Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that RICHARD LIRIANO pled guilty today to one count of computer fraud in connection with his scheme to use malicious software programs, including a program known as a “keylogger,” on dozens of his coworkers’ computers at a New York City-area hospital, secretly obtaining user names and passwords to his victims’ personal email and other accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and accessed their sensitive personal photographs, videos, and other private documents. LIRIANO pled guilty earlier today in Manhattan federal court before United States Magistrate Judge Kevin N. Fox.
U.S. Attorney Geoffrey S. Berman said: “To feed his voyeuristic curiosity, Richard Liriano, an information technology professional at a New York hospital, installed a “keylogger” on dozens of his coworkers’ computers and used other unauthorized software to spy on and steal personal information from them. Liriano’s disturbing crimes not only invaded the privacy of his coworkers; he also intruded into computers housing vital healthcare and patient information, costing his former employer hundreds of thousands of dollars to remediate. He will now be held accountable for his actions.”
According to the allegations in the Information to which LIRIANO pled guilty, a prior Indictment filed against LIRIANO, as well as statements made during the plea and other proceedings in the case:
From at least in or about 2013, up to and including at least in or about 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records and personal photographs, onto his own workspace computer for his own personal use.
To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, without authorization, used various malicious programs to steal the user names and passwords of his primarily female co-workers. One of these programs was known as a keylogger, which recorded and sent victim employees’ keystrokes to LIRIANO, such as the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 70 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”).
LIRIANO then used those stolen usernames and passwords to log in to the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for sexually explicit photographs and videos in the Compromised Accounts.
LIRIANO’s computer intrusions into Hospital-1’s computer networks caused over $350,000 in losses to Hospital-1.
* * *
LIRIANO, 33, of the Bronx, New York, was arrested on November 14, 2019. LIRIANO pled guilty today to one count of transmitting a program to a protected computer that intentionally caused damage, which carries a maximum sentence of 10 years in prison. The maximum potential sentence in this case is prescribed by Congress and is provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge.
LIRIANO is scheduled to be sentenced by U.S. District Judge Lewis A. Kaplan on April 15, 2020, at 3:00 p.m.
Mr. Berman praised the investigative work of the Federal Bureau of Investigation and thanked the New York City Police Department for its assistance.
This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution.
Geoffrey S. Berman, the United States Attorney for the Southern District of New York, and William F. Sweeney Jr., Assistant Director-in-Charge of the New York Office of the Federal Bureau of Investigation (“FBI”), announced the arrest of RICHARD LIRIANO for installing a malicious software program known as a “keylogger” on dozens of his coworkers’ computers at a New York City area hospital, obtaining unauthorized access to his victims’ email, social media and other online accounts, and using that unauthorized access to steal private and confidential files. Using his victims’ stolen credentials, LIRIANO repeatedly compromised their password-protected online accounts, and pilfered their sensitive personal photographs and other private documents.
LIRIANO was arrested yesterday and arraigned in federal court before United States Magistrate Judge Katharine H. Parker.
U.S. Attorney Geoffrey S. Berman said: “Richard Liriano, an information technology professional at a New York hospital, is alleged to have installed a ‘keylogger’ program onto dozens of his coworkers’ computers in order to spy on and steal personal information from them. Liriano allegedly used the access he gained through the malicious software to steal photos, tax records, and other personal information from his coworkers and people associated with them. As information technology increasingly becomes an integral part of our workplaces, ensuring the integrity of those systems becomes even more critical. The arrest of Liriano should serve as an error message to any information technology professionals seeking to capitalize on their trusted access to information: As in this case, you will be caught and prosecuted.”
FBI Assistant Director-in-Charge William F. Sweeney Jr. said: “Whatever alleged motivation the subject in this case had, hacking into his co-workers lives, albeit extremely disturbing, wasn't the most egregious act. He allegedly installed a harmful program on computers that house vital and critical healthcare information for hospital patients, without a thought to what he could be compromising in his attempts to spy on people.”
According to the Indictment unsealed today in Manhattan federal court[1]:
From at least in or about 2017, up to and including at least about in or about September 28, 2018, LIRIANO misused administrative access provided to him as an information technology employee at a New York City-area hospital (“Hospital-1”), to log in to employee accounts, and copy other employees’ personal documents, including tax records, and personal photographs onto his own workspace computer for his own personal use.
To further his efforts to steal personal information from Hospital-1’s employees, LIRIANO, without authorization, secretly installed a malicious program known as a keylogger on the accounts of other, primarily female, employees. This program recorded and sent victim employees’ keystrokes to LIRIANO, which included the usernames and passwords those employees entered to access their personal web-based email accounts. Through the course of this conduct, LIRANO stole usernames and passwords for at least approximately 30 email accounts belonging to Hospital-1 employees or persons associated with those employees (the “Compromised Accounts”).
LIRIANO then used those stolen usernames and passwords to log in to the Compromised Accounts and obtain unauthorized access to other password-protected email, social media, photographs, and online accounts to which the Compromised Accounts were registered. Among other things, LIRIANO conducted searches for personal photographs in the Compromised Accounts.
* * *
LIRIANO, 33, of Bronx, New York, is charged in three counts. The first count charges him with transmitting a program to a protected computer that intentionally caused damage, which carries a maximum sentence of 10 years in prison. The second count charges him with intentionally accessing a protected computer without authorization and recklessly causing damage, which carries a maximum sentence of five years in prison. The third count is aggravated identity theft, which requires a two year prison term to be served consecutive to any sentence imposed on the computer intrusion charges. The maximum potential sentences are prescribed by Congress and are provided here for informational purposes only, as any sentencing of the defendant will be determined by the judge.
