News

10/10/2017
04:40 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Former Employee of Transcontinental Railroad Company Found Guilty of Damaging Ex-Employers Computer Network

Canadian Pacific Railway former employee convicted for causing intentional damage to Canadian Pacific's computer network.

Acting Assistant Attorney General Kenneth A. Blanco of the Justice Department’s Criminal Division and Acting U.S. Attorney Gregory G. Brooker of the District of Minnesota announced the conviction of a former employee of Canadian Pacific Railway for causing intentional damage to Canadian Pacific’s computer network.

Christopher Victor Grupe, 46, of Minneapolis, Minnesota, was charged on April 11, with one count of intentional damage to a protected computer and on Oct. 6, following a five-day trial, was found guilty by a federal jury in Minneapolis, Minnesota. A sentencing date has not been set.

As proven at trial, from September 2013 until December 2015, Grupe was employed as an IT professional by Canadian Pacific Railway (CPR), a transcontinental railroad company headquartered in Alberta, Canada, with U.S. headquarters in Minneapolis, Minnesota. On Dec. 15, 2015, following a 12-day suspension, Grupe was notified by CPR management that he was going to be fired due to insubordination. However, at his request, Grupe was instead allowed to resign, effective that same day. In his resignation letter, Grupe indicated that he would return all company property, including his laptop, remote access device, and access badges, to the CPR office.

As proven at trial, on Dec. 17, 2015, before returning his laptop and remote access device, Grupe used both to gain access to the CPR network’s core “switches” – high-powered computers through which critical data in the CPR network flowed. Once inside, Grupe strategically deleted files, removed administrative-level accounts, and changed passwords on the remaining administrative-level accounts, thereby locking CPR out of these network switches. Grupe then attempted to conceal his activity by wiping the laptop’s hard drive before returning it to CPR.

On Jan. 6, 2016, while trying to address a networking problem, the CPR network staff discovered that they were unable to access the main network switches. After CPR IT staff was able to regain access to the switches through a risky, but successful, rebooting procedure, they discovered evidence in logging data stored in the memory of the switches connecting the damage to Grupe. CPR hired an outside computer security company to identify the source and scope of the intrusion as well as conduct an incident analysis, which also connected the damage to Grupe.  In total, CPR experienced a financial loss of approximately $30,000 as a result of Grupe’s conduct.

This case is the result of an investigation conducted by the FBI Minneapolis field office, with assistance from the Cybercrime Laboratory of the Criminal Division’s Computer Crime and Intellectual Property Section.

Trial  Attorney Aaron R. Cooper of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Timothy C. Rank of the District of Minnesota are prosecuting the case.

 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
New Cold Boot Attack Gives Hackers the Keys to PCs, Macs
Kelly Sheridan, Staff Editor, Dark Reading,  9/13/2018
Yahoo Class-Action Suits Set for Settlement
Dark Reading Staff 9/17/2018
RDP Ports Prove Hot Commodities on the Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: In Russia, application hangs YOU!
Current Issue
Flash Poll
How Data Breaches Affect the Enterprise
How Data Breaches Affect the Enterprise
This report, offers new data on the frequency of data breaches, the losses they cause, and the steps that organizations are taking to prevent them in the future. Read the report today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-3912
PUBLISHED: 2018-09-18
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
CVE-2018-6690
PUBLISHED: 2018-09-18
Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.
CVE-2018-6693
PUBLISHED: 2018-09-18
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escal...
CVE-2018-16515
PUBLISHED: 2018-09-18
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-16794
PUBLISHED: 2018-09-18
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.