Pittsburgh Man Sentenced for Role in Law Firm Hack
|U.S. Attorney’s Office November 01, 2013|
PITTSBURGH—A Pittsburgh resident has been sentenced in federal court today on his conviction of recklessly damaging a computer and password trafficking, United States Attorney David J. Hickton announced today.
United States District Judge David S. Cercone imposed the sentence on Matthew James West, 22. West was sentenced to two years' probation; 250 hours community service; full restitution of $2,445.96; and computer monitoring; and he must notify any employer of this conviction.
According to information presented to the court, on November 28, 2011, Alyson Cunningham had been fired from a Pittsburgh law firm referred to as “VG.” In retaliation for the firing, Matthew West, acting at Alyson and Jonathan Cunningham’s encouragement, logged into VG servers using an internal company password provided to him by Alyson Cunningham over Facebook. West utilized a VPN proxy server located in Germany to use the password to access VG servers, so as to shield his identity. Once West accessed the server, he installed software on the server that could be used to capture passwords of anyone on the firm’s network.
On November 29, 2011, West sent a partner at VG law firm an e-mail from the account firstname.lastname@example.org that stated that the firm’s web servers had been compromised and that their backup files had been copied and deleted. This e-mail, which was used to notify the victim company of the hack caused by the usage of the illegally trafficked password, electronically traveled from West’s computer in Pennsylvania to Google’s servers in California, before arriving back at VG’s server in Pennsylvania. The e-mail further stated that “we are not interested in ruining your business, but routinely checking that business is fair and just. Our motive is to solely capture and record 100% of Pittsburgh business records and operations and protect it or use it against you as we could if Anonymous had a reason and needed to.” Anonymous is a loosely connected network of computer hacker/activists who are known to intrude upon computer networks for political purposes.
According to the victim company, neither Alyson Cunningham, Jonathan Cunningham, nor Matthew West had authority to access their computer server, nor did they have authority to place malware onto VG’s servers.
Internet chats indicate that Jonathan Cunningham was actively communicating with West during the hack into VG’s servers, providing instruction and suggestions, including suggesting the use of specific VPN servers. When IM chatting with West on the night of the hack, Jonathan Cunningham and Alyson Cunningham alternated in their use of Alyson’s Skype account when communicating with West about the hack.
Assistant United States Attorney James T. Kitchen prosecuted this case on behalf of the government.
U.S. Attorney Hickton commended the Federal Bureau of Investigation for the investigation leading to the successful prosecution of West.