United States v. Assistant Director-in-Charge of the New York Office of the Fbi, et al.
raw: Former Employee Of Hospital Charged With Compromising Dozens Of Coworkers’ Email Accounts And Stealing Their Confidential Information
Former Employee Of Hospital Charged With Compromising Dozens Of Coworkers’ Email Accounts And Stealing Their Confidential Information (S.D.N.Y. Nov. 15, 2019)
Richard Liriano, a former IT employee at a New York City hospital, installed keylogging malware on dozens of coworkers' computers to steal login credentials and steal private photos, tax records, and confidential files from at least 30 email and online accounts, and now faces three federal charges including aggravated identity theft with a mandatory two-year consecutive sentence.
Richard Liriano, an IT employee at a New York City-area hospital, allegedly installed keyloggers on coworkers' computers between 2017 and September 2018 to steal usernames, passwords, and sensitive personal data, including tax records and private photographs. He compromised at least 30 email and online accounts—primarily belonging to female employees—and used the stolen credentials to access password-protected accounts for personal gain. Liriano is charged with transmitting a malicious program causing damage (max 10 years), unauthorized access causing reckless damage (max 5 years), and aggravated identity theft (mandatory 2-year consecutive sentence), with prosecution handled by the Southern District of New York’s Complex Frauds and Cybercrime Unit.
Richard Liriano, a 33-year-old IT employee at a New York City-area hospital, abused his administrative access to secretly install keylogging malware on dozens of coworkers' computers between 2017 and September 2018, capturing keystrokes to harvest usernames and passwords. Using these stolen credentials, he gained unauthorized access to at least 30 email, social media, and online accounts belonging to employees and their associates, conducting searches for and stealing private photographs, tax records, and other confidential documents for personal use, with a pattern of targeting primarily female employees. His actions also raised concerns about potential risks to patient data, as the compromised systems housed critical healthcare information. Liriano was arrested and arraigned in federal court, facing three charges: transmitting a malicious program causing damage (max 10 years), intentionally accessing a protected computer without authorization and recklessly causing damage (max 5 years), and aggravated identity theft (mandatory 2-year consecutive sentence). The case, prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit, underscores the dangers of insider threats in healthcare IT environments. Authorities emphasized that Liriano’s conduct was not motivated by financial gain but by personal intrusion, and the charges remain allegations pending trial. The FBI and NYPD collaborated on the investigation, with U.S. Attorney Geoffrey Berman warning that trusted IT professionals who exploit their access will be prosecuted.
Extracted insights
- agency assistant director-in-charge of the new york office of the fbi
- person Geoffrey S. Berman
- person richard liriano
- Richard Liriano was arrested for Installing malicious keylogger software on coworkers' computers and stealing confidential information
- Richard Liriano installed Keylogger program on dozens of coworkers' computers
- Richard Liriano stole Personal photographs, tax records, and confidential files from coworkers
- Richard Liriano obtained unauthorized access to Email, social media, and online accounts of victims
- Geoffrey S. Berman is United States Attorney for the Southern District of New York
- William F. Sweeney Jr. is Assistant Director-in-Charge of the New York Office of the FBI
- Richard Liriano was arraigned before United States Magistrate Judge Katharine H. Parker
- Richard Liriano worked as Information technology professional at a New York City-area hospital
- Richard Liriano misused Administrative access as IT employee from 2017 to September 28, 2018
- Richard Liriano copied Personal documents including tax records and photographs onto his workspace computer
- Indictment was unsealed on November 15, 2019 in Manhattan federal court
Press Release Former Employee Of Hospital Charged With Compromising Dozens Of Coworkers’ Email Accounts And Stealing Their Confidential Information Friday, November 15, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, and William F. Sweeney Jr., Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced the arrest of RICHARD LIRIANO for installing a malicious software program known as a “keylogger” on dozens of his coworkers’ computers at a New York City area hospital, obtaining unauthorized access to his victims’ email, social media and other online accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and pilfered their sensitive personal photographs and other private documents. LIRIANO was arrested yesterday and arraigned in federal court before United States Magistrate Judge Katharine H. Parker. U.S. Attorney Geoffrey S. Berman said: “Richard Liriano, an information technology professional at a New York hospital, is alleged to have installed a ‘keylogger’ program onto dozens of his coworkers’ computers in order to spy on and steal personal information from them. Liriano allegedly used the access he gained through the malicious software to steal photos, tax records, and other personal information from his coworkers and people associated with them. As information technology increasingly becomes an integral part of our workplaces, ensuring the integrity of those systems becomes even more critical. The arrest of Liriano should serve as an error message to any information technology professionals seeking to capitalize on their trusted access to information: As in this case, you will be caught and prosecuted.” FBI Assistant Director-in-Charge William F. Sweeney Jr. said: “Whatever alleged motivation the subject in this case had, hacking into his co-workers lives, albeit extremely disturbing, wasn't the most egregious act. He allegedly installed a harmful program on computers that house vital and critical healthcare information for hospital patients, without a thought to what he could be compromising in his attempts to spy on people.” According to the Indictment