Some employees do not hesitate to compromise their company by selling sensitive data and internal access on the dark web. Testimonies of those who track them.
To sabotage, enrich themselves or take revenge, employees exfiltrate data from their company. “And we are seeing it more and more. At the firm, we have several clients from very varied sectors, such as tourism, health, transport, who have been affected by this phenomenon. The act of cyber-betrayal which is the most successful at the moment is the illegal downloading of company information by the employee, the temporary worker, or the work-study worker, who resells it on the dark web”, indicates the lawyer Alexandra Iteanuspecializing in cybersecurity law. Far from being uniform, the strategies deployed by these collaborators, called “insider” in the world of cybersecuritysometimes turn out to be frankly atypical.
Revenge is a dish best served cold
“I handled an insider case with which it went very far, really very far. In fact, it was the insider himself who requested our services to investigate a data leak of which he himself was at the origin,” recalls David Syguladirector of the cyber threat intelligence division of Anozr Way. Before joining the Breton company Osint, David Sygula was in charge of research and analysis of cyber threats in another cybersecurity company. It was at that moment that he crossed paths with this atypical insider. “He contacted us explaining that strange things were happening in the company that employed him: people were receiving threats by emails, SMS, etc. Then he explained to us that he had found company data on the dark web. But we very quickly realized that this person was not telling us everything. As we untangled the ball of yarn, we found that there was a lot inconsistencies in his speech. And the messages in the dark web, which he attributed to a cybercriminal, contained data that he was one of the only ones who could have possessed. Also, these messages contained the name of the company, which is strange, very quickly, lots of small inconsistencies indicated to me that this story clearly did not hold water and that the data leak could only come from him.
But that’s not all. Continuing his investigations with his team, David Sygula came across a very worrying message: “In a mutual aid forum between cybercriminals, someone who presented himself as a service provider close to the industry, explained that he had been hired to kill and kidnap employees of the company if the company did not pay a ransom to recover his data. But this false service provider was in fact the insider himself! It was he himself who had invented this whole story. It was to scare, to for the company to pay the ransom or to create an alibi in case he was caught.” At that point, David Sygula decided to talk to the company’s CEO: “he told us that he already had doubts about this person.” “By contacting us, by telling us his version of the facts, this insider actually wanted to condition us into his own story. I think he had personal problems linked to the company, resentment against it. In my opinion, his act went beyond pure cyber-ransoming.”
And for good reason. “In all these cases of malicious employees, what we frequently see is that it is revenge that motivates. This revenge can be linked to a refused raise, to being put aside, etc. Sometimes employees are no longer at all motivated by their work and have access to too much information. They will therefore monetize it in the dark web without feeling too guilty. Some individuals have far too much access, which makes revenge easy.” A client of Alexandra Iteanu was also the victim of cyber-revenge caused by overly broad and exclusive access: “He was a community manager for a company. He therefore managed all the social networks. He was fired and, to take revenge, he did not want to give back access to the social networks, which only he had. Then, he wrote defamatory posts about the company from the company’s LinkedIn account.”
Serving competitors and States
In some cases, cyber-betrayal can serve business intelligence and espionage purposes. Gabriel de Brossesexternal CISO and president of Tevarua-Conseil, a cybersecurity company, was an “indirect witness” of such a situation: “I advised a company where one of the employees was exfiltrating data to share with the main competitor. During calls for tender, the competitor then knew the prices offered by the company, and other information. It was very unfair.”
Sometimes this espionage is carried out for geopolitical purposes. Loïc Guézodirector of cybersecurity strategy at Proofpoint, and vice-president of the French Information Security Club (Clusif), worked on “an unprecedented case of espionage linked to the Russian-Ukrainian conflict”: “In parallel with military operations on Ukrainian soil, a large industrial group present, among other places, in Ukraine, noted illegitimate access to its information system coming from Ukrainian workstations and accounts. The Proofpoint tools effectively detected unprecedented downloads by their volume and locally. They also noted legitimate but abnormal access from the point of view of the employee to whom the account was attached. From a position in Ukraine, someone was searching the global information system of this industrialist. The explanation given to me is that pro-Russian Ukrainians had carried out a special operation on the information system of this industrial group.
A betrayal often committed with impunity
Although these cyber-betrayals can be fatal for an organization, their perpetrators often act with a sense of impunity. It is indeed difficult to identify the insider, recalls Geert Baudewijns, cybernegotiator and CEO of Secutec, a cybersecurity company. “A hacker who does not know the company’s network as an employee knows it, leaves traces everywhere. We see this very clearly when we carry out the forensic analysis following a ransomware attack. But when the attack comes from an insider, the investigation gives few results, because the person knows very well where he must go, through which accesses he must pass, etc. So we understand very quickly when the attack comes from an insider. However, given the few traces that let the insider know, it is very often difficult to identify him among all the company’s employees. Much to the company’s dismay…