2020-10-02 DOJ SDNY press_release 118 KB 4,949 chars

United States v. Audrey Strauss, et al.

raw: Former Information Technology Employee Of Hospital Sentenced To 30 Months In Prison For Computer Intrusion

Former Information Technology Employee Of Hospital Sentenced To 30 Months In Prison For Computer Intrusion (S.D.N.Y. Oct. 2, 2020)

Caption
United States v. Audrey Strauss, et al.
summary

Former hospital IT employee Richard Liriano was sentenced to 30 months in prison for using keyloggers and malicious software to steal over 70 personal accounts' credentials and sensitive data from coworkers, causing over $350,000 in remediation costs and violating privacy over a five-year period.

paragraph

Richard Liriano, a former information technology employee at a New York City-area hospital, was sentenced to 30 months in prison for computer intrusion after abusing his administrative access to install keyloggers and other malicious software on coworkers’ systems. Over a five-year period from 2013 to 2018, he stole usernames and passwords for at least 70 personal and work accounts, accessing private photos, videos, tax records, and other confidential files. He pleaded guilty to the charges, was ordered to pay $351,850.25 in restitution, and will serve three years of supervised release after his prison term.

narrative

Richard Liriano, a former IT employee at a New York City-area hospital, abused his administrative access to install malicious software—including keyloggers—on dozens of coworkers’ computers between 2013 and 2018, secretly capturing keystrokes to steal login credentials. Using these stolen credentials, he accessed over 70 personal email, social media, and online accounts belonging to employees and their associates, searching for and harvesting private photographs, videos, and tax documents for his own use. His unauthorized intrusions compromised both personal privacy and the integrity of hospital systems housing sensitive healthcare data. The hospital incurred over $350,000 in costs to remediate the damage caused by his actions. Liriano pleaded guilty to computer intrusion charges and was sentenced to 30 months in prison, followed by three years of supervised release. He was also ordered to pay $351,850.25 in restitution to the hospital. The case was investigated by the FBI and NYPD, and prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit, highlighting the severe consequences of insider cybercrime and breach of institutional trust.

Enriched metadata

Scheme
cyber-fraud (100%)
Court
Southern District of New York
Outcome
pleaded
Restitution
$351,850
Classified cyber-fraud(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
audrey straussrichard liriano
Keywords
lirianoaccountsinformationpersonalcomputerinformation technologynewhospitaltechnology employeemonths prisoncompromised accountslinkcompromisedhospital-former information

