United States v. Richard Liriano
raw: Former Employee Of Hospital Pleads Guilty To Compromising Dozens Of Hospital Computers And Coworkers’ Email Accounts And Stealing Their Confidential Information
Former Employee Of Hospital Pleads Guilty To Compromising Dozens Of Hospital Computers And Coworkers’ Email Accounts And Stealing Their Confidential Information (S.D.N.Y. Dec. 20, 2019)
Richard Liriano, a former IT employee at a New York City-area hospital, pled guilty to computer fraud for installing keyloggers and malicious software to steal login credentials and confidential personal data from at least 70 coworkers’ accounts, causing over $350,000 in remediation costs and exposing sensitive healthcare and private information for voyeuristic purposes.
Richard Liriano, a 33-year-old former IT employee at a New York City-area hospital, pled guilty to one count of computer fraud for using keyloggers and unauthorized software to steal usernames and passwords from at least 70 coworkers’ email and online accounts between 2013 and 2018. He abused his administrative access to access sensitive personal data—including tax records, photographs, and videos—primarily targeting female employees, and also compromised systems containing protected healthcare and patient information. His actions resulted in over $350,000 in remediation costs to the hospital, and he faces a maximum of 10 years in prison, with sentencing scheduled for April 15, 2020.
Richard Liriano, a 33-year-old former information technology employee at a New York City-area hospital, pled guilty to one count of computer fraud for systematically compromising dozens of coworkers’ computers between 2013 and 2018 using malicious software, including keyloggers that captured keystrokes to steal login credentials. He exploited his administrative access to log into at least 70 compromised email and online accounts, accessing private and confidential files such as personal photographs, videos, tax records, and other sensitive documents, often conducting voyeuristic searches targeting primarily female employees. His intrusions extended to hospital systems housing protected healthcare and patient information, causing over $350,000 in remediation costs to the institution. Liriano copied stolen data onto his own workspace computer for personal use and maintained unauthorized access over several years. He was arrested on November 14, 2019, and pleaded guilty in Manhattan federal court before Magistrate Judge Kevin N. Fox. The case was prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit, with investigative support from the FBI and NYPD. Liriano is scheduled to be sentenced on April 15, 2020, by U.S. District Judge Lewis A. Kaplan, facing a maximum statutory penalty of 10 years in prison.
Extracted insights
- $350K $350,000 $100K–$1M
- person richard liriano
- Richard Liriano Pled Guilty To Compromising Dozens Of Hospital Computers And Coworkers’ Email Accounts And Stealing Their Confidential Information
- Richard Liriano Used Malicious Software Programs, Including A Program Known As A “Keylogger”
- Richard Liriano Obtained User Names And Passwords To His Victims’ Personal Email And Other Accounts
- Richard Liriano Stole Private And Confidential Files
- Richard Liriano Compromised Their Password-Protected Online Accounts
- Richard Liriano Accessed Their Sensitive Personal Photographs, Videos, And Other Private Documents
- Richard Liriano Installed A “Keylogger” On Dozens Of His Coworkers’ Computers
- Richard Liriano Used Other Unauthorized Software To Spy On And Steal Personal Information From Them
- Richard Liriano Misused Administrative Access Provided To Him As An Information Technology Employee At A New York City-Area Hospital
- Richard Liriano Copied Other Employees’ Personal Documents, Including Tax Records And Personal Photographs, Onto His Own Workspace Computer For His Own Personal Use
- Richard Liriano Used Various Malicious Programs To Steal The User Names And Passwords Of His Primarily Female Co-Workers
- Keylogger Recorded And Sent Victim Employees’ Keystrokes To Liriano
- Richard Liriano Stole Usernames And Passwords For At Least Approximately 70 Email Accounts Belonging To Hospital-1 Employees Or Persons Associated With Those Employees
- Richard Liriano Logged In To The Compromised Accounts And Obtain Unauthorized Access To Other Password-Protected Email, Social Media, Photographs, And Online Accounts To Which The Compromised Accounts Were Registered
- Richard Liriano Conducted Searches For Sexually Explicit Photographs And Videos In The Compromised Accounts
Press Release Former Employee Of Hospital Pleads Guilty To Compromising Dozens Of Hospital Computers And Coworkers’ Email Accounts And Stealing Their Confidential Information Friday, December 20, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that RICHARD LIRIANO pled guilty today to one count of computer fraud in connection with his scheme to use malicious software programs, including a program known as a “keylogger,” on dozens of his coworkers’ computers at a New York City-area hospital, secretly obtaining user names and passwords to his victims’ personal email and other accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and accessed their sensitive personal photographs, videos, and other private documents. LIRIANO pled guilty earlier today in Manhattan federal court before United States Magistrate Judge Kevin N. Fox. U.S. Attorney Geoffrey S. Berman said: “To feed his voyeuristic curiosity, Richard Liriano, an information technology professional at a New York hospital, installed a “keylogger” on dozens of his