The Daily Caveat is written by Michael Thomas, a recovering corporate investigator in the Washington, DC-area.

CARE TO CONTRIBUTE?

TIPS, COMMENTS and QUESTIONS are always welcome (and strictly confidential).

Contact The Daily Caveat via:



Join our mailing list to new posts via email.



Or justrss icon read the feed...


Previous Posts Archives
5/02/2007
Wired Updates Word on OneDOJ
OneDOJ, the proposed master database consolidating a wide range of public (and non-public) records for law enforcement is well underway. Crucial anti-terrorism tool or ID thief buffet? Time will tell. Wired offers a brief update on the progress.

-- MDT

Labels: , , ,

0 Comments.
Post a Comment
12/28/2006
Latest Attempt at Huge Law Enforcement Database
Codename: ONE DOJ. While I can't say for sure, this sounds much like the "The Matrix" or Multistate Anti-Terrorism Information Exchange. This was a similar system that was proposed, developed and shelved a few years back. Is this the same program under a new, less machine-led-humans-as batteries-armageddon moniker?

The Maxtrix was designed to aggregate public records along with private data sources (credit headers, etc.) to create one massive personal info chopper. For the time being, ONE DOJ appears to be a much more modest effort, geared toward nation-wide availability of casefiles and investigative reports from around the country.

Techdirt, for its part, will tell you why this is a bad idea (again).

-- MDT

Labels: , , ,

0 Comments.
Post a Comment
10/24/2006
Ridiculously Cool: Enron Emails Searchable Online
Highly appropriate based on this week's resurgence of Enron-related news --> Want a window into the disintegration of the company that perpetrated one of the great corporate frauds of all time?

Check out this amazing resource, Trampoline's Enron Explorer which contains a searchable, graphically relatable database of all the emails flitting about Enron revealed in the course of the investigation into the energy trader. You can seach globally on full text or sort by individual and then drill down or even render a web of their contacts with others (not unlike the sadly seldom updated They Rule - another site you really must visit if you have never seen it).

Found at the always entertaining (and no certainly need of link-backs from little ol' me) blogging all-star, BoingBoing.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
9/01/2006
FBI Security Database Still Woefully Insecure
Its not as if we didn't see this coming with. The ever-interesting Techdirt has the latest.

-- MDT

Labels: ,

0 Comments.
Post a Comment
5/30/2006
Using a Broken Tool - Expanded use of a Federal Background Check Database Promises More Errors
A government background check database which combines Social Security and immigration sources to verify a potential employee's immigration status may be expanded for general use, complete with a billion dollar price tag to get it up and running on a large scale. The database is designed to help employers distinguish legal and illegal immigrants applying for work. Not a bad idea in theory, but small scale tests haven't exactly shown the system to be error free. Hence the billions. Homeland Security is offering a voluntary program for business owners to test usage of the system, with 6,000 employers currently enrolled.

For more info on the system and its potential pitfalls, click here.

-- MD

Labels: ,

0 Comments.
Post a Comment
5/17/2006
Feds Debating New Data Breach Disclosure Law
The Cyber-Security Enhancement and Consumer Data Protection Act of 2006 would require disclosures on breaches involving more than 10,000 names or illegal/inadvertent access of any government database.

No word on whether the recent disclosures of comprehensive NSA phone record tracking have any bearing on this...

See the bill details here.

-- MDT

Labels: ,

0 Comments.
Post a Comment
5/08/2006
NASD Expels Salomon Grey Financial Corp, Bans Owner for Lifetime
Salomon Grey Financial, a Dallas, Texas-based brokerage that was first registered in 1998 has been dealt a severe penalty by the National Association of Securities Dealers. Salomon Grey went out of business since Febuary but has been in regulators sites for the past several years. In August 2004 Salomon Grey and owner Kyle Browning Rowe agreed to a $100,000 fine on charges relating to money laundering, poor supervision, employing brokers with past disciplinary problems and conducting unauthorized searches of an NASD database. Rowe was also suspended for two weeks by the NASD (Sept. 7 - Sept. 20, 2004) in relation to the same charges. In paying the $100,000 fine, neither Rowe nor his firm were required to admit any wrongdoing. However, as of late last month the NASD made their assessment of the situation very clear, with the decision to expel Salomon Grey and to ban Kyle Rowe for life. Time to keep the eagle-eyes out for where Mr. Rowe and the rest of the crew from Solomon Grey's 14 offices land next.

