Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Incidents

January 16th, 2013, 15:28 GMT · By

Security Audit Reveals Developer Paid Chinese Programmers to Do His Job

SHARE:

Adjust text size:

US developer outsources his job to China
Enlarge picture
While investigating a possible security breach at a US-based company, experts from Verizon’s Risk Team discovered that one of the developers had actually outsourced his job to China.

The firm had set up a VPN concentrator to allow employees to work from home on certain days. However, when analyzing the VPN logs, they found a connection from Shenyang, China, to the workstation of one employee.

They contacted Verizon because they thought it was the work of hackers. In reality, when they analyzed the computer to which the connections were made to, they discovered hundreds of invoices from a contractor in China.

That’s when they realized that their employee, Bob, was actually paying the Chinese company to do his work.

“Bob spent less than one fifth of his six-figure salary for a Chinese firm to do his job for him. Authentication was no problem, he physically FedExed his RSA token to China so that the third-party contractor could log-in under his credentials during the workday. It would appear that he was working an average 9 to 5 work day,” explained Andrew Valentine of Verizon.

Since he didn’t actually work, Bob spent most of his free time surfing the web. He watched cat videos on YouTube, updated his social media accounts, and surfed eBay.

At the end of the work day, he sent an update email to the management.

With no proper monitoring systems in place, the scam went on for a long time and the company’s HR department always gave him good reviews because he always submitted his code on time.

“Evidence even suggested he had the same scam going across multiple companies in the area. All told, it looked like he earned several hundred thousand dollars a year, and only had to pay the Chinese consulting firm about fifty grand annually,” Valentine said.


1,508 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


DHS Identifies Malware on ICS Networks of Two Power Companies

HRSD Canada Loses Hard Drive Containing Details of over 500,000 Individuals

Facebook, Twitter Accounts of Ohio Teen Who Joked About Girl’s Abuse Hacked

Belgian Police Website Hacked by SlixMe

TURKTRUST Incident Shows That Certificate-Based Attacks Are a Preferred Vector

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM