<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: kieber]]></title>
    <link>http://securityratty.com/tag/kieber</link>
    <description></description>
    <pubDate>Mon, 25 Feb 2008 11:03:19 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Cashing in on employee theft, or honest whistleblower?]]></title>
      <link>http://securityratty.com/article/6220385518c92bd41671151d57327dcd</link>
      <guid>http://securityratty.com/article/6220385518c92bd41671151d57327dcd</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/22/08

Organization
LGT Group - The Wealth and Asset Management Group of the Princely House of Liechtenstein
English Version
German Version
French...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/lgt.jpg" align="right" height="67" width="71"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/22/08<br><br><span style="font-weight: bold;">Organization: </span><br>LGT Group - The Wealth and Asset Management Group of the Princely House of Liechtenstein<br><a target="_blank" href="http://www.lgt.com/en/index.html">English Version</a> <br><a target="_blank" href="http://www.lgt.com/de/index.html">German Version</a> <br><a target="_blank" href="http://www.lgt.com/fr/index.html">French Version</a> <br><a target="_blank" href="http://www.lgt.com/it/index.html">Italian Version</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>LGT Treuhand AG<br>(LGT Trust Ltd in English)<br><br><span style="font-weight: bold;">Victims:</span><br>Clients of LGT Trust (prior to 2002)<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,400*<br><br><font size="1">*there may be an additional 4,527 beneficiaries affected.</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Confidential bank account information.<br><br><span style="font-weight: bold;">Breach Description:</span><br>Confidential customer information was stolen from LGT Trust in 2002 by a former employee of the company.&nbsp; As a result of this breach, Heinrich Kieber was convicted of "serious fraud, dangerous threats, unlawful compulsion, and suppression of documents."&nbsp; Now it appears that German authorities paid Mr. Kieber "as much as 5 million euros ($7.4 million)" for information about German account holders for the purpose of investigating tax evaders.&nbsp; Other countries that are interested in the information allegedly stolen by Mr. Kieber include the United Kingdom (U.K.), the United States (U.S.), Australia and others.&nbsp; Mr. Kieber now has a new identity (possibly as part of the arrangement with Germany) and his whereabouts are unknown.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.lgt.com/export/sites/inta_lgtcom/_news/attachments/080224_LGT_Media_Release_en.pdf">LGT Group Media Communique dated 2/24/08</a> <br><span style="font-style: italic;">[Evan] Highly recommended interesting read</span><br><a target="_blank" href="http://www.theaustralian.news.com.au/story/0,25197,23276025-601,00.html">The Australian online news story</a> <br><a target="_blank" href="http://www.bloomberg.com/apps/news?pid=20601085&amp;sid=atBBrvCnsT6w&amp;refer=europe">Bloomberg.com online news story</a> <br><a target="_blank" href="http://www.marketwatch.com/news/story/uk-authorities-have-liechtenstein-tax/story.aspx?guid=%7BC132E3BB-306E-46C9-B4D0-37F2CBD5C4A2%7D">MarketWatch online news story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Chad Thomas, Bloomberg.com<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>For LGT Group, all the facts now point - despite contradictory statements form sources said to be close to the German intelligence service - to the fact that the data material illegally disclosed to the German authorities is limited, in as far as LGT is concerned, to the client data stolen from LGT Treuhand in 2002.<br><br>Even though other rumors have been circulated about the occurrences, LGT Group is assuming on the basis of numerous indications that the person, who illegally passed the data on to the German intelligence service, is the same former employee of LGT Treuhand who stole the data in 2002.<br><br>Apparently, the stolen data material has also been illegally disclosed, directly or indirectly, to other authorities.&nbsp; According to reports in the media, the previously convicted offender was paid a sum of several millions for the information and was provided with a new identity.<br><br>this is a possibility that law firms were interposed as intermediaries.&nbsp; LGT will now re-register its report of a criminal offence committed by a person unknown directly against the convicted data thief.<br><br>approximately 1,400 client relationships with LGT Treuhand, which were established before the end of 2002.&nbsp; The largest proportion, about 600 clients, are resident in Germany.&nbsp; The figure circulated in the media of 4,527 sets of data represents the number of beneficiaries of all the foundations<br><br>it has become increasingly clear that the so-called "informant" of the BND German intelligence service is indeed the same convicted data thief who illegally disclosed the client data in 2002<br><br>Acting on the information, German authorities raided the home of one of the country's most high-profile executives, the chief executive of Deutsche Post AG, alleging he evaded paying about E1 million in taxes.