Fannie Mae Insider Convicted For Planting Malware
Former Unix engineer inserted malicious script designed to destroy data at the financial services firm, finds federal jury.
![]() | |
Slideshow: Cloud Security Pros And Cons | |
| (click for larger image and for full photo gallery) |
According to the FBI, Makwana worked as a contract Unix engineer for Fanny Mae -- aka the Federal National Mortgage Association, a federally chartered corporation that purchases mortgages -- for three years, and had access to the organization's network of almost 5,000 servers.
More Storage Insights
Webcasts
- SMB Server Guide: Meeting Email, Virtualization, and Business Application Challenges
- Forrester Total Economic Impact study of Midrange Storage
White Papers
More >>Reports
More >>Trial testimony detailed how Makwana was fired on October 24, 2008, and ordered to return all Fannie Mae-issued IT equipment, including his laptop. Five days later, however, "a Fannie Mae senior engineer discovered a malicious script embedded in a routine program," said the FBI.
"A subsequent analysis of the script, computer logs, Makwana's laptop, and other evidence revealed that Makwana had transmitted the malicious code on October 24, 2008, which was intended to execute on January 31, 2009," said the FBI. "The malicious code was designed to propagate throughout the Fannie Mae network of computers and destroy all data, including financial, securities, and mortgage information."
On that day, upon trying to log in to the Fannie Mae network, users would have received a message saying only "server graveyard."
The attack is a reminder of the danger of insider attacks, and highlights how, even though the erased data would likely have been restored, the incident would still have disrupted the organization's operations.
"Even though it would be likely that the firm would have off-site backups that would not have been hit by the malware attack, it would still have been enormously disruptive for the company, at a time when confidence in the financial industry was quite rocky anyway," said Graham Cluley, senior technology consultant at Sophos. "Indeed, the court heard evidence that it would take a week for the company to get its systems back up and running again."
The server market is changing rapidly. In this report, we look into the technological advances driving the server market forward, as well as the server strategies of Dell, Hewlett-Packard, IBM, Oracle-Sun, Cisco, and other vendors. Download it here (registration required).
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Subscribe to RSSResource Links
Related Webcasts
- Reduce Cost and Improve Manageability with IBM Windows Storage Server
- SMB Server Guide: Meeting Email, Virtualization, and Business Application Challenges
- The Dell Difference: Lessons from Dell’s Own IT Transformation
- Best Practices in SMB Desktop Virtualization
- Forrester Total Economic Impact study of Midrange Storage
This Week's Issue
Free Print Subscription
SubscribeCurrent Healthcare Issue
- InformationWeek Healthcare CIO 25: Our second annual honor roll of the health IT leaders driving healthcare's transformation.
- EHR Unreadiness: Only a small percentage of physicians planning to apply for Meaningful Use funds have e-health record systems capable of achieving most of the requirements. .
- And much more!
- Read the Current Issue
Related Whitepapers
Featured Resource
"Read this white paper to learn about the security issues you need to consider and how IBM assessment services and guidelines for securing cloud implementations can help you maximize the business value of cloud investments while minimizing risk.
Read Now














Comments: