Search This Blog

Showing posts with label DOJ. Show all posts
Showing posts with label DOJ. Show all posts

Saturday, April 15, 2017

5 Eastern European Immigrants Plead Guilty to Credit Card Fraud and Identity Theft Charges Related to Cyberattacks on 3 U.S. Companies

Department of Justice
U.S. Attorney’s Office
Central District of California

FOR IMMEDIATE RELEASE
Tuesday, April 11, 2017

5 Eastern European Immigrants Plead Guilty to Credit Card Fraud and Identity Theft Charges Related to Cyberattacks on 3 U.S. Companies

          LOS ANGELES – The fifth and final defendant charged with using credit and debit cards obtained from a series of cyberattacks on U.S. companies that resulted in an estimated $5 million in losses – and caused one victim company to go out of business – has pleaded guilty to federal fraud charges.
          Irina Fedoseeva, 33, a Russian national who resides in the Koreatown District of Los Angeles, pleaded guilty yesterday afternoon to conspiracy to use unauthorized credit and debit cards and admitted causing more than $225,000 in losses.
          In a plea agreement filed in United States District Court, Fedoseeva admitted to helping make fraudulent purchases with debit cards obtained as a result of cyberattacks on two healthcare administrators in December 2015 and February 2016.
          After helping a co-defendant make unauthorized purchases from retail stores that included Apple and Best Buy, Fedoseeva resold the merchandise on the internet.
          Four other defendants previously pleaded guilty to federal fraud charges for their roles in the computer attacks.
          Timur Safin, 29, of Burbank; Dmitry Fedoseev, 34, of Koreatown; and Kristina Gerasimova, 22, of the Miracle Mile District of Los Angeles, all of whom are Russian nationals, each pleaded guilty on March 20 to aggravated identity theft and debit/credit card fraud.
          The fifth defendant charged as a result of this investigation – Siarhei Patapau, 26, of the Miracle Mile District of Los Angeles, a native of Belarus – pleaded guilty on March 6 to similar felony charges.
          All five defendants pleaded guilty before United States District Judge Stephen V. Wilson, who is scheduled to sentence the defendants during hearings scheduled in June and September.
          According to court documents filed in two separate cases, the five defendants conspired with computer hackers, some of whom are believed to be in Russia. The hackers staged attacks that included:
  • a July 2014 intrusion into an airline’s computer system in which the hackers funded pre-paid credit cards in the amount of $900,000;
  • a December 2015 hack into the system of a healthcare administrator that allowed the cybercriminals to reactivate a dormant dependent care account and order the production of numerous debit cards that were used to make approximately $550,000 in fraudulent purchases; and
  • a February 2016 attack on another healthcare administrator that allowed the intruders to order the production of debit cards linked to reactivated accounts that were used to make approximately $3.5 million in fraudulent purchases.
          The computer hackers directed the pilfered debit and credit cards to be sent to the five defendants charged in Los Angeles and other co-conspirators. Members of the conspiracy then used the unauthorized cards to make cash withdrawals, purchase money orders and make purchases at retail outlets such as Apple, Best Buy, Home Depot and Target.
          For example, Safin admitted in court that he used a number of the pre-paid credit cards to withdraw approximately $5,074 at ATMs throughout Los Angeles County and to purchase money orders totaling $19,420. He used debit cards obtained from the healthcare administrators to make at least $225,000 in fraudulent purchases.
          When they were arrested last year, Fedoseev was in the possession of more than 519 unauthorized credit, debit and gift cards, and Patapau was found with approximately 525 credit and debit cards in other people’s names.
          As a result of their guilty pleas, Patapau, Safin and Fedoseev each face a statutory maximum sentence of 12 years in federal prison when they are sentenced by Judge Wilson. Gerasimova faces a statutory maximum sentence of seven years, and Fedoseeva faces a statutory maximum sentence of five years.
          The investigation that led to the two cases filed in Los Angeles was conducted by the Federal Bureau of Investigation.
          The two criminal cases are being prosecuted by Assistant United States Attorneys Bryant Yang and Eric Tung of the General Crimes Section.