coworkers’ computers and used other unauthorized software to spy on and steal personal information from them. Liriano’s disturbing crimes not only invaded the privacy of his coworkers; he also intruded into computers housing vital healthcare and patient information, costing his former employer hundreds of thousands of dollars to remediate. He will now be held accountable for his actions.” According to the allegations in the Information to which LIRIANO pled guilty, a prior Indictment filed against LIRIANO, as well as statements made during the plea and other proceedings in the case: From at least in or about 2013, up to and including at least in or about 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records and personal photographs, onto his own workspace computer for his own personal use. To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, without authorization, used various malicious programs to steal the user names and passwords of his primarily female co-workers. One of these programs was known as a keylogger, which recorded and sent victim employees’ keystrokes to LIRIANO, such as the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 70 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”). LIRIANO then used those stolen usernames and passwords to log in to the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for sexually explicit photographs and videos in the Compromised Accounts. LIRIANO’s computer intrusions into Hospital-1’s computer networks caused over $350,000 in losses to Hospital-1. * * * LIRIANO, 33, of the Bronx, New York, was arrested on November 14, 2019. LIRIANO pled guilty today to one count of transmitting a program to a protected computer that intentionally caused damage, which carries a maximum sentence of 10 years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. LIRIANO is scheduled to be sentenced by U.S. District Judge Lewis A. Kaplan on April 15, 2020, at 3:00 p.m. Mr. Berman praised the investigative work of the Federal Bureau of Investigation and thanked the New York City Police Department for its assistance. This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution. Contact Jim Margolin, Nicholas Biase (212) 637-2600 Updated December 20, 2019 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 19-443
Press Release Former Employee Of Hospital Pleads Guilty To Compromising Dozens Of Hospital Computers And Coworkers’ Email Accounts And Stealing Their Confidential Information Friday, December 20, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that RICHARD LIRIANO pled guilty today to one count of computer fraud in connection with his scheme to use malicious software programs, including a program known as a “keylogger,” on dozens of his coworkers’ computers at a New York City-area hospital, secretly obtaining user names and passwords to his victims’ personal email and other accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and accessed their sensitive personal photographs, videos, and other private documents. LIRIANO pled guilty earlier today in Manhattan federal court before United States Magistrate Judge Kevin N. Fox. U.S. Attorney Geoffrey S. Berman said: “To feed his voyeuristic curiosity, Richard Liriano, an information technology professional at a New York hospital, installed a “keylogger” on dozens of his coworkers’ computers and used other unauthorized software to spy on and steal personal information from them. Liriano’s disturbing crimes not only invaded the privacy of his coworkers; he also intruded into computers housing vital healthcare and patient information, costing his former employer hundreds of thousands of dollars to remediate. He will now be held accountable for his actions.” According to the allegations in the Information to which LIRIANO pled guilty, a prior Indictment filed against LIRIANO, as well as statements made during the plea and other proceedings in the case: From at least in or about 2013, up to and including at least in or about 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records and personal photographs, onto his own workspace computer for his own personal use. To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, without authorization, used various malicious programs to steal the user names and passwords of his primarily female co-workers. One of these programs was known as a keylogger, which recorded and sent victim employees’ keystrokes to LIRIANO, such as the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 70 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”). LIRIANO then used those stolen usernames and passwords to log in to the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for sexually explicit photographs and videos in the Compromised Accounts. LIRIANO’s computer intrusions into Hospital-1’s computer networks caused over $350,000 in losses to Hospital-1. * * * LIRIANO, 33, of the Bronx, New York, was arrested on November 14, 2019. LIRIANO pled guilty today to one count of transmitting a program to a protected computer that intentionally caused damage, which carries a maximum sentence of 10 years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. LIRIANO is scheduled to be sentenced by U.S. District Judge Lewis A. Kaplan on April 15, 2020, at 3:00 p.m. Mr. Berman praised the investigative work of the Federal Bureau of Investigation and thanked the New York City Police Department for its assistance. This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution. Contact Jim Margolin, Nicholas Biase (212) 637-2600 Updated December 20, 2019 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 19-443