quick case study for the cybersec folks here. got this real story in my dpo class & wanted ur thoughts.
IT guy at a bank, last day of his notice period. a trainee saw him puttin some CD-ROMs in his bag & told security. they checked him at the exit and found a full export of the bank’s top clients on the discs. guy got fired for gross misconduct & a police complaint was filed.
any red flags or stuff that stands out to u technicaly or otherwise ? i have my own ideas on this cas but curious what u guys think first?
thx 😎
Trainees shouldn’t be able to access the “top clients” anyway.
The IT guy wasn’t a trainee; the trainee is the one who noticed him.
Some operational security questions: What’s this trainee doing? Why was it a trainee noticing things being put in backpacks? Why was the trainee the one notifying security?
Are there protocols in place for media being brought in or out of the facility and its workstations? Why or why not? Was the trainee the only one who reviewed them recently enough to notice a breach and alert?
But most importantly and at any rate you don’t do the grand heist on the last day. Rookie move.
First draft Raiden from Mortal Kombat looking dude.
Came here to say this exact thing hahahahahaha!
Why did the bank have CD Roms/writers? Secure institutions computers from those devices, locked cases and physically secured ports. Network alarms triggered if anything gets inserted.
Edit: also alarms and logs of anyone who accesses large volumes of data, let alone copies.
why cd’s? less digital footprint? burnin a disc feels more ‘mechanical’ — maybe it leaves nothing on the host side compared to mounting a usb mass storage? is it off the grid coz its physical legacy tech and modern dlp/edr just ignore it? anyone ever seen optical media used as a stealth exfiltration vector like this?
it was probably a long time ago