<br><br>The government, which paid as much as 5 million euros ($7.4 million) for information on German account holders in Liechtenstein on a disk provided by an informant to the Federal Intelligence Service, or BND, will share this information with other countries, the finance ministry said today.<br><span style="font-style: italic;">[Evan] You mean to tell me that its possible (and acceptable) to steal confidential corporate information and sell it for big bucks?&nbsp; German authorities paid over $12,000 per record (7,400,000/600)!&nbsp; The question is, is this an informant or a data thief cashing in?</span><br><br>U.K. tax collectors, after initially turning up their nose at an informant's offer to sell them confidential data from a Liechtenstein bank, have now paid up and have information on about 100 wealthy British subjects<br><br>they were persuaded to pay the informant around 100,000 pounds only after Berlin tax officials launched in recent weeks a high-profile crackdown on Germans with money said to be stowed away in Liechtenstein<br><span style="font-style: italic;">[Evan] The UK got a deal.&nbsp; They only paid ~$2,000 per record.</span><br><br>Australian authorities have been given details of Australian clients of Liechtensteinische Landesbank (LL<img src="http://breachblog.com/emoticons/cool.png" border="0" />, according to reports in the Wall Street Journal and Guardian newspapers.<br><br>"The Australian Tax Office does not pay for information about tax schemes," an ATO spokeswoman said. "Nonetheless, we have a good flow of information from people concerned about fairness and equity in the tax system."<br><span style="font-style: italic;">[Evan] The best deal of all.&nbsp; Australia got the stolen information for free!</span><br><br>The former employee, who was convicted of the data theft, is a Liechtenstein citizen named Heinrich Kieber (HK).<br><br>He was active from October 1999 as an external employee of an IT-company, and from April 2001 to November 2002 as an employee of LGT Treuhand.&nbsp; At the time of his recruitment and during his employment with LGT Treuhand, he had not been previously convicted of a crime.&nbsp; However, as would become known later, an arrest warrant had been issued against HK, which was not accessible for examination during the standard checks carried out on new employees.<br><br>This arrest warrant was linked to a real estate deal in Spain in 1996, which HK had allegedly financed with uncovered checks, and was issued by the Spanish criminal prosecution authorities in 1997, firstly at national and subsequently at international level.<br><br>It has been reported that he (Heinrich Kieber)&nbsp; has been given a new identity and is living in Australia.<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very intriguing story and one that will take a while to shake out.&nbsp; I am a little torn by the series of events, and struggle with the ethics of it all.&nbsp; I don't think Heinrich Kieber is any kind of hero by any means.&nbsp; I think he is a common thief that just received a huge payday. <br><br>A couple of questions to think about:<br></font><ul><li><font size="2">Do you think Heinrich Kieber is lucky criminal, or do you think he is an honest "informant" and "whistleblower"?&nbsp; <br></font></li><li><font size="2">If he were truly an honest guy, why would he shop the confidential information around like he did and not give it freely?</font></li><li>Do you think this story will encourage other insiders to follow suit?<br></li></ul><font size="2"><br>On one hand authorities catch criminals, which is great!&nbsp; On the other hand, we just enabled (and in some circles encouraged) insider criminal activity and potentially employee fraud.&nbsp; Read the <a target="_blank" href="http://www.lgt.com/export/sites/inta_lgtcom/_news/attachments/080224_LGT_Media_Release_en.pdf">LGT Group Media Communique</a>, it is very interesting stuff. <br><br>Past Breaches:<br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/25/lgt.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 25 Feb 2008 11:03:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/confidential">confidential</category>
      <category domain="http://securityratty.com/tag/confidential data">confidential data</category>
      <category domain="http://securityratty.com/tag/kieber">kieber</category>
      <category domain="http://securityratty.com/tag/named heinrich kieber">named heinrich kieber</category>
      <category domain="http://securityratty.com/tag/lgt">lgt</category>
      <category domain="http://securityratty.com/tag/lgt trust">lgt trust</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://breachblog.com/2008/02/25/lgt.aspx">Cashing in on employee theft, or honest whistleblower?</source>
    </item>
  </channel>
</rss>