Friday, April 14, 2017

Justice Department Announces Actions to Dismantle Kelihos Botnet

Department of Justice
Office of Public Affairs

FOR IMMEDIATE RELEASE
Monday, April 10, 2017

Justice Department Announces Actions to Dismantle Kelihos Botnet

The Justice Department today announced an extensive effort to disrupt and dismantle the Kelihos botnet – a global network of tens of thousands of infected computers under the control of a cybercriminal that was used to facilitate malicious activities including harvesting login credentials, distributing hundreds of millions of spam e-mails, and installing ransomware and other malicious software. 
Acting Assistant Attorney General Kenneth A. Blanco of the Justice Department’s Criminal Division, Acting U.S. Attorney Bryan Schroder for the District of Alaska, Assistant Director Scott Smith for the FBI’s Cyber Division and FBI Special Agent in Charge Marlin Ritzman of the AnchorageDivision made the announcement.
“The operation announced today targeted an ongoing international scheme that was distributing hundreds of millions of fraudulent e-mails per year, intercepting the credentials to online and financial accounts belonging to thousands of Americans, and spreading ransomware throughout our networks.   The ability of botnets like Kelihos to be weaponized quickly for vast and varied types of harms is a dangerous and deep threat to all Americans, driving at the core of how we communicate, network, earn a living, and live our everyday lives,” said Acting Assistant Attorney General Blanco.  “Our success in disrupting the Kelihos botnet was the result of strong cooperation between private industry experts and law enforcement, and the use of innovative legal and technical tactics. The Department of Justice is committed to combatting cybercrime, no matter the size or sophistication of the scheme, and to punish those who are engaged in such crimes.”
“Cybercrime is a worldwide problem, but one that infects its victims directly through the computers and personal electronic devices that we use every day,” said Acting U.S. Attorney Bryan Schroder for the District of Alaska.  “Protecting the American people from such a worldwide threat requires a broad-reaching response, and the dismantling of the Kelihos botnet was such an operation.  We are lucky that we have talented FBI agents and federal prosecutors with the skillsets to help protect Americans from this pervasive cybercrime.”
“On April 8, 2017, we started the extraordinary task of blocking malicious domains associated with the Khelios botnet to prohibit further infections,” said FBI Special Agent in Charge Ritzman. “This case demonstrates the FBI’s commitment to finding and eradicating cyber threats no matter where they are in the world.”
Kelihos malware targeted computers running the Microsoft Windows operating system.  Infected computers became part of a network of compromised computers known as a botnet and were controlled remotely through a decentralized command and control system.  According to the civil complaint, Peter Yuryevich Levashov allegedly operated the Kelihos botnet since approximately 2010.  The Kelihos malware harvested user credentials by searching infected computers for usernames and passwords and by intercepting network traffic.  Levashov allegedly used the information gained from this credential harvesting operation to further his illegal spamming operation which he advertised on various online criminal forums.  The Kelihos botnet generated and distributed enormous volumes of unsolicited spam e-mails advertising counterfeit drugs, deceptively promoting stocks in order to fraudulently increase their price (so-called “pump-and-dump” stock fraud schemes), work-at-home scams, and other frauds.  Kelihos was also responsible for directly installing additional malware onto victims’ computers, including ransomware and malware that intercepts users’ bank account passwords.
            
As with other botnets, Kelihos is designed to operate automatically and undetected on victims’ computers, with the malicious code secretly sending requests for instructions to the botnet operator. In order to liberate the victim computers from the botnet, the United States obtained civil and criminal court orders in the District of Alaska.  These orders authorized measures to neutralize the Kelihos botnet by (1) establishing substitute servers that receive the automated requests for instructions so that infected computers no longer communicate with the criminal operator and (2) blocking any commands sent from the criminal operator attempting to regain control of the infected computers.
In seeking authorization to disrupt and dismantle the Kelihos botnet, law enforcement obtained a warrant pursuant to recent amendments to Rule 41 of the Federal Rules of Criminal Procedure.  A copy of this warrant along with the other court orders are produced below.   The warrant obtained by the government authorizes law enforcement to redirect Kelihos-infected computers to a substitute server and to record the Internet Protocol addresses of those computers as they connect to the server.  This will enable the government to provide the IP addresses of Kelihos victims to those who can assist with removing the Kelihos malware including internet service providers.  
The efforts to disrupt and dismantle the Kelihos botnet were led by the FBI’s Anchorage Office and New Haven Office; Senior Counsel Ethan Arenson and Harold Chun, and Trial Attorney Frank Lin of the Computer Crime and Intellectual Property Section; and Assistant U.S. Attorneys Yvonne Lamoureux and Adam Alexander of the District of Alaska.  Critical assistance was also provided by foreign partners, and invaluable technical assistance was provided by Crowd Strike and The Shadow server Foundation in executing this operation.
The details contained in the civil complaint and related pleadings are merely accusations, and the defendant is presumed innocent unless and until proven guilty.
The Government has and will continue to share samples of the Kelihos malware with the internet security community so that antivirus vendors can update their programs to detect and remove Kelihos.  A number of free and paid antivirus programs are already capable of detecting and removing Kelihos, including the Microsoft Safety Scanner(link is external), a free product.
The documents filed by the Government as well as the court orders entered in this case are available online at the following web address:

Wednesday, April 5, 2017

Former El Paso-Based Company Employee Pleads Guilty to Computer Intrusion

Department of Justice
U.S. Attorney’s Office
Western District of Texas

FOR IMMEDIATE RELEASE
Thursday, March 30, 2017

Former El Paso-Based Company Employee Pleads Guilty to Computer Intrusion

In El Paso, 41-year-old Joe Vito Venzor faces up to ten years in federal prison after admitting today to illegally accessing his former employer’s computer system and shutting it down announced United States Attorney Richard L. Durbin, Jr., and Federal Bureau of Investigation Special Agent in Charge Douglas E. Lindquist, El Paso Division.

Appearing before Senior United States District Judge David Briones, Venzor pleaded guilty to one count of transmission of a program to cause damage to a computer. By pleading guilty, Venzor admitted that on September 1, 2016, after being terminated from his position at the company’s help desk, he logged onto the company’s network through an administrator account and shut down the company’s email server and application server while deleting systems files essential to restoring computer operations.

Because of the intrusion, 300 employees in the production and shipping factory were unable to work for nearly three hours before the decision was made to send them home for the rest of the shift. The distribution center was not able to ship any of their products and customers could not place orders online. The IT Managing Director also had to hire a third party IT staff to assist with setting up a new application server for the company. The company continued to suffer direct and indirect losses because of the intrusion into its computer server in the ensuing days and weeks, as they had to reconstruct files, and fulfill production and customer services issues.

Venzor remains on bond pending sentencing scheduled for 9:30am on June 6, 2017, before Judge Briones in El Paso. In addition to the prison term, Venzor is also subject to a fine of up to $250,000 and restitution to his former employer, which has yet to be determined.

