IT pro gets four years for building botnets
By
Robert McMillan
,
IDG News Service
, 03/06/2009
- Share/Email
- Tweet This
- Print
An employee of search engine startup Mahalo has been sentenced to four years in prison for infecting as many as 250,000 computers with malicious botnet computer code.
Slideshow: 10 of the Worst Moments in Network Security History
John Schiefer was sentenced Wednesday in federal court after previously pleading guilty to hacking, fraud and wiretapping
charges. He was arrested in 2007 as part of a large U.S. Federal Bureau of Investigation enforcement action against botnet makers, called Operation Bot Roast II.
The case marks the first time that someone has been charged with operating a botnet under federal wiretapping laws. Schiefer
could have been sentenced to as much as five years in prison on the charges.
When they hired him, Mahalo executives didn't know about his criminal activities. In a blog posting, Mahalo founder Jason Calacanis said company CTO Mark Jeffrey had "screwed up by not doing a simple Google search on John’s
name," but he stood by his employee, saying there is a fine line between hackers "who put one foot over the line" and commit
minor indiscretions, and others like Schiefer, who "race past it."
"I consider myself a fairly decent judge of character, and after spending months with John, I’m convinced he was an angry
stupid kid when he launched his botnet attack (which did .000000001% of the damage it could have)," Calacanis wrote. "Now
he’s an adult who just wants to make a decent living, spend time with his significant other and breathe the clean air off
the Pacific Ocean by our offices in Santa Monica."
"When he comes out, I hope to be able to offer him a job and that we can work together again," Calacanis said.
Schiefer built his botnet army while a consultant at 3G Communications, a small Los Angeles telecommunications company. The
network, built with the help of two accomplices, was used to snoop in on Internet traffic between victims' computers and financial
institutions such as PayPal, prosecutors said. Schiefer would then make purchases or simply drain his victims' bank accounts.
He used several partners in the scheme -- some of them minors whom he "bullied ... into participating in the crimes," prosecutors
said in the suit, filed in the U.S. District Court for the Central District of California.
When a minor named Adam expressed reservations about claiming stolen money from PayPal, Schiefer told Adam to "quit being
a bitch and claim it," the filing states.
Online, Schiefer was known as Acidstorm. His MSN Messenger handle also included the tagline, "Remember the name or feel the
pain."
In another scam, a Dutch online marketing company called Simpel Internet paid him more than $19,000 for installing the company's
TopConverting adware on PCs, which he did without the consent of his victims. As part of his plea agreement, Schiefer will pay $20,000
in restitution to Simpel Internet and the financial institutions he defrauded.
He also used the botnet to launch distributed denial of service (DDOS) attacks, and in an interview with the FBI he claimed
to have knocked the Los Angeles Times' Web site offline, prosecutors said.
The IDG News Service is a Network World affiliate.
Comments (4)
Far too little penalty for far-reaching crimesBy Anonymous on March 6, 2009, 4:46 pmOnly four years TOTAL? He should have received 4 years for each PC and financial account he illegally accessed, not just a blanket 4 years for the thousands of...
Reply | Read entire comment
Guy's a thiefBy Anonymous on March 6, 2009, 6:01 pmAbsolutely too small a penalty. Realistically, he should do a minimum of 10 years in the state pen. If he lives through it, permanent parole with no computer access...
Reply | Read entire comment
What the?By Anonymous on March 7, 2009, 1:55 pmThis person should be put in jail for a long time. Just like any other felon, not allowed to own a weapon. He uses technology as a weapon. Ban him, track him,...
Reply | Read entire comment
WTF?By Anonymous on March 9, 2009, 4:34 pm"Schiefer hopes to seek future employment in the information security field, prosecutors said." Come on...Good luck with that career. NOBODY will hire this guy...
Reply | Read entire comment
View all comments