Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« More On The HHS HIPAA Compliance Activities | Main | BONY Loss Of Backup Tape With Unencrypted PII Is Disappointing...But Not Surprising »

Insider Threat Example: Bank Worker Sentenced To 36 Months In Prison; + Prison Terms For Others In Cahoots

I've been doing some research for insider threat training content I'm creating, and I ran across a recent judgment against a bank employee for identity theft. This provides some good lessons to organizations for the insider threat, and would make a great case study for any organization to help personnel improve the ability to better protect personally identifiable information (PII).

Here's the news release from the The United States Attorney's Office for the Southern District of Texas...

"AMEGY BANK EMPLOYEE SENTENCED FOR IDENTITY THEFT

(HOUSTON, Texas) - Former Amegy Bank senior banker Lamont Wallace, 34, of Houston, Texas, has been sentenced to 36 months in federal prison, U.S. Attorney Don DeGabrielle announced today. U.S. District Judge Sim Lake also sentenced co-defendant Ifeyhewen Badidi, a 34-year-old illegal immigrant from Liberia, to 57 months in federal prison.

Wallace pleaded guilty to conspiracy to commit bank fraud and aggravated identity theft, while Badidi pleaded guilty to mail fraud and aggravated identity theft. Wallace was also ordered to serve three years supervised release after he completes his prison term. It is expected that Badidi will be deported after he has served his sentence.

Senior banker Lamont Wallace acquired the personal bank account information of Amegy Bank customers and sold the information to an individual named Chukwemeka Felix Iroh. Iroh and Badidi used that information to unlawfully transfer funds from the accounts to other bank accounts the conspirators had established using the stolen identity of others. Investigators discovered a total of $161,000 unlawfully transferred from the compromised Amegy Bank accounts. Bank investigators detected the scheme and froze the funds before the conspirators could withdraw the money.

Iroh, a Nigerian national, pleaded guilty to conspiracy to commit bank fraud and aggravated identity theft and is scheduled to be sentenced May 22, 2008. Both Badidi and Iroh have been in federal custody since there arrest in May 2007. Wallace has been permitted to remain free on bond pending an order to surrender to a Bureau of Prisons facility to be determined in the near future.

This case was investigated by Inspectors of the United States Postal Inspection Service and is being prosecuted by Assistant United States Attorney Jay Hileman."

Think about the controls that could have been in place to help prevent this type of co-conspiracy from occurring in the first place...there are several.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/728

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.