The Federal Bureau of Investigation investigated this case. Assistant United States Attorneys Greg McDonald and Rifian Newaz are prosecuting this case on behalf of the Government.

Monday, April 3, 2017

Boerne Man Admits Hacking into Former Employer’s Computer System and Shutting it Down

Department of Justice
U.S. Attorney’s Office
Western District of Texas

FOR IMMEDIATE RELEASE
Wednesday, March 29, 2017

Boerne Man Admits Hacking into Former Employer’s Computer System and Shutting it Down

In San Antonio, 40-year-old Brian Neal Bond of Boerne, TX, faces up to five years in federal prison after admitting to hacking into a local business and shutting down their computer operations announced United States Attorney Richard L. Durbin, Jr., and FBI Special Agent in Charge Christopher Combs, San Antonio Division.

Appearing before United States District Judge Xavier Rodriguez, Bond pleaded guilty to one count of computer intrusion and damage. According to court records, from September 2010 to approximately April 2015, Bond worked as an Information Technology Help Desk manager in the Boerne, TX, facility of Colorado-based business. Bond left that company’s employment to accept a position with a different company. By pleading guilty, Bond admitted that beginning in June 2015 and continuing to January 2016, Bond, without authorization, accessed his former employer’s computers approximately 124 times. On one of those occasions—January 12, 2016—Bond admitted to shutting down his former employer’s trading system, making it unavailable to customers. Bond also deleted a file that was essential to the trading systems ability to operate. Bond’s interruption actions resulted in an estimated loss to his former employer of $10,816, which Bond has already paid into the registry of the Court.

The defendant remains out on bond pending sentencing scheduled for June 28, 2017, before Judge Rodriguez.

The Federal Bureau of Investigation conducted this investigation. Assistant United States Attorney William R. Harris is prosecuting this case on behalf of the Government.

Sunday, April 2, 2017

Romanian Man Pleads Guilty To Participating In International Fraud Scheme Involving Online Marketplace Websites

Department of Justice
U.S. Attorney’s Office
Middle District of Tennessee

FOR IMMEDIATE RELEASE
Tuesday, March 28, 2017

Romanian Man Pleads Guilty To Participating In International Fraud Scheme Involving Online Marketplace Websites

Vlad Diaconu, 36, of Bucharest, Romania, pleaded guilty today in U.S. District Court in Nashville, to one count of conspiracy to commit bank and wire fraud, announced Acting U.S. Attorney Jack Smith of the Middle District of Tennessee and Acting Assistant Attorney General Kenneth A. Blanco of the Justice Department’s Criminal Division. Diaconu pleaded guilty for his participation in an international scheme involving fraudulent advertisments on online marketplaces that induced victims to send approximately $873,000 to conspirators for the purchase of various items that were not actually available for purchase.
Diaconu was indicted in the Middle District of Tennessee in June 2015 for conspiracy to commit bank and wire fraud in connection with his participation in the online marketplace scheme. Diaconu was extradited from Romania to the Middle District of Tennessee in August 2016.
In connection with his guilty plea, Diaconu admitted that his co-conspirators fraudulently listed vehicles for sale at online marketplaces such as eBay. When victims expressed interest in purchasing the vehicles, the co-conspirators responded with emails directing the victims to wire payments to specified bank accounts. These bank accounts were opened by members of the conspiracy, including Diaconu, who used false identities and fraudulent documents, including counterfeit passports. Specifically, twelve victims sent a total of $184,900 to accounts that were opened by Diaconu under the belief that they were purchasing the advertised vehicles, and other victims sent additional funds to bank accounts opened by co-conspirators. Diaconu and his co-conspirators subsequently sent the bulk of the victims’ funds to co-conspirators located overseas.
The FBI and the Tennessee Bureau of Investigation investigated the case. Assistant U.S. Attorney Byron M. Jones of the Middle District of Tennessee and Senior Counsel Mysti Degani of the Criminal Division’s Computer Crime and Intellectual Property Section and prosecuted the case. The Criminal Division’s Office of International Affairs also provided substantial assistance.

Russian Citizen Pleads Guilty For Involvement In Global Botnet Conspiracy

Department of Justice
U.S. Attorney’s Office
District of Minnesota

FOR IMMEDIATE RELEASE
Tuesday, March 28, 2017

Russian Citizen Pleads Guilty For Involvement In Global Botnet Conspiracy

WASHINGTON – A Russian citizen pleaded guilty today for his participation in a criminal enterprise that installed and exploited malicious computer software (malware) on tens of thousands of computer servers throughout the world to generate millions of dollars in fraudulent payments.

Acting Assistant Attorney General Kenneth A. Blanco of the Department of Justice’s Criminal Division, Acting U.S. Attorney Gregory G. Brooker of the District of Minnesota and Assistant Director Scott Smith of the FBI’s Cyber Division made the announcement.

MAXIM SENAKH, 41, of Velikii Novgorod, Russia, pleaded guilty today to conspiracy to violate the Computer Fraud and Abuse Act and to commit wire fraud before U.S. District Judge Patrick J. Schlitz of the District of Minnesota. Sentencing is set for August 3, 2017. SENAKH was indicted on January 13, 2015, and was subsequently arrested by Finnish authorities, who extradited him to the United States.

According to admissions made in connection with the plea agreement, the malware, which is known as Ebury, harvested log-on credentials from infected computer servers, allowing SENAKH and his co-conspirators to create and operate a botnet comprising tens of thousands of infected servers throughout the world, including thousands in the United States. SENAKH and his co-conspirators used the Ebury botnet to generate and redirect internet traffic in furtherance of various click-fraud and spam e-mail schemes, which fraudulently generated millions of dollars in revenue. As part of the plea, SENAKH admitted that he supported the criminal enterprise by creating accounts with domain registrars which helped build the Ebury botnet infrastructure and personally profited from traffic generated by the Ebury botnet.

The FBI Minneapolis Field Office is investigating the case. Senior Counsels Aaron Cooper and Benjamin Fitzpatrick of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Kevin Ueland of the District of Minnesota are prosecuting this case. The Department of Justice extends its thanks to the government of Finland, the Bundeskriminalamt (BKA), CERT-Bund and the cyber security firm ESET. The Criminal Division’s Office of International Affairs also provided substantial assistance.


Defendant Information:

Maxim Senakh, 41
Velikii Novgorod, Russia

Convicted:
  • Conspiracy to Violate the Computer Fraud and Abuse Act, and to Commit Wire Fraud, 1 count


# # #

Friday, March 31, 2017

Owner Of Florida Telecommunications Company and His Co-Conspirator Sentenced to Prison for Involvement in International Cellphone Fraud Scheme

Department of Justice
Office of Public Affairs

FOR IMMEDIATE RELEASE
Monday, March 27, 2017

Owner Of Florida Telecommunications Company and His Co-Conspirator Sentenced to Prison for Involvement in International Cellphone Fraud Scheme

A federal court in West Palm Beach, Florida, today sentenced the owner and operator of a Florida-based telecommunications company to 75 months in prison and his co-conspirator, a resident of Bronx, New York to 36 months in prison in connection with a sophisticated global cellphone fraud scheme that involved compromising cellphone customers’ accounts and “cloning” their phones to make fraudulent international calls. 
Acting Assistant Attorney General Kenneth A. Blanco of the Justice Department’s Criminal Division, Acting U.S. Attorney Benjamin G. Greenberg of the Southern District of Florida and Special Agent in Charge George L. Piro of the FBI’s Miami Field Office made the announcement.  
Ramon Batista, 50, the owner and operator of Arymyx Inc., earlier pleaded guilty before Senior U.S. District Judge Daniel T.K. Hurley in the Southern District of Florida to one count of conspiracy to commit wire fraud; access device fraud; the use, production or possession of modified telecommunications instruments; and the use or possession of hardware or software configured to obtain telecommunications services, as well as one count of wire fraud and one count of aggravated identity theft.  Batista’s co-conspirator, Farintong Calderon, 38, pleaded guilty to the same count of conspiracy.  
According to the plea agreements, Batista, Calderon and their co-conspirators participated in a scheme to steal access to and fraudulently open new cellphone accounts using the personal information of individuals around the United States.  Batista and others also operated “call sites” in South Florida and elsewhere, where they would receive telecommunications identifying information associated with customers’ accounts from Calderon and additional co-conspirators, and use that data, as well as other software and hardware, to reprogram cellphones that they controlled.  Batista and other co-conspirators would then transmit thousands of international calls over the internet to the call sites, where Batista and others would route them through the re-programmed cellphones to Cuba, Jamaica, the Dominican Republic and other countries with high calling rates.  The calls were billed to the customers’ compromised accounts.
Batista admitted that his role in the scheme included selling fraudulent telecommunications services through Arymyx; acting as a  “call site operator” which involved maintaining and re-programming cellphones through which he routed phone calls as part of the fraud scheme; and using and providing other co-conspirators with stolen or compromised telecommunications identifying information that was then employed to reprogram cellphones.  Moreover, Batista admitted that he sent or received 1,132 “lines,” that is, combinations of telecommunications identifying numbers for specific devices or accounts associated with U.S. cellphone customers, and that the fraudulent use of these “lines” caused almost $800,000 in losses to Sprint and Verizon.  
In addition, Calderon admitted that he was a “line supplier” based in New York City, who provided stolen or compromised telecommunications identifying information to Batista and other co-conspirators in Florida and elsewhere.  Among other things, Calderon admitted that he sent or received about 1,408 “lines” and was personally responsible for more than $250,000 in losses resulting from the scheme. 
Batista and Calderon are the third and fourth defendants to be sentenced in the case by Senior Judge Hurley.  Edwin Fana was sentenced on Dec. 22, 2016, to 48 months in prison and Jose Santana was sentenced on Jan. 4, 2017, to 52 months in prison.
The FBI investigated the case, dubbed Operation Toll Free, which is part of the Bureau’s ongoing effort to combat large-scale telecommunications fraud.  Senior Counsel Matthew A. Lamberti of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Jared M. Strauss of the Southern District of Florida prosecuted the case. 

Saturday, March 25, 2017

Lithuanian Man Arrested For Theft Of Over $100 Million In Fraudulent Email Compromise Scheme Against Multinational Internet Companies

Department of Justice
U.S. Attorney’s Office
Southern District of New York

FOR IMMEDIATE RELEASE
Tuesday, March 21, 2017

Lithuanian Man Arrested For Theft Of Over $100 Million In Fraudulent Email Compromise Scheme Against Multinational Internet Companies

Joon H. Kim, the Acting United States Attorney for the Southern District of New York, and William F. Sweeney Jr., the Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced criminal charges against EVALDAS RIMASAUSKAS for orchestrating a fraudulent business email compromise scheme that induced two U.S.-based internet companies (the “Victim Companies”) to wire a total of over $100 million to bank accounts controlled by RIMASAUSKAS. RIMASAUSKAS was arrested late last week by authorities in Lithuania on the basis of a provisional arrest warrant.  The case has been assigned to U.S. District George B. Daniels. 
Acting U.S. Attorney Joon H. Kim said:  “From half a world away, Evaldas Rimasauskas allegedly targeted multinational internet companies and tricked their agents and employees into wiring over $100 million to overseas bank accounts under his control. This case should serve as a wake-up call to all companies – even the most sophisticated – that they too can be victims of phishing attacks by cyber criminals. And this arrest should serve as a warning to all cyber criminals that we will work to track them down, wherever they are, to hold them accountable. The charges and arrest in this case were made possible thanks to the terrific work of the FBI and the cooperation of the victim companies and their financial institutions. We thank the companies and their banks for acting quickly, coming forward promptly, and cooperating with law enforcement; it led not only to the charges announced today, but also the recovery of much of the stolen funds.
FBI Assistant Director William F. Sweeney Jr. said:  “As alleged, Evaldas Rimasauskas carried out a business email compromise scheme creatively targeting two very specific victim companies. He was initially successful, acquiring over $100 million in proceeds that he wired to various bank accounts worldwide. But his footprint would eventually lead investigators to the truth, and today we expose his lies. Criminals continue to commit a wide variety of crimes online, and significant cyber data breaches have had a negative impact across a variety of industries. The FBI will continue to work with our domestic and international partners to pursue criminals who engage in this type of activity, wherever they may be hiding.”
According to the allegations contained in the Indictment unsealed today[1]:
From at least in or around 2013 through in or about 2015, RIMASAUSKAS orchestrated a fraudulent scheme designed to deceive the Victim Companies, including a multinational technology company and a multinational online social media company, into wiring funds to bank accounts controlled by RIMASAUSKAS.  Specifically, RIMASAUSKAS registered and incorporated a company in Latvia (“Company-2”) which bore the same name as an Asian-based computer hardware manufacturer (“Company-1”), and opened, maintained, and controlled various accounts at banks located in Latvia and Cyprus in the name of Company-2.  Thereafter, fraudulent phishing emails were sent to employees and agents of the Victim Companies, which regularly conducted multimillion-dollar transactions with Company-1, directing that money the Victim Companies owed Company-1 for legitimate goods and services be sent to Company-2’s bank accounts in Latvia and Cyprus, which were controlled by RIMASAUSKAS.  These emails purported to be from employees and agents of Company-1, and were sent from email accounts that were designed to create the false appearance that they were sent by employees and agents of Company-1, but in truth and in fact, were neither sent nor authorized by Company-1.  This scheme succeeded in deceiving the Victim Companies into complying with the fraudulent wiring instructions.
After the Victim Companies wired funds intended for Company-1 to Company-2’s bank accounts in Latvia and Cyprus, RIMASAUSKAS caused the stolen funds to be quickly wired into different bank accounts in various locations throughout the world, including Latvia, Cyprus, Slovakia, Lithuania, Hungary, and Hong Kong.  RIMASAUSKAS also caused forged invoices, contracts, and letters that falsely appeared to have been executed and signed by executives and agents of the Victim Companies, and which bore false corporate stamps embossed with the Victim Companies’ names, to be submitted to banks in support of the large volume of funds that were fraudulently transmitted via wire transfer. 
Through these false and deceptive representations over the course of the scheme, RIMASAUSKAS, the defendant, caused the Victim Companies to transfer a total of over $100,000,000 in U.S. currency from the Victim Companies’ bank accounts to Company-2’s bank accounts.
*                *                *
RIMASAUSKAS, 48, of Vilnius, Lithuania, is charged with one count of wire fraud and three counts of money laundering, each of which carries a maximum sentence of 20 years in prison, and one count of aggravated identity theft, which carries a mandatory minimum sentence of two years in prison. 
The maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge. 
Mr. Kim praised the outstanding investigative work of the FBI, and thanked the Prosecutor General’s Office of the Republic of Lithuania, the Lithuanian Criminal Police Bureau, the Vilnius District Prosecutor’s Office and the Economic Crime Investigation Board of Vilnius County Police Headquarters for their assistance in the investigation and arrests, as well as the Department of Justice’s Office of International Affairs.
The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit.  Assistant U.S. Attorney Eun Young Choi is in charge of the prosecution.  Assistant U.S. Attorney Edward Diskant is handling the forfeiture aspects of the prosecution. 
The charges contained in the Indictment are merely accusations, and the defendant is presumed innocent unless and until proven guilty.
 
[1] As the introductory phrase signifies, the entirety of the text of the Indictment, and the description of the Indictment set forth herein, constitute only allegations, and every fact described should be treated as an allegation.

Tuesday, January 10, 2017

Operator Of Unlawful Bitcoin Exchange Pleads Guilty In Multimillion-Dollar Money Laundering And Fraud Scheme

Department of Justice
U.S. Attorney’s Office
Southern District of New York

FOR IMMEDIATE RELEASE
Monday, January 9, 2017

Operator Of Unlawful Bitcoin Exchange Pleads Guilty In Multimillion-Dollar Money Laundering And Fraud Scheme

Three Guilty Pleas to Date in Bitcoin and Bribery Scheme

Preet Bharara, the United States Attorney for the Southern District of New York, announced that ANTHONY R. MURGIO pled guilty today before U.S. District Judge Alison J. Nathan to charges associated with operating Coin.mx, an internet-based Bitcoin exchange, through which MURGIO processed more than $10 million in illegal Bitcoin transactions. MURGIO also pled guilty to conspiring to obstruct an examination of the Helping Other People Excel Federal Credit Union (“HOPE FCU”) by the National Credit Union Administration (“NCUA”) in furtherance of the illegal Coin.mx scheme. To date, three individuals involved in the Coin.mx schemes have pled guilty. MURGIO is scheduled to be sentenced by Judge Nathan on June 16, 2017.

