Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Hacker Who Sold UPMC Employee Information Pleads Guilty

A Michigan man has pleaded guilty to hacking a University of Pittsburgh Medical Center employee database, stealing the personal information of more than 65,000 people and then selling the information online.

Justin Johnson, 30, is being held at Butler County Prison and will be sentenced in four months, the Tribune-Review reported.

A Michigan man has pleaded guilty to hacking a University of Pittsburgh Medical Center employee database, stealing the personal information of more than 65,000 people and then selling the information online.

Justin Johnson, 30, is being held at Butler County Prison and will be sentenced in four months, the Tribune-Review reported.

Johnson pleaded guilty Thursday to two of the 43 counts against him, one count of conspiracy and one count of aggravated identity theft.

According to Assistant U.S. Attorney Greg Melucci, investigators from the IRS, U.S. Postal Service and U.S. Secret Service found that Johnson used his expertise in the PeopleSoft software, used by UPMC, to gain access to the database in 2014.

He then used the moniker “The Dearth Star” and later “Dearthy Star” to sell the information on the dark web.

“Virtually every UPMC employee’s (personally identifiable information) was victimized,” Melucci said. “The intruder clearly had a high skill set.”

Johnson was arrested last year in Detroit.

Related: Developer of DDoS Botnets Based on Mirai Code Sentenced to Prison

Advertisement. Scroll to continue reading.

Related: US Teen ‘Mastermind’ in Epic Twitter Hack Sentenced to Prison

Related: Member of FIN7 Hacking Group Sentenced to US Prison

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

Shane Barney has been appointed CISO of password management and PAM solutions provider Keeper Security.

Edge Delta has appointed Joan Pepin as its Chief Information Security Officer.

Vats Srivatsan has been appointed interim CEO of WatchGuard after Prakash Panjwani stepped down.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.