Fired IT worker jailed for intentionally damaging railway's computer network

midian182

Posts: 11,745   +178
Staff member

If you’re being let go from a job you hate, it may be tempting to leave a ‘goodbye present.’ But while locking a tuna sandwich in your desk drawer on the last day, for example, is unlikely to get you jailed, sabotaging the company’s computer systems probably will.

The Register reports that Christopher Victor Grupe, a 46-year-old former IT administrator at Canadian Pacific Railway (CPR), has been sentenced to 366 days behind bars for intentionally damaging the firm’s computer network.

It seems that Grupe was unlikely to win employee of the month at his former job: he was suspended for 12 days in December 2015 for insubordination.

Grupe’s attorney told the Star Tribune that his client’s suspension was attributed to increased stress from “working around the clock,” which led to him “yelling at [his boss] and using some language he probably shouldn’t have.”

When he returned on December 15, CPR told him he was being fired from its US headquarters in Minneapolis. The company allowed Grupe to resign, rather than being terminated. He signed a resignation letter and promised to give back his laptop, remote access authentication token, and access badges. But two days later, Grupe decided to take revenge.

On December 17, he used his work notebook and credentials to log into CPR’s computer network switches. Grupe removed administrator-level accounts, deleted key files, and changed the passwords for other accounts. He then wiped the laptop clean and destroyed all logs to try and hide his crime.

CPR discovered the effects of Crupe’s actions on January 5 when staff found they couldn’t log into the switches. Court documents state that parts of the system went down, and staff had to force reboot all the switches to regain access.

Two days later, outside computer forensic experts hired by CPR traced the damage back to Grupe. A jury found him guilty of one count of intentional damage to a protected computer in October last year. US District Judge Patrick Schiltz sentenced him to a year and a day behind bars yesterday.

Permalink to story.

 
Takes the definition of "foamer" to a whole new level.

Also, do NOT **** with the railroads. They do not care, and will pursue you to the end of the earth if you screw with their stuff. This guy figured it out the hard way, I guess.
 
Sounds like management should be fired too or at least evaluated. The company decided to "terminate" the employee therefore had plenty of time to prepare. Another administrator should have been notified and disabled his accounts when Chris is meeting with management/HR on the 15th. Why the credentials are still valid days later is the fault of the company.
Every employee upon termination should have risk evaluated by the company. When the employer decide to let someone go, it should always be treated as High Risk.
We should all learn something from cases like this.
 
Damn. This gives me ideas of what I should've done at Potbelly in Rand Tower (inside US Bank Plaza off 5th & Marquette, downtown Minneapolis), when I quite October 2016. Those people were really bad; several people quit due to inappropriate and illegal behavior such as assistant managers threatening to kill employees.
 
This was handled terribly by CPR. Terminating an employee while he still has his equipment, AND leaving his accounts enabled? Kezhen is completely right - This is a high risk term if there ever was one.
 
Yeah... when there's a termination I remove access to company logins and systems within an hour or two (usually within 5 minutes of getting the actual notice) unless explicitly told otherwise, so this just sounds like a really bad outbound process.
 
Even the dumbest of managers knows to confiscate company equipment and delete access accounts BEFORE you drop the hammer ..... apparently one got through the net .....
 
Served that A-H right. Should have increased his jail term in fact.
company was nice enough to let him resign instead of fire him and this is how he repays them. Plus the consequences of messing with trains can be extremely severe.
 
Served that A-H right. Should have increased his jail term in fact.
company was nice enough to let him resign instead of fire him and this is how he repays them. Plus the consequences of messing with trains can be extremely severe.

I suspect the company must have done something for the hacker to be extremely angry. Normally we hackers have a higher threshold of being irritated for doning something like this!
 
Served that A-H right. Should have increased his jail term in fact.
company was nice enough to let him resign instead of fire him and this is how he repays them. Plus the consequences of messing with trains can be extremely severe.

I suspect the company must have done something for the hacker to be extremely angry. Normally we hackers have a higher threshold of being irritated for doning something like this!
Or, given this man was already agitated, was allowed to resign rather then be fired, then responded by SCREWING WITH HIS OWN COMPANY, the worker has some serious anger management or other psychological issues.
 
It's HIS EXCOMPANY as apparently he does not OWN this company... He yelled at his boss and then paid this bill by two weeks suspension. Why another penlity (being fired "or take the resign") was laid on him? This seems like double punishment, and whether this is lawful is under question. I suspect the company played a trick on forcing him to "resign". So what can he do when he found the company cheated him and unable to sue them? It's understandable that he hacked that company.
 
Or, given this man was already agitated, was allowed to resign rather then be fired, then responded by SCREWING WITH HIS OWN COMPANY, the worker has some serious anger management or other psychological issues.
It's HIS "EX" COMPANY as apparently he does not OWN this company... He yelled at his boss and then paid this bill by two weeks suspension. Why another penlity (being fired "or take the resign") was laid on him? This seems like double punishment, and whether this is lawful is under question. I suspect the company played a trick on forcing him to "resign". So what can he do when he found the company cheated him and unable to sue them? It's understandable that he hacked that company.
 
Back