Man stole data from U.S. service members via P2P
- 16 September, 2011 16:14
- Comments
A California man who dug up sensitive information belonging to U.S. service members on peer-to-peer networks, and then used it to order iPods, cameras, and even washing machines from an online store, was sentenced to 75 months in federal prison Thursday.
Rene Quimby, 42, had already pleaded guilty to fraud and identity theft charges in May. According to court filings, Quimby stumbled upon the scam four years ago after uncovering military rosters listing sensitive information online. His victim was the Army and Air Force Exchange Services (AAFES), the organization that does about US$10 billion in business annually, running the post exchange retail outlets on military bases.
"Quimby learned of the AAFES.com website when he downloaded a file that contained a service member's username and password for an AAFES account," reads a factual resume signed by Quimby in May when he entered his guilty plea. "He then learned that he could use service members' social security numbers and dates of birth to log into the site."
His next move was to chat with the website's customer support staff. Using the same stolen information to answer their security questions, he'd get them to tell him the victim's STAR credit card number, used to make purchases with the AAFES. He then would spend as much as he could in an online shopping spree, buying computers, cameras, iPods, even washing machines. He'd have the goods mailed to different addresses in California, where he'd pick them up and fence them.
In some cases, Quimby found digital images of victims' checks. Using the account and bank routing numbers visible on the checks, he'd set up online fund transfers and empty checking accounts to pay down the balances on his stolen STAR cards. Then he'd "'max-out' the military STAR credit cards over and over again," the factual resume states.
The scam ended when AAFES.com finally changed its policy and stopped handing out credit card numbers via online chat.
Investigators found more than 16,000 identities on Quimby's computer, and he'd compiled detailed dossiers on 650 victims, the U.S. Department of Justice said in a statement.
Data leakage on peer-to-peer networks has emerged as a serious problem for consumers and corporations. Often peer-to-peer users don't realize that they're sharing folders or files that they'd really prefer to keep secret. Apparently that is how Quimby was able to uncover all his data, using popular file-sharing programs such as Etomi Pro and Frostwire.
The problem got so bad that last year that the U.S. Federal Trade Commission sent out letters to about 100 U.S. companies warning them that they were inadvertently publishing customer information such as social security numbers and driver's licenses on peer-to-peer networks.
Quimby was sentenced in the U.S. District Court for the Northern District of Texas. He must also pay more than $210,000 in restitution to AAFES. His attorney, Carlton McLarty, did not return messages seeking comment.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
So Long, Silos: Why Multi-Domain MDM Is Better For Your Business
Say “so long” to silos. This white paper explains why a multi-domain MDM solution is far better than single-domain, single-focused point solutions. You’ll learn what to look for in a multi-domain solution so you don’t outgrow it or are forced to purchase multiple products down the road. You’ll also get tips on how to select a multi-domain solution that can lead to multiple benefits over many years. The age of multi-domain MDM is here. See why you should say “hello” to it! -
Government Communications 2.0
The problem with data is that it’s only useful if you share and use it. Equally, the more data we share electronically, the greater the risk of it falling into the wrong hands. Public sector organisations can’t function without legitimately gathering and using personal information about the citizens they are mandated to serve. Technology has made a significant contribution to that process, but has also brought new risks. Read on. -
Oracle Database 11g Product Family
Oracle Database 11g is available in a variety of editions tailored to meet the business and IT needs of all organisations. This paper outlines the features and options available with each edition of Oracle Database 11g. Read on for more details.
-
Office 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Office 2007 for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7








Comments
Post new comment