Extracted insights

Dollar amounts 2
  • $352K $351,850 $100K–$1M
  • $350K $350,000 $100K–$1M
Entities 2
  • person audrey strauss
  • person richard liriano
Triples 9
  • Richard Liriano was sentenced to 30 months in prison
  • Richard Liriano compromised dozens of hospital computers and over 70 personal accounts
  • Richard Liriano stole personal and confidential information from coworkers
  • Audrey Strauss announced Richard Liriano was sentenced to 30 months in prison
  • Lewis A. Kaplan imposed object":
  • Richard Liriano misused administrative access to log in to employee accounts
  • Richard Liriano used malicious software programs including a keylogger
  • Richard Liriano stole user names and passwords of primarily female co-workers
  • Richard Liriano costed his former employer hundreds of thousands of dollars to remediate
View original DOJ press releasejustice.gov
Extracted body text (4,949c)
Press Release Former Information Technology Employee Of Hospital Sentenced To 30 Months In Prison For Computer Intrusion Friday, October 2, 2020 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Richard Liriano Compromised Dozens of Hospital Computers and Over 70 Personal Accounts to Steal Personal and Confidential Information from Coworkers Audrey Strauss, the Acting United States Attorney for the Southern District of New York, announced that RICHARD LIRIANO was sentenced yesterday to 30 months in prison for engaging in a scheme to use malicious software programs, including a program known as a “keylogger,” on dozens of his coworkers’ computers at a New York City-area hospital, secretly obtaining user names and passwords to his victims’ personal email and other accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and accessed their sensitive personal photographs, videos, and other private documents. LIRIANO’s sentence was imposed by United States District Judge Lewis A. Kaplan. Acting U.S. Attorney Audrey Strauss said: “For approximately five years, Richard Liriano used his computer skills and abused the trust placed in him as an information technology professional at a New York hospital to spy on his coworkers and steal personal information from them. Liriano’s disturbing crimes not only grossly violated the privacy of his coworkers but jeopardized the integrity of computers housing vital healthcare and patient information, costing his former employer hundreds of thousands of dollars to remediate. He will now be held accountable.” According to the allegations in the Information to which LIRIANO pled guilty, a prior Indictment filed against LIRIANO, as well as statements made during the sentencing and other proceedings in the case: From at least in or about 2013, up to and including at least in or about 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records and personal photographs, onto his own workspace computer for his own personal use. To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, used various malicious programs that he installed on Hospital-1’s computer systems without authorization, to steal the user names and passwords of his primarily female co-workers. One of these programs is known as a keylogger, which surreptitiously recorded and sent victim employees’ keystrokes to LIRIANO, such as the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 70 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”). LIRIANO then used those stolen usernames and passwords to log into the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for sexually explicit photographs and videos in the Compromised Accounts. LIRIANO’s computer intrusions into Hospital-1’s computer networks caused over $350,000 in losses to Hospital-1, which include the expenses that Hospital-1 incurred to remediate the damage that LIRIANO caused to its computer networks. * * * In addition to the prison term, LIRIANO, 34, of the Bronx, New York, was sentenced to three years of supervised release. LIRIANO was also ordered to pay restitution of $351,850.25. Ms. Strauss praised the investigative work of the Federal Bureau of Investigation and thanked the New York City Police Department for its assistance. This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution. Contact James Margolin, Nicholas Biase (212) 637-2600 Updated October 2, 2020 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 20-222
OCR text (4,949c · plain-text · 99% conf)
Press Release Former Information Technology Employee Of Hospital Sentenced To 30 Months In Prison For Computer Intrusion Friday, October 2, 2020 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Richard Liriano Compromised Dozens of Hospital Computers and Over 70 Personal Accounts to Steal Personal and Confidential Information from Coworkers Audrey Strauss, the Acting United States Attorney for the Southern District of New York, announced that RICHARD LIRIANO was sentenced yesterday to 30 months in prison for engaging in a scheme to use malicious software programs, including a program known as a “keylogger,” on dozens of his coworkers’ computers at a New York City-area hospital, secretly obtaining user names and passwords to his victims’ personal email and other accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and accessed their sensitive personal photographs, videos, and other private documents. LIRIANO’s sentence was imposed by United States District Judge Lewis A. Kaplan. Acting U.S. Attorney Audrey Strauss said: “For approximately five years, Richard Liriano used his computer skills and abused the trust placed in him as an information technology professional at a New York hospital to spy on his coworkers and steal personal information from them. Liriano’s disturbing crimes not only grossly violated the privacy of his coworkers but jeopardized the integrity of computers housing vital healthcare and patient information, costing his former employer hundreds of thousands of dollars to remediate. He will now be held accountable.” According to the allegations in the Information to which LIRIANO pled guilty, a prior Indictment filed against LIRIANO, as well as statements made during the sentencing and other proceedings in the case: From at least in or about 2013, up to and including at least in or about 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records and personal photographs, onto his own workspace computer for his own personal use. To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, used various malicious programs that he installed on Hospital-1’s computer systems without authorization, to steal the user names and passwords of his primarily female co-workers. One of these programs is known as a keylogger, which surreptitiously recorded and sent victim employees’ keystrokes to LIRIANO, such as the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 70 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”). LIRIANO then used those stolen usernames and passwords to log into the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for sexually explicit photographs and videos in the Compromised Accounts. LIRIANO’s computer intrusions into Hospital-1’s computer networks caused over $350,000 in losses to Hospital-1, which include the expenses that Hospital-1 incurred to remediate the damage that LIRIANO caused to its computer networks. * * * In addition to the prison term, LIRIANO, 34, of the Bronx, New York, was sentenced to three years of supervised release. LIRIANO was also ordered to pay restitution of $351,850.25. Ms. Strauss praised the investigative work of the Federal Bureau of Investigation and thanked the New York City Police Department for its assistance. This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution. Contact James Margolin, Nicholas Biase (212) 637-2600 Updated October 2, 2020 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 20-222