On MovieTome: Whedon makes an offer on Terminator
BNET Business Network:
BNET
TechRepublic
ZDNet

January 29th, 2009

Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn't revoke server privileges

Posted by Larry Dignan @ 6:46 am

Categories: General, Government, IT Management, Security

Tags: Fannie Mae, Information Technology, Malware, Mortgages, Servers, Finance, Capital Structures, Hardware, Larry Dignan

A former Fannie Mae IT contractor has been indicted for planting a virus that would have nuked the mortgage agency’s computers, caused millions of dollars in damages and even shut down operations. How’d this happen? The contractor was terminated, but his server privileges were not.

Rajendrasinh Makwana was indicted on Tuesday in the U.S. District Court for Maryland (press reportscomplaint and indictment PDFs). From early 2006 to Oct. 24, Makwana was a contractor for Fannie Mae. According to the indictment, Makwana allegedly targeted Fannie Mae’s network after he was terminated. The goal was to “cause damage to Fannie Mae’s computer network by entering malicious code that was intended to execute on January 31, 2009.” And given Fannie Mae–along with Freddie Mac–was nationalized in an effort to stabilize the mortgate market Makwana could caused a good bit of havoc. 

Makwana worked at Fannie Mae’s data center in Urbana, MD as a Unix engineer as a contractor with a firm called OmniTech. He had root access to all Fannie Mae servers. 

The tale of Makwana malware bomb plot is a warning shot to all security teams and IT departments. Given the level of layoffs we’ve seen lately the ranks of disgruntled former employees is likely to grow. Is there any company NOT lopping off a big chunk of its workforce? And some of these workers may even have Makwana’s access privileges and knowledge of the corporate network. 

Sophos’ Graham Cluley says:

As belts tighten and the credit crunch continues to hit around the world, more and more companies will be making the decision to make staff redundant. As we’ve written before, a disaffected employee could create havoc inside your organisation so make sure that appropriate security is in place.

Also seeAre you wary of the insider on the outside?

Indeed, Makwana had intended to do some serious damage such as “destroying and altering all of the data on all Fannie Mae servers.” That quote puts it mildly. According to the initial complaint against Makwana, the former contractor’s virus “would have caused millions of dollars of damage.” Anyone that logged into the Fannie Mae network on Jan. 31 would have seen a message “Server Graveyard.”

Details of Makwana’s alleged plot surfaced in a complaint that was initially sealed to protect the identity of Fannie Mae. In the complaint, Fannie Mae is referred to as “ABC,” but defined as an outfit that facilitates mortgages. In a sworn statement, FBI agent Jessica Nye outlined the following:

Luckily, the Fannie Mae server scripts were returned to normal before mortgage chaos ensued. But the errors listed in the complaint are clear. The biggest problem: Makwana’s access wasn’t terminated when he was. He had access to Fannie Mae servers longer than he should have. 

Here’s a look at the notable excerpts of the complaint. As you can see there were warning signs and mistakes made along the way. Emphasis is mine. 

 

So far so good right? Makwana screwed up, was terminated and had to turn in his gear and access privileges. 

Well that last part didn’t go so well. 

The good news is that Makwana’s access didn’t go on indefinitely. I’ve known more than a few people that could access their former employer’s network for months after they left the company. 

However, catching Makwana’s script was really a function of luck.

There was also some good detective work too–the complaint details Makwana’s techniques and script set-up–by the Fannie Mae security team. However, a lot of work could have been avoided if only Makwana’s privileges were terminated when he was.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 51 Talkback(s)
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn
Convert MOD files is designed for mod converting.... (Read the rest)
Posted by: gwreg4fge Posted on: 10/27/09 You are currently: a Guest | | Terms of Use
Must Have Been A Windows Network  itanalyst2@... | 01/29/09
Message has been deleted.  n0neXn0ne | 01/29/09
LOL.. you apparently cant read. Read the article again.  Been_Done_Before | 01/29/09
Why should he let facts get in the way of his trolling?  James T. Kirk | 01/29/09
Windows server.  RobertMoore12@... | 01/29/09
In this case...  Marty R. Milette | 02/01/09
Remind me not to hire itanalyst2  Dr_Zinj | 02/02/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  disgen@... | 01/29/09
They do  letranger66 | 01/30/09
Gee -- that'd work REAL GOOD...  Marty R. Milette | 02/01/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  aspit | 01/29/09
LDAP is a pain to setup and maintain...  rdiekema@... | 01/29/09
Even so...  mejohnsn | 01/29/09
That's what it sounds like.  zclayton2 | 01/30/09
Fannie Mae is not in the stone age  nadofurtado | 01/31/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  jhampton@... | 01/29/09
Change Management  IanF | 01/29/09
Government run (imagine that)...  Christian_<>< | 01/29/09
Internal Threats  jshinn | 02/01/09
This kind of stuff is VERY real...  Marty R. Milette | 02/01/09
I'edfmrr Jill my cat does linux.  rtirman37@... | 01/29/09
End of the day?  jshaw4343 | 01/29/09
Exactly, we dont even warn people, we call them in and remove access....  Been_Done_Before | 01/29/09
Ideally security systems are linked and centralized,  dinosaur_z | 01/29/09
Not necessarily in this case  dkawalec | 01/29/09
We remove priviledges first  sholleran | 01/29/09
Same here...  James T. Kirk | 01/29/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  seannj427 | 01/29/09
Never wait till you last day!  tlwalker1962@... | 01/29/09
Malware?  juantar | 01/29/09
Point made  Cayble | 01/29/09
Re Point made  vilppuu@... | 02/01/09
It's similar  AndyCee | 01/29/09
SHOCKER! - Democrat ran Fannie Mae disaster  Christian_<>< | 01/29/09
And you are still cashing those welfare checks...  B.O.F.H. | 01/29/09
Have you all been booted of the political forums? nt  AndyCee | 01/29/09
The opensource_user01 broken record skips repeatedly....  MGP2 | 01/30/09
Who's Fannie Mae be at risk here?  bobmatch@... | 01/31/09
Like my Daddy used to say  dev-null | 02/27/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  IanF | 01/29/09
Is my personal information safe?  DAvenger | 01/29/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  JOHN_TUOHY | 01/30/09
Does the Press Understand Computers?  jabailo1 | 01/30/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  SysAdminII | 01/30/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  netsecure | 01/31/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  nadofurtado | 01/31/09
FBI agent lack of computer knowledge  bobpeg | 02/02/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  storm@... | 02/10/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  storm@... | 02/10/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  dev-null | 02/27/09
RE: Fannie Mae IT contractor indicted for planting malware; Mortgage giant didn  gwreg4fge | 10/27/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline