Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Developer Who Hacked Former Employer’s Systems Sentenced to Prison

Davis Lu was sentenced to four years in prison for installing malicious code on employer’s systems and for deleting encrypted data.

A Chinese national was sentenced to four years in prison for sabotaging his former employer’s systems through malicious code.

The man, Davis Lu, 55, a legal resident of Houston, Texas, was a software engineer at the victim company, headquartered in Beachwood, Ohio, from November 2007 to October 2019.

According to court documents, Lu began sabotaging the employer’s network after his responsibilities and system access were restricted in 2018, following a corporate realignment.

By August 2019, documents presented in court show, he installed malicious code that exhausted system resources, causing crashes and preventing user logins.

The code was designed to repeatedly create Java threads without proper termination, creating infinite loops leading to server hangs or crashes.

Additionally, Lu deleted coworker profile files, and implemented a kill switch that logged all users out of their accounts as soon as his credentials were disabled in Active Directory, court documents show.

Advertisement. Scroll to continue reading.

The kill switch, named ‘IsDLEnabledinAD’ (an abbreviation for ‘Is Davis Lu enabled in Active Directory’) was activated when Lu was placed on leave and asked to turn in his laptop. He also deleted encrypted data on the day he was directed to surrender his laptop.

According to documents presented in court, Lu searched the internet for methods to escalate privileges, delete files, and hide processes, which indicate he was researching means to prevent system restoration attempts.

His actions impacted thousands of users worldwide and caused hundreds of thousands of dollars in losses to his employer.

Lu was convicted in March. In addition to the four-year prison sentence, he received three years of supervised release.

Related: Scattered Spider Hacker Sentenced to Prison

Related: Hacktivist Sentenced to 20 Months of Prison in UK

Related: UK Student Sentenced to Prison for Selling Phishing Kits

Related: In Other News: Hacker Helps Kill Informants, Crylock Developer Sentenced, Ransomware Negotiator Probed

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.