ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

IT worker arrested over hacking plot

Anne Broache CNET News.com

Published: 20 Dec 2006 08:59 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A systems administrator who apparently feared imminent layoffs was arrested Tuesday in connection with installing "destructive computer code" on servers at his company, a major manager of prescription benefit plans.

FBI agents arrested Yung-Hsun "Andy" Lin, 50, at his Montville, New Jersey home on Tuesday morning, one day after a grand jury returned a two-count indictment against him.

The indictment accuses Lin of planting a "logic bomb" sometime around October 2003 that, if activated successfully, would have deleted "virtually all information" on more than 70 HP-Unix servers at Medco Health Solutions and wreaked havoc on the business and its users.

The servers contained numerous applications and databases that managed bills, rebates, new prescription call-ins from doctors, insurance coverage, and clinical assessments of patients. One database that received special attention in the indictment, known as the Drug Utilization Review, was designed to allow pharmacists to see what drugs patients were already taking so that they could determine whether taking different medicines simultaneously was safe.

"The potential damage to Medco and the patients and physicians served by the company cannot be understated," Christopher Christie, US attorney for the New Jersey district, said in a statement.

According to the indictment, the alleged criminal activity started just after Medco, once a wholly owned subsidiary of Merck & Co, became a publicly traded company in August 2003. During the month that followed, Lin and others exchanged emails in which they voiced concerns about possible layoffs in their department. While Lin ultimately kept his job, four fellow systems administrators lost theirs.

Lin allegedly programmed the so-called bomb to do its work on 23 April, 2004 — his birthday — but because of a coding error, it failed to detonate. He later modified the coding so that it would deploy on 23 April, 2005 but another computer administrator happened to stumble upon the program in January 2005 and "neutralised" it, the indictment said.

The New Jersey district has made three such prosecutions in five years, according to a press release. Just last week, 63-year-old Roger Duronio, a former systems administrator for UBS PaineWebber, landed a 97-month prison sentence after being convicted of placing malicious code on some 1,000 corporate computers, triggering more than $3m in damage.

In 2002, Timothy Allen Lloyd was sentenced to 41 months in prison after a Newark, New Jersey, jury convicted him of devising a "time bomb" that deleted programs on servers at the high-tech measurement company Omega Engineering. Prosecutors said that activity, which occurred 20 days after Lloyd's departure from the company, cost the company $10m.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
291 out of 333 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Expert Front End Developer / Designer for E-Commerce Retailer

Expert Front End Designer / Developer with skills in PhotoShop, CS2/3, Hand coding in HTML and CSS2. Your key skills will include PhotoShop, CS2/3, ...

Next generation networks - Unix and C programming platform - URGENT

An end to end engineer role giving a systems administrator (Unix and C coding) experience in a niche telecoms market. Technically you must: Software ...

Embedded Software Engineer/C,Linux,Embedded,TCP,Flash/Brighton

For this role you will need -Expertise in Embedded C coding -working with Linux OS -Strong understanding of communication protocols (CAN,LIN,TCP/IP) ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation