Former IT Contractor Pleads Guilty To DaimlerChrysler Sabotage
A federal prosecutor said William Johns was let go from a wireless installation job before using a computer kiosk in a visitors' lobby to delete needed passwords and files.
An IT contractor who had been let go from his job at DaimlerChrysler pleaded guilty to sabotaging the automaker's wireless inventory network and causing more than $29,000 in damages.
William A. Johns, 65, of Lake Orion, Mich., pleaded to the charge of unlawful computer intrusion in U.S. District Court. Under the terms of the plea agreement, he faces up to 12 months in prison and a fine of up to $250,000. Johns also will be required to make full restitution to DaimlerChrysler in the amount of $29,916 to pay for the costs associated with repairing the damaged network.
"A case like this shows the potential vulnerability -- the potential for a seriously damaging breach," said Terrence Berg, First Assistant U.S. Attorney, in an interview with InformationWeek. "The company caught on quickly and took swift action so this didn't cause them especially significant damage. But it showed that the vulnerability was there and it gave them a chance to fix it."
According to a release from the U.S. Attorney's office, Johns worked for Intermec, a consulting company hired to come in and set up a new wireless network for Chrysler's remote parts distribution facilities in Atlanta, Georgia, Portland, Oregon, and Denver and Colorado. MOPAR is the carmaker's parts distribution component. Johns was part of the installation team.
However, Berg said at some point Johns was let go from the DaimlerChrysler job.
Court papers showed that on Oct. 3, 2003, Johns entered the DaimlerChrysler Assembly plant in Sterling Heights, Mich., and accessed a computer kiosk in the visitors' lobby. Based on his familiarity with DaimlerChrysler's computer system and security systems, he used the terminal to delete files and passwords from wireless devices used in remote parts distribution facilities in remote cities.
The government told the court that DaimlerChrysler was forced to remove and repair the devices, causing each MOPAR facility to shut down for about seven and a half hours, causing more than $25,000 in damages.
Berg said that while Johns was making his plea to the court, he called his actions "a prank."
"If that's accurate, I don't know," added Berg. "Sometimes when someone is an IT consultant like that, they cause a problem because they want to be the one to fix it. They cause problems so they can be appreciated when they solve them."
Berg said DaimlerChrysler was quick to call in the FBI when it discovered the incident.
How Enterprises Are Attacking the IT Security EnterpriseTo learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Digital Transformation Myths & TruthsTransformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.