Risk
11/2/2009
07:15 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Bank IT Worker Charged In $1.1 Million Fraud

A computer technician has been indicted for stealing the identities of 150 Bank of New York employees, as well as for grand larceny and money laundering.

Adeniyi Adeyemi, 27, of Brooklyn, New York, was charged last week in a 149-count indictment for allegedly using his position as a computer technician to steal the identities of over 150 employees of the Bank of New York Mellon and to subsequently defraud charities, non-profits, and other organizations for more than $1.1 million over an eight year period.

The crimes with which Adeyemi is charged -- grand larceny, identity theft, money laundering, scheme to defraud, computer tampering, and unlawful possession of personal identification information -- allegedly took place between November 1, 2001 and April 30, 2009.

According to the Manhattan District Attorney's Office, Adeyemi worked as a computer technician at the Bank of New York on 1 Wall Street and at other bank locations around Manhattan. While in the bank's employ, he is alleged to have stolen the personal information of dozens of bank employees, mostly from the bank's information technology department.

A spokesperson for the Manhattan District Attorney's Office was not immediately available to confirm how long Adeyemi worked for the bank.

Over the eight year period, Adeyemi is alleged to have used the identities of other bank employees to open brokerage accounts at various institutions, including E*Trade, Fidelity, Citi, Wachovia, and Washington Mutual, and to have used those accounts to store and transfer money stolen from charities and non-profits.

Adeyemi's ability to access the bank accounts of charities and non-profits was made easier than it might otherwise have been because such organizations often make their bank account information available online to facilitate donations, the District Attorney's Office said.

The list of affected organizations includes: Goodwill Industries of Greater New York and Northern New Jersey, Iris Ministries, the Kalgidhar Trust, the Sudanese American Community Development Organization, Ravi Zacharias International Ministries, AFK Foundation, the American Community School at Beirut, the Jacksonville Humane Society, American Friends of Birdlife International, the International Association of Women Judges, the Space Generation Advisory Council, and the American Association for Clinical Chemistry.

Adeyemi allegedly stole $128,000 from the IT employees whose identities he'd stolen. The District Attorney's Office claims that Adeyemi changed his former colleagues' online bank account contact information, hijacked their accounts and wired money out -- in increments below $10,000 to avoid triggering mandatory reporting to the US Treasury -- to the dummy accounts he had established at various brokerages. He allegedly bought about $100,000 in US Postal Service money orders, which he used to pay living expenses and to send money overseas, primarily to Nigeria.

Adeyemi was placed under Secret Service surveillance "when suspicious Internet activity traced back to wireless Internet connections in Adeyemi's apartment building, and mail connected to the fraud was delivered to the various apartments within the building," the District Attorney's Office said.

An April 30, 2009 search of Adeyemi's apartment turned up credit reports belonging to dozens of Bank of New York employees on his computer, along with other documents containing personal information on over 150 bank employees, and $30,000 in cash. A storage locker rented by Adeyemi was found to contain similar documents and credit cards bearing the names of bank employees.

Adeyemi was arrested when the warrant was served and has remained in custody.

In an e-mail, Kurt Johnson, VP of corporate strategy for security vendor Courion, said that if the bank had had the proper automated access management technology in place, Adeyemi probably would not have been able to abuse his position as easily.

"Companies need to wake up to internal threats facing them today and stop handing the keys to the kingdom to people who have no business holding them," Johnson said.

InformationWeek Analytics has published an analysis of the current state of identity management. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVE-2014-7292
Published: 2014-10-23
Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.16125), and 2.3 (2.3.9074.18820) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to ct.ashx.

CVE-2014-8071
Published: 2014-10-23
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerPatient.page; the (5) comment parameter to all...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.