unsealed today in Manhattan federal court[1]: From at least in or about 2017, up to and including at least about in or about September 28, 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records, and personal photographs onto his own workspace computer for his own personal use. To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, without authorization, secretly installed a malicious program known as a keylogger on the accounts of other, primarily female, employees. This program recorded and sent victim employees’ keystrokes to LIRIANO, which included the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 30 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”). LIRIANO then used those stolen usernames and passwords to log in to the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for personal photographs in the Compromised Accounts. * * * LIRIANO, 33, of Bronx, New York, is charged in three counts. The first count charges him with transmitting a program to a protected computer that intentionally caused damage, which carries a maximum sentence of 10 years in prison. The second count charges him with intentionally accessing a protected computer without authorization and recklessly causing damage, which carries a maximum sentence of five years in prison. The third count is aggravated identity theft, which requires a two year prison term to be served consecutive to any sentence imposed on the computer intrusion charges. The maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. Mr. Berman praised the extraordinary work of the FBI and the New York City Police Department. This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution. The charges contained in the Indictment are merely accusations, and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Indictment, and the description of the Indictment set forth herein, constitute only allegations, and every fact described should be treated as an allegation. Contact James Margolin, Nicholas Biase (212) 637-2200 Updated November 15, 2019 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 19-379
Press Release Former Employee Of Hospital Charged With Compromising Dozens Of Coworkers’ Email Accounts And Stealing Their Confidential Information Friday, November 15, 2019 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, and William F. Sweeney Jr., Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced the arrest of RICHARD LIRIANO for installing a malicious software program known as a “keylogger” on dozens of his coworkers’ computers at a New York City area hospital, obtaining unauthorized access to his victims’ email, social media and other online accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and pilfered their sensitive personal photographs and other private documents. LIRIANO was arrested yesterday and arraigned in federal court before United States Magistrate Judge Katharine H. Parker. U.S. Attorney Geoffrey S. Berman said: “Richard Liriano, an information technology professional at a New York hospital, is alleged to have installed a ‘keylogger’ program onto dozens of his coworkers’ computers in order to spy on and steal personal information from them. Liriano allegedly used the access he gained through the malicious software to steal photos, tax records, and other personal information from his coworkers and people associated with them. As information technology increasingly becomes an integral part of our workplaces, ensuring the integrity of those systems becomes even more critical. The arrest of Liriano should serve as an error message to any information technology professionals seeking to capitalize on their trusted access to information: As in this case, you will be caught and prosecuted.” FBI Assistant Director-in-Charge William F. Sweeney Jr. said: “Whatever alleged motivation the subject in this case had, hacking into his co-workers lives, albeit extremely disturbing, wasn't the most egregious act. He allegedly installed a harmful program on computers that house vital and critical healthcare information for hospital patients, without a thought to what he could be compromising in his attempts to spy on people.” According to the Indictment unsealed today in Manhattan federal court[1]: From at least in or about 2017, up to and including at least about in or about September 28, 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records, and personal photographs onto his own workspace computer for his own personal use. To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, without authorization, secretly installed a malicious program known as a keylogger on the accounts of other, primarily female, employees. This program recorded and sent victim employees’ keystrokes to LIRIANO, which included the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 30 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”). LIRIANO then used those stolen usernames and passwords to log in to the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for personal photographs in the Compromised Accounts. * * * LIRIANO, 33, of Bronx, New York, is charged in three counts. The first count charges him with transmitting a program to a protected computer that intentionally caused damage, which carries a maximum sentence of 10 years in prison. The second count charges him with intentionally accessing a protected computer without authorization and recklessly causing damage, which carries a maximum sentence of five years in prison. The third count is aggravated identity theft, which requires a two year prison term to be served consecutive to any sentence imposed on the computer intrusion charges. The maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. Mr. Berman praised the extraordinary work of the FBI and the New York City Police Department. This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution. The charges contained in the Indictment are merely accusations, and the defendant is presumed innocent unless and until proven guilty. [1] As the introductory phrase signifies, the entirety of the text of the Indictment, and the description of the Indictment set forth herein, constitute only allegations, and every fact described should be treated as an allegation. Contact James Margolin, Nicholas Biase (212) 637-2200 Updated November 15, 2019 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 19-379