An astonishing case came to light this week in which an employee of a US-critical infrastructure company managed to outsource his entire job to China for a period of at least six months. All the while, the unnamed computer programmer received “excellent remarks” in his performance reviews, which noted him as “the best developer in the building”.
The scam was discovered when the company noticed some unusual activity in their Virtual Private Network (VPN) logs. One VPN allowed their workers to work securely from home when required, requiring a two-stage authentication process. While the VPN should have been restricted to employees’ homes, bosses found that it harboured an open-ended connection to Shenyang in China. Experts from security firm Verizon were called in to investigate and initially they, too, were perplexed, fearing a major security breach. After toying with various bits of convoluted data, they discovered hundreds of invoices on his computer from a third-party developer in – you guessed it – Shenyang, China.
Essentially, the employee had subcontracted his workload out, allowing him to spend his “business” days surfing the internet. He circumvented security by simply FedExing authentication details to his “shadow” in China, to whom he paid around $50,000 a year in fees. The employee himself, meanwhile, trousered several hundred thousand pounds in wages. It later transpired that he was using the same scheme across multiple companies in the area. The employee was promptly fired.
There are several lessons to be taken from this incredible story:
- Verizon points out that proactive log reviews and internal audits happen very rarely – and if the company had not requested one, he would never have been found out; therefore management should always keep a keen eye on what exactly is occurring via their computer networks, as the most unlikely goings-on can never be ruled out.
- However, the story does also suggest that the company was not operating efficiently. After all, if someone in China was completing the work to such a high standard for much less money, perhaps they should have been the ones employed in the first place (although perhaps this criticism is unfair, seeing as it was a US-critical company).
- Perhaps instead of firing the employee, he should have been promoted? He clearly had a keen eye for maximising productivity and minimising effort, and therefore had a sharp business brain that could have been utilised higher up in the company. He would not have been the first maverick to do penance in this way: US government agencies have often recruited computer hackers that they have busted.
Whatever the conclusions, it is certainly a fascinating story