U.S. Attorney Preet Bharara said: “Anthony Murgio took a new age approach to an age-old crime of fraud. As he admitted in his guilty plea today, Murgio used Coin.mx, an internet-based Bitcoin exchange, to process over $10 million in Bitcoin transactions in violation of federal anti-money laundering laws, and then obstructed a regulatory examination to hide his scheme.”

According to the allegations contained in the Superseding Indictment to which MURGIO pled guilty and statements made during the plea proceeding and other court proceedings:

The Unlawful Bitcoin Exchange

Between 2013 and July 2015, MURGIO knowingly operated Coin.mx, an unlawful internet-based Bitcoin exchange, in violation of federal anti-money laundering laws and regulations,including those requiring money services businesses like Coin.mx to meet state licensing and federal registration requirements set forth by the United States Treasury Department. MURGIO and his co-conspirators engaged in substantial efforts to evade detection of their unlawful Bitcoin exchange by operating through a phony front company called “Collectables Club.” MURGIO used Collectables Club to open bank accounts, through which Coin.mx operated, in order to trick financial institutions into believing the unlawful Bitcoin exchange was simply a members-only association of individuals who discussed, bought, and sold collectible items and memorabilia.

In addition to lying to banks to open accounts, MURGIO and his co-conspirators deceived financial institutions by deliberately misidentifying and miscoding Coin.mx customers’ credit and debit card transactions, in violation of bank and credit card company rules and regulations. MURGIO and his co-conspirators also instructed Coin.mx customers to mislead banks about the nature of the credit and debit card transactions the customers executed through Coin.mx. For example, MURGIO and his co-conspirators caused customers to falsely tell the banks that the transactions in which they engaged with Coin.mx were for collectibles items, when in reality they were for Bitcoins. Through the illegal Coin.mx scheme, MURGIO and his co-conspirators caused more than $10 million in Bitcoin-related transactions to be processed illegally through financial institutions.

The Federal Credit Union Scheme
In 2014, in an effort further to evade scrutiny from financial institutions about the nature of the business engaged in by Coin.mx, MURGIO and his co-conspirators gained control of HOPE FCU, a federal credit union in New Jersey with primarily low-income members. After making more than $150,000 in illegal bribes, MURGIO and his co-conspirators took control of HOPE FCU. MURGIO installed various co-conspirators on HOPE FCU’s Board of Directors and transferred Coin.mx’s banking operations to HOPE FCU.

In late 2014, MURGIO and his co-conspirators attempted to obstruct an examination of HOPE FCU by the NCUA in order to perpetuate MURGIO’s control of the credit union. In furtherance of this scheme, MURGIO and others caused numerous misrepresentations to be made to the NCUA, including misrepresentations about the headquarters of the Collectables Club, in an effort to convince the NCUA that the Coin.mx-affiliated board members were eligible to serve on HOPE FCU’s Board of Directors. HOPE FCU was operated as a captive bank by MURGIO and his co-conspirators until the end of 2014.

In October 2015, the NCUA placed HOPE FCU into conservatorship, and subsequently liquidation.

* * *

MURGIO, 33, of Tampa, Florida, pled guilty to one count of conspiracy to operate an unlicensed money transmitting business, which carries a maximum sentence of five years in prison; one count of conspiracy to commit bank fraud, which carries a maximum sentence of 30 years in prison; and one count of conspiracy to obstruct an examination of a financial institution, which carries a maximum sentence of five years in prison.

Two of MURGIO’s co-defendants have been convicted and are awaiting sentence. Jose M. Freundt pled guilty on October 13, 2016, to one count of conspiracy to operate an unlicensed money transmitting business, one count of operating an unlicensed money transmitting business, and one count of conspiracy to corruptly make payments to an officer of a financial institution, each of which carries a maximum sentence of five years in prison; and one count of corruptly making payments to an officer of a financial institution, one count of conspiracy to commit wire fraud, and one count of wire fraud, each of which carries a maximum sentence of 30 years in prison. Freundt is scheduled to be sentenced by Judge Nathan on April 13, 2017. Michael J. Murgio pled guilty on October 27, 2016, to one count of conspiracy to obstruct an examination of a financial institution, which carries a maximum sentence of five years in prison, and is scheduled to be sentenced by Judge Nathan on January 27, 2017.

The maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendants will be determined by the judge.

Trial for two additional co-defendants, Trevon Gross and Yuri Lebedev, is scheduled to begin on February 6, 2017. The description of the offense set forth in this release are merely allegations and Gross and Lebedev are innocent until proven guilty.

Mr. Bharara praised the outstanding investigative work of the FBI and the Secret Service. He also thanked the NCUA for its assistance with the investigation and prosecution.

The prosecution of this case is being overseen by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorneys Eun Young Choi, Daniel S. Noble, and Won S. Shin are in charge of the prosecution.

