Fired Gucci Employee Accused of Attacking Network
WrongSizeGlass writes "Computer World, Information Week, The Register are all reporting on the story of a former Gucci IT employee who is accused of a November 2010 assault on Gucci's network deleting files and virtual servers, taking a storage area network offline, and deleting mailboxes from the corporate email server. The lost productivity is estimated at $200,000. Sam Chihlung Yin, 34, of Jersey City, NJ, allegedly created a fake VPN token in the name of a non-existent employee which he tricked Gucci IT staff into activating in June 2010, a month after his employment contract was terminated by Gucci for unrelated reasons."
Down with fashion!
"When information is power, privacy is freedom" - Jah-Wren Ryel
They should be paying him that lost $200,000 for running the white-hat attack to fish out the vulnerabilities. Yeah that's it...White. Hat.
Loading...
I remember a guy in intermediate school wearing Gucci. He used to dance a lot with the ladies a lot, I don't know what happened to him. If he has a family I guarantee you he's feeding off of my tax dollars! GNU FTW!
Burn the Gucci flag
It's funny how the closer something is to hacking, the less the word is actually used in an article. While this seems to me to be more of a result of bad policies (admin passwords were never changes) and social engineering (which is a form of hacking) actual hacking, I find it funny that the term is hardly used at all whereas when Anonymous tries a DDoS, it's ZOMG HACK0RZ!!!! every other line.
Don't piss off network admins or sysadmins. Not saying don't fire them if they screw up, but don't fire them without a justified reason either. Without knowing the whole story I can't really pass judgment, but this sort of action smacks of revenge against pointy haired bosses to me.
Occasionally living proof of the Ballmer peak.
I wonder how long it took for the IT staff to determine the bogus user and remove remote access. The IT department must have activated that account with a minimum of domain admin permission. Bad IT policy at Gucci.
Conjugal visits? Not that I know of. Minimum security prison is no picnic. The trick is, kick someone's ass on the first day or become someone's bitch.
http://www.killerclips.com/clip.php?id=74&qid=669&PHPSESSID=6ea47a84f4b8b325495d3b4b2a7ed7cd
Learning HOW to think is more important than learning WHAT to think.
Gucci...
Cleavon Little...
The new sheriff is a ni[BONG]
I wonder what a bank would do to the branch manager if a former employee could walk away with $200,000 six months after being fired. Or, to use a car analogy, if a former employee was able to walk into a dealership and drive away with a $200,000 car just like that.
The law about computer crimes should have strong penalties for managers that allow that shit to happen. It would be somewhat different if the guy still worked for the corporation, because it's much harder to guard against an attack from inside, but if someone is responsible for managing a valuable asset he should be competent enough to take reasonable precautions to protect it from any attack someone could bring from outside.
In other news Gucci recouped the lost revenue today with one sale (1 item). I kid I kid
Thanks Gucci for not breaching time continuity for not firing him for something he would do in the future!
1) if you're going to fire an IT admin who has access to all your stuff, you meet him at the door in the morning while your other admins are changing passwords. He doesn't touch a computer in your building again. You'll put his files on a flash drive and don't let the door hit you on the way out.
2) Anyone posting IT post-firing sabotage fantasies who isn't posting as a Anonymous Coward deserves the results of their next interview. I'm looking at you sandytaru.
Quote from google finance.
"Gucci Group, an Italian company with a Dutch address that sells French fashion, does quite well in Japan, too. Its offerings include handbags and other leather goods, shoes, ready-to-wear clothing, cosmetics, skin care, jewelry, and watches. Gucci family squabbles and imprudent licensing once nearly doomed the firm. New management revived it with fresh product lines and stricter licensing, as well as heavy investing in its Asian presence. Gucci operates more than 550 stores worldwide and wholesales products through franchisees and upscale department stores. French retailer PPR purchased almost all of the remaining shares in the company in 2004, taking its interest up to 99.4%. "
Although this is a private company, i'd guess that recent events (Tsunami, credit crunch,) have put this company into the corporate death spiral.But , it needs to be confirmed... wonder if gucci turnover figures are available from any ex employees.
I don't believe any mention has been made about the reasons for the original termination.
Maybe this guy had a real asshole boss or something.
Doesn't completely excuse what he did but....
At least he didn't follow the Postal model of getting even.
sounds to me like ", allegedly created a fake VPN token in the name of a non-existent employee which he tricked Gucci IT staff into activating" means he found a serious process issue. everywhere ive ever worked you had to jump through more hoops than a Ringling brothers trained animal to get any access. In most places, IS security calls physical security (or the other way around) and the resulting person has to check with a manager of a department who gets authority from someone with director in their name. I guess gucci will be enlarging it's process model now.
Why wasn't this guys password deactivated? Did Gucci actually have common all-powerful known to all the engineers? We did that at our little IT shop because we didn't have full control of the network (we were a first response team to the main IT guys). It seems like you would give the guys some logins to use to things, use LDAP or ActiveDirectory groups to put them in the admin user level, and then when they leave/fired/downsized/outsourced/etc revoke them from the admin group(s).
How many times do we need to read "Fired techguy used his/known admin passwords to cause hell" before someone catches on?
Procrastinating life a way at a rapid rate of speed.
Sam Chihlung Yin allegedly created a fake VPN token... which he tricked Gucci IT staff into activating a month after his employment contract was terminated by Gucci for unrelated reasons.
I certainly hope the reason they fired him wasn't for something he hadn't done yet. Especially if it was in retaliation for being fired in the first place.
It`s like you have an emplyee, who duplicate his company keys and burns down the company at night. What he did is he commited a crime..If he did that with fake accounts or fake keys makes no difference. If I would get fired I WOULD NOT EVEN REMOTELY THINK of harming the company...what he did is really dumb and even if he left in anger, this does not justify any of his actions. I once got fired, but I worked till my last day like every day.Especially in IT you have to have some kind of tact, or you are COMPLETELY WRONG in IT. With great power comes great responsibility!
We've been having a lot of trouble with you lately, and that ALL-CAPS tirade is the last straw. You're fired, now grab your coat and hat and get the hell out!