Mr. Berman praised the extraordinary work of the FBI and the New York City Police Department.
This case is being handled by the Office’s Complex Frauds and Cybercrime Unit. Assistant U.S. Attorney Vladislav Vainberg is in charge of the prosecution.
The charges contained in the Indictment are merely accusations, and the defendant is presumed innocent unless and until proven guilty.
[1] As the introductory phrase signifies, the entirety of the text of the Indictment, and the description of the Indictment set forth herein, constitute only allegations, and every fact described should be treated as an allegation.
Description: The fiscal year of the data file obtained from the AOUSC
Format: YYYY
Description: The code of the federal judicial circuit where the case was located
Format: A2
Description: The code of the federal judicial district where the case was located
Format: A2
Description: The code of the district office where the case was located
Format: A2
Description: Docket number assigned by the district to the case
Format: A7
Description: A unique number assigned to each defendant in a case which cannot be modified by the court
Format: A3
Description: A unique number assigned to each defendant in a case which can be modified by the court
Format: A3
Description: A sequential number indicating whether a case is an original proceeding or a reopen
Format: N5
Description: Case type associated with the current defendant record
Format: A2
Description: A concatenation of district, office, docket number, case type, defendant number, and reopen sequence number
Format: A18
Description: A concatenation of district, office, docket number, case type, and reopen sequence number
Format: A15
Description: The status of the defendant as assigned by the AOUSC
Format: A2
Description: A code indicating the fugitive status of a defendant
Format: A1
Description: The date upon which a defendant became a fugitive
Format: YYYYMMDD
Description: The date upon which a fugitive defendant was taken into custody
Format: YYYYMMDD
Description: The date when a case was first docketed in the district court
Format: YYYYMMDD
Description: The date upon which proceedings in a case commenced on charges pending in the district court where the defendant appeared, or the date of the defendant’s felony-waiver of indictment
Format: YYYYMMDD
Description: A code used to identify the nature of the proceeding
Format: N2
Description: The date when a defendant first appeared before a judicial officer in the district court where a charge was pending
Format: YYYYMMDD
Description: A code indicating the event by which a defendant appeared before a judicial officer in the district court where a charge was pending
Format: A2
Description: A code indicating the type of legal counsel assigned to a defendant
Format: N2
Description: The title and section of the U.S. Code applicable to the offense committed which carried the highest severity
Format: A20
Description: A code indicating the level of offense associated with FTITLE1
Format: N2
Description: The four digit AO offense code associated with FTITLE1
Format: A4
Description: The four digit D2 offense code associated with FTITLE1
Format: A4
Description: A code indicating the severity associated with FTITLE1
Format: A3
Description: The title and section of the U.S. Code applicable to the offense committed which carried the second highest severity
Format: A20
Description: A code indicating the level of offense associated with FTITLE2
Format: N2
Description: The four digit AO offense code associated with FTITLE2
Format: A4
Description: The four digit D2 offense code associated with FTITLE2
Format: A4
Description: A code indicating the severity associated with FTITLE2
Format: A3
Description: The title and section of the U.S. Code applicable to the offense committed which carried the third highest severity
Format: A20
Description: A code indicating the level of offense associated with FTITLE3
Format: N2
Description: The four digit AO offense code associated with FTITLE3
Format: A4
Description: The four digit D2 offense code associated with FTITLE3
Format: A4
Description: A code indicating the severity associated with FTITLE3
Format: A3
Description: The title and section of the U.S. Code applicable to the offense committed which carried the fourth highest severity
Format: A20
Description: A code indicating the level of offense associated with FTITLE4
Format: N2
Description: The four digit AO offense code associated with FTITLE4
Format: A4
Description: The four digit D2 offense code associated with FTITLE4
Format: A4
Description: A code indicating the severity associated with FTITLE4
Format: A3
Description: The FIPS code used to indicate the county or parish where an offense was committed
Format: A5
Description: The date of the last action taken on the record
Format: YYYYMMDD
Description: The date upon which judicial proceedings before the court concluded
Format: YYYYMMDD
Description: The date upon which the final sentence is recorded on the docket
Format: YYYYMMDD
Description: The date upon which the case was closed
Format: YYYYMMDD
Description: The total fine imposed at sentencing for all offenses of which the defendant was convicted and a fine was imposed
Format: N8
Description: A count of defendants filed including inter-district transfers
Format: N1
Description: A count of defendants filed excluding inter-district transfers
Format: N1
Description: A count of original proceedings commenced
Format: N1
Description: A count of defendants filed whose proceedings commenced by reopen, remand, appeal, or retrial
Format: N1
Description: A count of defendants terminated including interdistrict transfers
Format: N1
Description: A count of defendants terminated excluding interdistrict transfers
Format: N1
Description: A count of original proceedings terminated
Format: N1
Description: A count of defendants terminated whose proceedings commenced by reopen, remand, appeal, or retrial
Format: N1
Description: A count of defendants pending as of the last day of the period including long term fugitives
Format: N1
Description: A count of defendants pending as of the last day of the period excluding long term fugitives
Format: N1
Description: The source from which the data were loaded into the AOUSC’s NewSTATS database
Format: A10
Description: A sequential number indicating the iteration of the defendant record
Format: N2
Description: The date the record was loaded into the AOUSC’s NewSTATS database
Format: YYYYMMDD
Description: Statistical year ID label on data file obtained from the AOUSC which represents termination year