi's apartment turned up credit reports belonging to dozens of Bank of New York employees on his computer, along with other documents containing personal information on over 150 bank employees, and $30,000 in cash. A storage locker rented by Adeyemi was found to contain similar documents and credit cards bearing the names of bank employees.

Adeyemi was arrested when the warrant was served and has remained in custody.

In an e-mail, Kurt Johnson, VP of corporate strategy for security vendor Courion, said that if the bank had had the proper automated access management technology in place, Adeyemi probably would not have been able to abuse his position as easily.

"Companies need to wake up to internal threats facing them today and stop handing the keys to the kingdom to people who have no business holding them," Johnson said.

InformationWeek Analytics has published an analysis of the current state of identity management. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7896
Published: 2015-03-03
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before ...

CVE-2014-9283
Published: 2015-03-03
The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

CVE-2014-9683
Published: 2015-03-03
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.

CVE-2015-0656
Published: 2015-03-03
Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCum81269.

CVE-2015-0890
Published: 2015-03-03
The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.