Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

mahatmakanejeeves

(61,654 posts)
Mon May 24, 2021, 09:06 AM May 2021

Hacker who sold UPMC employee data on the dark web pleads guilty

Hat tip, a listserv I'm on

Via the Associated Press:

Hacker who sold UPMC employee data on the dark web pleads guilty

Paula Reed WardPAULA REED WARD | Thursday, May 20, 2021 11:57 a.m.

A Michigan man pleaded guilty Thursday morning to hacking a UPMC employee database in 2014 and stealing the personal information of more than 65,000 people and then selling it on the dark web. ... Justin Sean Johnson, 30, will be sentenced by U.S. District Chief Judge Mark Hornak in about four months. He is being held in the Butler County Prison and appeared for Thursday’s hearing on an online video program.

Johnson faces a maximum of seven years in prison after pleading guilty to just two of 43 counts against him. He pleaded guilty to one count of conspiracy and one count of aggravated identity theft, although he accepted responsibility for all of the conduct laid out in the indictment. ... According to Assistant U.S. Attorney Greg Melucci, Johnson, investigators with the IRS, U.S. Postal Service and U.S. Secret Service conducted a nearly five-year investigation concerning Johnson and his co-conspirators.

They found that Johnson, who had become an expert in the PeopleSoft software used by UPMC, used that expertise to hack their employee database. ... He then sold that information, using the moniker “The Dearth Star” and later “Dearthy Star” on the dark web.

“Virtually every UPMC employee’s [personally identifiable information] was victimized,” Melucci said. “The intruder clearly had a high skill set.” ... Then, in 2014, the prosecutor continued, the IRS received hundreds of false 2013 tax returns seeking to have the refunds sent on Amazon.com gift cards.

{snip}

I don't think that's one of the options.
2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Hacker who sold UPMC employee data on the dark web pleads guilty (Original Post) mahatmakanejeeves May 2021 OP
Only 7 years max? TheFarseer May 2021 #1
Pittsburgh Post-Gazette coverage of same story FakeNoose May 2021 #2

FakeNoose

(36,019 posts)
2. Pittsburgh Post-Gazette coverage of same story
Mon May 24, 2021, 09:44 AM
May 2021

(link) https://www.post-gazette.com/news/crime-courts/2021/05/20/Hacker-stole-sold-UPMC-employee-data-admits-crimes-Justin-Sean-Johnson-detroit/stories/202105200148

This version contains many details on the involvement of a fellow-hacker from Venezuela, Yoandy Perez Llanes, who had previously been convicted in the case and deported. Also details on how Johnson was able to hack into the UPMC datafiles and steal the data.

Before Johnson tried to sell the employee's data, he used it in 2013 to file false income tax returns to steal the UPMC employees' refunds. The weird thing that tipped off the IRS was the repeated request that refund be placed on Amazon gift cards. That's the item the investigators used to break the case as they followed the Amazon purchases to Venezuela.

The international hacking case has developed over the last 7 years, with Justin Sean Johnson finally pleading guilty to 2 of the 49 federal charges. He'll be sentenced in 4 months. The refund scheme has cost the IRS an estimated $1.7 million and restitution will likely be part of the sentence.


Latest Discussions»Region Forums»Pennsylvania»Hacker who sold UPMC empl...