Original URL: http://www.channelregister.co.uk/2006/06/08/ubs_hack_attack/
A US court has heard how a disgruntled IT manager allegedly wiped out all UBS Paine Webber servers for a day leaving traders unable to trade because he was unhappy with his bonus.
Not only is Roger Duronio accused of using a "logic bomb" to crash the investment bank's servers he is also accused of going short on UBS shares just before the incident - so if UBS shares fell in value Duronio would make a profit. UBS yesterday asked the judge to keep the trial secret to avoid embarrassment and injury to the bank - the judge refused.
Roger Duronio was paid a salary of $125,000 by the bank and was expecting a bonus of $50,000. When he only got $32,000 he decided to take revenge on the bank, prosecutors claim.
He created the logic bomb which would delete all the files in the host server in the central data centre and then every server in every branch.
Some 2,000 servers did go down and 400 branch offices were hit. Backup systems did not work and files were deleted.
UBS IT manager Elvira Maria Rodriguez told the court: "It was the magnitude of it. How on earth were we going to bring them all back up?...If I had a scale of 1 to 10 this would be a 10-plus."
She told the court the escalation centre was "chaos" on the day and that 200 IBMers had to be drafted in to help fix problems at branch offices.
Duronio's defence attorney said the code was planted as a joke by someone else. He accused UBS, and its first forensics company @Stake of destroying evidence.
More details from Information Week here. (http://www.informationweek.com/industries/showArticle.jhtml?articleID=188702216&pgno=1&queryText=)
Irate sysadmin locks San Francisco officials out of network (15 July 2008)
http://www.theregister.co.uk/2008/07/15/sf_bofh_sabotage_charges/
Sys admin jailed for 30 months over failed logic bomb (9 January 2008)
http://www.channelregister.co.uk/2008/01/09/logic_bomb_bofh_jailed/
Sysadmin admits planting 'logic bomb' in drug firm database (22 September 2007)
http://www.channelregister.co.uk/2007/09/22/sysadmin_logic_bomb_followup/
Sysadmin 'tried to boobytrap' drug firm database (20 December 2006)
http://www.channelregister.co.uk/2006/12/20/bofh_logic_bomb_charges/
UBS logic bomber jailed for eight years (13 December 2006)
http://www.channelregister.co.uk/2006/12/13/ubs_logic_bomber_sentenced/
Dating site hacker avoids jail (8 November 2006)
http://www.channelregister.co.uk/2006/11/08/dating_site_hacker_sentenced/
Flaw exposed in HSBC's online banking (10 August 2006)
http://www.channelregister.co.uk/2006/08/10/flaw_hsbc/
More thoughts on identity (7 June 2006)
http://www.theregister.co.uk/2006/06/07/branscombe_identity_blog/
Getting your site sorted for IE 7 (2 June 2006)
http://www.theregister.co.uk/2006/06/02/support_ie7/
Teen hack suspects charged over MySpace extortion bid (25 May 2006)
http://www.channelregister.co.uk/2006/05/25/myspace_hack_charges/
Dating site hack suspect charged (25 May 2006)
http://www.channelregister.co.uk/2006/05/25/hacking_charges/
'Pentagon hacker' prepares for verdict (28 April 2006)
http://www.channelregister.co.uk/2006/04/28/mckinnon_interview/
Breach case could curtail web flaw finders (28 April 2006)
http://www.channelregister.co.uk/2006/04/28/breach_suspect_prosecuted/
Early days of dial-up hacking recalled (27 April 2006)
http://www.theregister.co.uk/2006/04/27/infosec_blog_six/
© Copyright 2008