Tuesday, September 6, 2016

Florida Computer Programmer Arrested For Hacking

Department of Justice
U.S. Attorney’s Office
Northern District of California

FOR IMMEDIATE RELEASE
Thursday, September 1, 2016

Florida Computer Programmer Arrested For Hacking

SAN FRANCISCO – A South Florida-based computer programmer made an appearance in the Southern District of Florida today after being arrested Sunday on charges of hacking into computers operated by the Linux Kernel Organization and the Linux Foundation, announced United States Attorney Brian J. Stretch and Federal Bureau of Investigation Special Agent in Charge John F. Bennett.
The Linux Kernel Organization operates the www.kernel.org[external link] website from which it distributes the Linux kernel software. The Linux Foundation is a separate nonprofit foundation that supports thewww.kernel.org[external link] website.
Donald Ryan Austin, 27, of El Portal, Fla., was arrested during a traffic stop on August 28, 2016, by officers of the Miami Shores Police Department. Austin was arrested pursuant to a four-count indictment returned by a federal grand jury in the Northern District of California on June 23, 2016, and unsealed Tuesday.
Austin is charged with causing damage to four servers located in the Bay Area by installing malicious software. Specifically, he is alleged to have gained unauthorized access to the four servers by using the credentials of an individual associated with the Linux Kernel Organization. According to the indictment, Austin used that access to install rootkit and trojan software, as well as to make other changes to the servers.  Austin is charged with four counts of intentional transmission causing damage to a protected computer, in violation of 18 U.S.C. § 1030(a)(5)(A).
Austin made his initial appearance in federal court in Miami, Fla., on August 29, 2016. He was released on bond today. Bail was set at $50,000.  Austin’s next scheduled appearance is in San Francisco at 9:30 a.m. on September 21, 2016, before the Honorable Sallie Kim, United States Magistrate Judge.        
An indictment merely alleges that crimes have been committed, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt. If convicted, the defendant faces a maximum sentence of ten years of imprisonment, and a fine of $250,000, plus restitution, for each violation of 18 U.S.C. § 1030(a)(5)(A).  However, any sentence following conviction would be imposed by the court after consideration of the U.S. Sentencing Guidelines and the federal statute governing the imposition of a sentence, 18 U.S.C. § 3553. 
The prosecution is the result of an investigation by the Federal Bureau of Investigation.

Monday, September 5, 2016

Miami Student Sentenced for Cyberstalking on Facebook and Instagram

Department of Justice
U.S. Attorney’s Office
Southern District of Florida

FOR IMMEDIATE RELEASE
Wednesday, August 31, 2016

Miami Student Sentenced for Cyberstalking on Facebook and Instagram

A Miami student was sentenced yesterday for cyberstalking on Facebook and Instagram. 
Wifredo A. Ferrer, United States Attorney for the Southern District of Florida, and George L. Piro, Special Agent in Charge, Federal Bureau of Investigation (FBI), Miami Field Office, made the announcement. 
Kassandra Cruz, 23, of Miami, Florida, was sentenced by U.S. District Judge Frederico A. Moreno to 22 months in prison, followed by three years of supervised release, a $100 special assessment, and $2,178.32 in restitution, stemming from her conviction on one count of cyberstalking, in violation of Title 18, United States Code, Section 2261(A)(2)(B).
According to court documents, beginning in June 2015, victim “S.B.” received a “friend” request from Cruz on her Instagram and Facebook accounts.  In an effort to gain “S.B.’s” friendship, Cruz created a false persona on her Instagram account wherein she portrayed herself as a male who was an active duty U.S. Marine.  Under that ruse, “S.B.” accepted the friend request.
From late June 2015 until September 2015, Cruz, posing as Giovanni, “liked” and commented on pictures “S.B.” posted on both her Instagram and Facebook accounts.  However, when “S.B.” noticed that Cruz had begun “following” and “liking” all of her friends pages and posts, she became suspicious and “blocked” and “unfollowed” Cruz from her social media accounts.
As a result, Cruz threatened that “S.B.” would face repercussions at her job and with her family if she did not comply, and specifically threatened to expose “S.B.’s” past via social media.  The threats to “S.B.” persisted from Cruz on social media and later via text messaging, and Cruz ultimately demanded on multiple occasions $100,000 in exchange for no further contact, adding that she “knew where “S.B.’s family lived and they should watch their backs because someone would be heading to…to deal with them.”  In total, “S.B.” received over 900 unwanted calls and text messages since the beginning of 2016, and the extortionate and threatening messages continued until late April 2016.  Ultimately, Cruz was arrested and taken into custody during a pre-arranged meeting in Miami.
Mr. Ferrer commended the investigative efforts of the FBI.  This case is being prosecuted by Assistant U.S. Attorneys Jodi L. Anton and Francis Viamontes.
Related court documents and information may be found on the website of the District Court for the Southern District of Florida at www.flsd.uscourts.gov or on http://pacer.flsd.uscourts.gov.

