ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Ex-IT worker charged with sabotage

Published: 19 Dec 2002 09:08 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A former system administrator for UBS PaineWebber was arraigned in a New Jersey federal court on Tuesday on charges of sabotaging two-thirds of the company's computer systems in an attempt to crash its stock price.

A two-count indictment charged 60-year-old Roger Duronio with being behind the more than $3m (about £2m) in damage caused when malicious programs placed on some 1,000 of UBS PaineWebber's nearly 1,500 computers became active on 4 March and deleted files. The indictment alleges that the Bogota, New Jersey resident, who had left UBS PaineWebber 10 days before the deletion of the files, would have profited if the company's stock had fallen as a result of the attack.

"Cybercrime against financial institutions is a significant issue," District Attorney Christopher J. Christie said in a statement. "Although the damage was contained in this case, the potential for catastrophic damage in other cases is always there."

Duronio posted a $1m bond on Tuesday for his release, according to a representative of the US Attorney's Office for the District of New Jersey, the office prosecuting the case. Duronio's defense attorney, Justin Walder, could not be immediately reached for comment.

In a seven-page indictment, a federal grand jury charged Duronio with one count of securities fraud and one count of violating the Computer Fraud and Abuse Act.

The indictment alleges that in his role as a system administrator for UBS PaineWebber, Duronio used the company's secure network to plant "logic bombs" -- destructive computer programs that are set to trigger at a specific time or as the result of a specific action -- in nearly 1,000 of the company's approximately 1,500 networked computers located in 370 branch offices. The malicious program had instructions to delete all the files stored on the systems at 9:30 am on every Monday in March, April and May of 2002.

Duronio had left the company on 22 February, 10 days before the first trigger date. He had allegedly complained repeatedly about his salary and bonuses from the company. Around the same time, Duronio purchased options to sell 31,800 shares of UBS stock at an average strike price of $42.91. Such options make money only if the stock price falls below the purchase price before the options expire. The indictment alleges that the former system administrator believed that crashing the company's systems would cause its stock price to plummet before his options expired on 15 March.

The alleged plan in some ways resembles the Emulex fraud incident that caused that company's stock to fall by more than 50 percent.

Logic bombs have in the past been used by irate employees against their employers. In February, Timothy Allen Lloyd was sentence to 41 months in prison for leaving behind malicious programs that deleted critical data from the servers of high-tech measurement company Omega Engineering. Prosecutors in the case said the attack cost the company $10m. Insider attacks are generally considered the most costly for companies.

The attack allegedly carried out by Duronio failed to have the desired effect, however. The attack was not made public at the time, and UBS's stock didn't fall below $45 in March 2002. On Wednesday, the stock stood at $49.34.

If found guilty, Duronio could serve as much as 20 years in prison and be subject to fines of more than $1.25m.

Representatives of UBS PaineWebber could not be reached for comment.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
43 out of 79 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Senior Fraud Analyst Yorkshire Up to 35K

Fraud Analyst Within Risk Management, the Fraud Strategy and Analysis team is responsible for ensuring that the card fraud scoring models, strategies ...

Risk/ Fraud Analyst - Compliance and Governance

Working in the Credit Risk Department in an established Fraud strategy team you will be working on all aspects of the You will support all fraud ...

OO Developer. Stock Exchange. London. C++/Java

Stock Exchange. C++/Java One of the smaller stock exchanges in London is looking for a less experienced OO developer versed in C++ and/or Java to ...

Discussions

Moley Moley

welcome to www.007trader.com

Saturday 17 May 2008, 11:37 PM

3 posts
Tallin Tallin

welcome to www.007trader.com

Saturday 17 May 2008, 11:11 PM

3 posts

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal