All the latest UK technology news, reviews and analysis

Former IT worker accused of hacking Gucci networks

by Shaun Nichols

05 Apr 2011

Be the first to comment

  • Tweet this

A former IT engineer at Gucci has been accused of causing more than $200,000 worth of damage after an attack on the company's IT infrastructure.

Sam Chihlung Yin is facing multiple felony charges, including identity theft, computer trespass and falsifying business records. The charges carry penalties of up to 15 years in prison.

Prosecutors allege that, following his termination from the company as a network engineer, Yin launched an elaborate social engineering scheme to access Gucci's corporate network.

The 34 year-old man is said to have created a fake employee account and convinced administrators at the company to grant the account access to Gucci's virtual private network (VPN) using a reconfigured USB token.

Once inside the VPN, Yin allegedly shut down access to the company's email networks and document archives, while deleting other corporate data.

Gucci estimates that the outage, which lasted nearly 24 hours, resulted in a loss of roughly $200,000, after factoring in lost productivity and restoration costs.

IT administrators have long known about the dangers associated with terminated and disgruntled employees. Former workers have been highlighted as one of the top causes of corporate data breaches.

In 2008, a rogue administrator took down a FiberWAN network used by the city government of San Francisco. The attack cut off nearly two thirds of the city's network traffic capacity.

"People do, of course, leave jobs all the time and most of them would never dream of logging back in to their old place of work to cause mischief," wrote Sophos senior technology consultant Graham Cluley in a blog post.

"But it only takes one disaffected former worker to wreak havoc, so make sure your defences are in place, and that only authorised users can access your sensitive systems."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

10%

55%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Flash Developer- actionscript, AJAX, JSON

Flash Developer- Actionscript 3.0, AJAX, JSON, computer...

Business Analyst, Risk platform, Equity Derivs, Investment Bank

Business Analyst - Risk platform - Equity Derivatives...

Java Developer - Algorithmic Trading - Global Trading Business

Java Developer - Algorithmic Trading - Global Trading...

Junior Treasury Project Manager, Tier One Investment Bank

Junior Middle Office Project Manager, Treasury, IB...

To send to more than one email address, simply separate each address with a comma.