District Man Found Guilty of Sexually Abusing 11-Year-Old Girl

Department of Justice
U.S. Attorney’s Office
District of Columbia

FOR IMMEDIATE RELEASE
Tuesday, August 30, 2016

District Man Found Guilty of Sexually Abusing 11-Year-Old Girl

Defendant Met the Child Through Instagram

     WASHINGTON - Robert Kelsey, 28, of Washington, D.C., has been found guilty of sexually abusing an 11-year-old girl he met through Instagram when he was 26 years old, U.S. Attorney Channing D. Phillips, Paul M. Abbate, Assistant Director in Charge of the FBI’s Washington Field Office, and Cathy L. Lanier, Chief of the Metropolitan Police Department (MPD), announced today.
     Kelsey was found guilty by a jury on Aug. 29, 2016, following a trial in the U.S. District Court for the District of Columbia, of transportation of a minor with intent to engage in criminal sexual activity, aggravated sexual abuse of a child, and first-degree child sexual abuse with aggravating circumstances. The Honorable Reggie B. Walton scheduled sentencing for Nov. 18, 2016. Kelsey, a convicted felon, faces a potential sentence of up to life in prison without the possibility of release, and a mandatory minimum sentence of 30 years in prison.
     According to the government’s evidence, Kelsey met the girl during the summer of 2014 on Instagram, concealing his true identity, posing as a 19-year-old and using a fictitious name.  He suggested that they begin communicating by text via Kik Messenger.  He flirted with her and told her that he wanted to have sex with her.  On July 25, 2014, Kelsey arranged to pick up the girl from her summer camp, which was held at an elementary school in Bowie, Md.  He told the camp staff that he was the child’s cousin so that he could take her from camp early that day.
     Kelsey drove the victim to his house in Washington, D.C., where he sexually abused her, and then returned her to the vicinity of the camp. By that time, the victim’s father, who was at the camp to pick up his daughter, learned that she had been taken from the camp by a man, and the father summoned police.  The victim disclosed what happened and Prince George’s County, Md. Police began an investigation.  The case was referred to the Metropolitan Police Department, and an investigation by MPD and the FBI’s Child Exploitation Task Force led to Kelsey’s arrest.  DNA analysis of evidence obtained from a medical examination of the victim also linked Kelsey to the crime.
     This case was brought as part of the Department of Justice's Project Safe Childhood initiative and investigated by the FBI's Child Exploitation Task Force, which includes members of the FBI's Washington Field Office and MPD.  In February 2006, the Attorney General created Project Safe Childhood, a nationwide initiative designed to protect children from online exploitation and abuse.  Led by the U.S. Attorney's Offices, Project Safe Childhood marshals federal, state, and local resources to better locate, apprehend, and prosecute individuals who exploit children via the Internet, as well as identify and rescue victims.  For more information about Project Safe Childhood, please visit www.projectsafechildhood.gov[external link]
     In announcing the verdict, U.S. Attorney Phillips, Assistant Director in Charge Abbate, and Chief Lanier commended the work of those who investigated the case from the FBI's Child Exploitation Task Force, which includes members of the FBI's Washington Field Office and MPD’s Youth Investigations Division.  They also expressed appreciation for the assistance provided by the Prince George’s County, Md. Police Department.  They acknowledged the efforts of those who worked on the case from the U.S. Attorney’s Office, including Michael Ambrosino, Special Counsel for DNA and Forensic Evidence LitigationElizabeth Trosman, Chief of the Appellate Division; Assistant U.S. Attorney Sharon Donovan; Victim/Witness Advocate Lezlie Richardson; Paralegal Specialists Joyce Arthur, Troy Griffith, and Tiffany Jones; Litigation Technology Specialists Aneela Bhatia and Anisha Bhatia, and Intern Wendy Acquazzino. Finally, they commended the work of Assistant U.S. Attorneys Andrea L. Hertzfeld and Kenya Davis, who prosecuted the case.

Trainer Man Charged With Internet Stalking

Department of Justice
U.S. Attorney’s Office
Eastern District of Pennsylvania

FOR IMMEDIATE RELEASE
Tuesday, August 30, 2016

Trainer Man Charged With Internet Stalking

Matthew Handy, 24, of Trainer, PA, was charged today by indictment with stalking another person via the Internet, announced United States Attorney Zane David Memeger. Handy is charged with cyberstalking, two counts of interstate use of telecommunications device to willfully convey a threat, and two counts of false statements.
According to the indictment, Handy was involved in a romantic relationship with the victim that ended on January 17, 2014.  From that date until February 24, 2014, Handy allegedly sent anonymous electronic mail messages to law enforcement agencies falsely claiming that the victim was engaging in child exploitation and molestation, was using drugs, was building pipe bombs, and a family member was supplying fertilizer and metal pipes to make the explosives, and the victim intended to use the explosives, all of which he knew was false. For example, on February 10, 2014, Handy allegedly sent an anonymous email to the Atlantic County (NJ) Prosecutor’s Office “Crime Stoppers” website claiming the victim and another individual intended to attack a middle school in New Jersey with guns and a pipe bomb on the morning of February 10, 2014, which he knew was false.  As a result of the threat, the school of 393 students and 58 faculty had to be evacuated while the school was searched by the New Jersey State Police’s K-9 Unit and Bomb Squad.  On February 9, 2014, Handy allegedly sent an anonymous email to the Department of Homeland Security alleging that the victim and the victim’s immediate family were obtaining materials to make explosives, one of the family members was supplying the bomb making materials, and that the victim was going to use the explosives against individuals, all of which he knew was false.
On January 28, 2014, Handy allegedly sent an anonymous email to the Department of Homeland Security alleging that the victim was selling drugs and explosives to people, threatened to use explosives at undisclosed locations, kept explosives somewhere in Atlantic City, New Jersey, and threatened to use an explosive at an unidentified mall in New Jersey, which Handy knew was false.  On January 27, 2014, Handy allegedly sent an anonymous email to the New Jersey Office of Homeland Security and Preparedness stating that the victim intended to use explosive devices against the Salvation Army in Chester, Pennsylvania and the Chester (PA) Police Headquarters, which he knew was false. 
If convicted of all charges, Handy faces a possible advisory sentencing guideline range of 63 to 78 months in prison with a statutory maximum 38 years, a $500 special assessment and up to three years of supervised release.  He could also be ordered to pay restitution to the victim for any physical, psychiatric or psychological care, and possible fines.
The case was investigated by Homeland Security Investigations (HSI), New Jersey State Police, and the FBI.  It is being prosecuted by Assistant United States Attorney Anita Eve.                                                                                                   
An Indictment is an accusation.  A defendant is presumed innocent unless and until proven guilty.