Risk
11/2/2009
07:15 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Bank IT Worker Charged In $1.1 Million Fraud

A computer technician has been indicted for stealing the identities of 150 Bank of New York employees, as well as for grand larceny and money laundering.

Adeniyi Adeyemi, 27, of Brooklyn, New York, was charged last week in a 149-count indictment for allegedly using his position as a computer technician to steal the identities of over 150 employees of the Bank of New York Mellon and to subsequently defraud charities, non-profits, and other organizations for more than $1.1 million over an eight year period.

The crimes with which Adeyemi is charged -- grand larceny, identity theft, money laundering, scheme to defraud, computer tampering, and unlawful possession of personal identification information -- allegedly took place between November 1, 2001 and April 30, 2009.

According to the Manhattan District Attorney's Office, Adeyemi worked as a computer technician at the Bank of New York on 1 Wall Street and at other bank locations around Manhattan. While in the bank's employ, he is alleged to have stolen the personal information of dozens of bank employees, mostly from the bank's information technology department.

A spokesperson for the Manhattan District Attorney's Office was not immediately available to confirm how long Adeyemi worked for the bank.

Over the eight year period, Adeyemi is alleged to have used the identities of other bank employees to open brokerage accounts at various institutions, including E*Trade, Fidelity, Citi, Wachovia, and Washington Mutual, and to have used those accounts to store and transfer money stolen from charities and non-profits.

Adeyemi's ability to access the bank accounts of charities and non-profits was made easier than it might otherwise have been because such organizations often make their bank account information available online to facilitate donations, the District Attorney's Office said.

The list of affected organizations includes: Goodwill Industries of Greater New York and Northern New Jersey, Iris Ministries, the Kalgidhar Trust, the Sudanese American Community Development Organization, Ravi Zacharias International Ministries, AFK Foundation, the American Community School at Beirut, the Jacksonville Humane Society, American Friends of Birdlife International, the International Association of Women Judges, the Space Generation Advisory Council, and the American Association for Clinical Chemistry.

Adeyemi allegedly stole $128,000 from the IT employees whose identities he'd stolen. The District Attorney's Office claims that Adeyemi changed his former colleagues' online bank account contact information, hijacked their accounts and wired money out -- in increments below $10,000 to avoid triggering mandatory reporting to the US Treasury -- to the dummy accounts he had established at various brokerages. He allegedly bought about $100,000 in US Postal Service money orders, which he used to pay living expenses and to send money overseas, primarily to Nigeria.

Adeyemi was placed under Secret Service surveillance "when suspicious Internet activity traced back to wireless Internet connections in Adeyemi's apartment building, and mail connected to the fraud was delivered to the various apartments within the building," the District Attorney's Office said.

An April 30, 2009 search of Adeyemi's apartment turned up credit reports belonging to dozens of Bank of New York employees on his computer, along with other documents containing personal information on over 150 bank employees, and $30,000 in cash. A storage locker rented by Adeyemi was found to contain similar documents and credit cards bearing the names of bank employees.

Adeyemi was arrested when the warrant was served and has remained in custody.

In an e-mail, Kurt Johnson, VP of corporate strategy for security vendor Courion, said that if the bank had had the proper automated access management technology in place, Adeyemi probably would not have been able to abuse his position as easily.

"Companies need to wake up to internal threats facing them today and stop handing the keys to the kingdom to people who have no business holding them," Johnson said.

InformationWeek Analytics has published an analysis of the current state of identity management. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.