Ads by TechWords

See your link here
Receive the latest technology news and information.
CareerMail
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Ready to blow the whistle on a cybercrime? Who ya gonna call?

A tangled web of agencies oversees computer crime. How can IT workers cut through the confusion?

September 12, 2007 12:00 PM ET

Computerworld - You stumble across evidence of a computer crime, something you believe is clearly and unequivocally against the law. Your first step is to report the crime to your employer.

But as Computerworld has reported (see Dark secrets and ugly truths: When ethics and IT collide), it isn't always so simple. Maybe your employer doesn't know how to handle the situation you've uncovered, maybe your superiors don't believe you, or, worse yet, maybe they're choosing to ignore the problem. (It's hard not to be haunted by the case of Shawn Carpenter, the network security analyst fired from Sandia National Laboratories for independently pursuing a network security breach at the company.)

If your conscience wins the ethical debate over whether to report the suspected crime to law enforcement, you'll face another hurdle: finding a law enforcement agency that will listen.

With the possible exception (we hope) of a threat to homeland security, efforts to report cybercrime can become mired in a complex web of overlapping jurisdictions or might even be totally ignored.

Asked where citizens should report various cybercrimes, FBI spokeswoman Cathy Milhoan could not offer definitive guidance. "The lines are still blurry," she acknowledges.

Who you call depends on many factors, including how much money is involved, the media used (Internet? U.S. mail? Telephone?) and whether the criminal activity originated domestically or overseas.

Local? State? Federal?

Beyond that, Milhoan declined to give specific guidance for fear of stepping on other agencies' toes. "I don't want the message to come across that everybody should report their crimes to the FBI, because a lot of state and locals, as well as other government agencies, have their own cyberteams," she says.

Milhoan ticks off a bewildering list of Web sites and agencies. For civil actions, the Federal Trade Commission might be involved. If it touches the U.S. mail, the U.S. Postal Inspector might want to hear about it.

 
Related Story:
Dark secrets and ugly truths: When ethics and IT collide


 

Even experts like Chuck Martell, managing director of investigative services at Veritas Global, sometimes struggle on where they should turn. Martell is currently handling a case in which a former IT employee gained access to the corporate network by means of a backdoor.

But the monetary damages are relatively low, only $30,000, so the U.S. Attorney's Office won't take the case.

"We're literally having a problem finding a law enforcement agency that's interested," Martell says. "We've talked with the FBI, with the state police, with the local police department, trying to get someone to take this case."

Martell has a suggestion that might at first seem counterintuitive: Make your first call to a major law firm. It will likely be able to either advise you or refer you to a private investigator who can tackle the task of figuring out where to report the crime and advise you on what to do.

Investigative firms can also immediately send in forensic specialists, a critical step to prosecuting these cases, Martell stresses. "I can't tell you how many cases [we've had in which] the IT people have attempted to preserve things or try to see what's there, and they polluted the evidence by doing that."


Tam Harbert is a Washington-based freelance journalist specializing in technology, business and public policy.



Jump to comments

cybercrime

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

Chiquita selects Workday's fresh approach to Human Capital Management
A fresh approach to meet IT and HR objectives.  

Usability Is Everything
Download this short video! Provided by Workday.

Supporting Employees Anytime, Anywhere
Download this White Paper Now!  

The Value of Real SaaS at Workday
Download this short video! Provided by Workday

Natural User Interface for Enterprise Applications
Download this Complimentary White Paper! Provided by Workday.  

SaaS at Flextronics, Inc.
Download this short Video! Provided by Workday.

A Truly Global HCM System
Download this Complimentary White Paper! Provided by Workday.  

Craft a Strategy to Lower Your Total Cost of Ownership
Download this Complimentary White Paper! Provided by Workday.