More on the story can be found here. And for the the NASD's press release on Rowe's lifetime ban and Solomon Grey's shady activities, click here.

--MDT

Labels: ,

0 Comments.
Post a Comment
5/01/2006
The Matrix (forgive me...) Reloaded?
Recall this story from last summer about the Federal government's abandoned plans for The Matrix, (or The Multistate Anti-Terrorism Information Exchange) a proposed database that would aggregate public records and commercially obtained data (read, credit headers, cell phone numbers and whatever else commerical firms can get their hands on) and make the information available to local law enforcement.

While the Feds discontinued their plans for the database, much to the relief of privacy advocates, Florida, for its part is apparently continuing to develop a similar system that would be powered by Lexis Nexis's Seisint. It is worth noting that Seisint was affilicated by a major personal info heist that touched off last summer's tidal wave of data breach news coverage and increased governmental, media and consumer attention to the issues surrounding personal data security.

-- MDT

Labels: , , , , , ,

0 Comments.
Post a Comment
4/04/2006
Limited Background Check Gives Free Pass to Drug-Dealing Teacher
There is no doubt that low-level background checks have become a commodity. You can search the web to find any number of automated searches promising things like a "comprehensive, nationwide criminal background check." Unfortunately, The Daily Caveat is here to tell you that no such animal exists and the advice your parents gave you still holds true - if it sounds too good to be true, it probably is.

Now, not every job or business decision necessitates "the Cadillac plan." There is no question that there is a difference in the due diligence burden for a new fry cook at McDonalds versus the new chief executive of a milti-billion dollar company. But in every case, no matter how big or small the budget, please be wary of an services that seems to offer a high level of risk mitigation at an impossibly low pricepoint. At the end of the day, you are most likely getting only as much as you paid for.

Investigations, to be worth anything must be thorough, concise and most of all, conducted by human beings, not just search fields in a database. Whether you opt to work with Caveat Research or one of our many competitors, my advice is, to the extent possibly, do not shop on price. Make your choice, rather, on the investigator's ability to help you understand the work undetaken on your behalf. Only through that understanding can a true accounting for costs be obtained. Failing to understand your own investigation is what leads to situations like this one, in Indiana:
Screening missed teacher's drug case - Case of a Hoosier's Florida arrest record exposes limitations of background checks

By Staci Hupp
April 2, 2006
Indianapolis Star

"It's scary that someone could be prosecuted in another state and come to Indiana and we don't know about it," said Rep. Robert W. Behning, R-Indianapolis, who heads the House Education Committee.

At least 41 other states have switched to FBI screenings that use fingerprints to scan criminal records nationwide. Teachers who apply for licenses in Indiana are subject only to the state's limited criminal history check, a computer screening that relies on incomplete records from county courthouses.

Money typically is the sticking point, according to Indiana State Police officials who have pushed for changes. Schools would have to pay up to $39 for FBI background checks, while the state system is available for free.

No one knows how many offenders have slipped through screening in Indiana. A check of newspaper stories from the past decade shows that at least three school employees convicted of violent crimes passed background checks.

Indiana bars those convicted of drug dealing, crimes involving children and some other felonies from teaching.

But first it has to spot them...
More here.

-- MDT

Labels: ,

0 Comments.
Post a Comment
1/26/2006
FTC Fines Choicepoint $15 Million in Data Breach
But don't week for the fine folks at Choicepoint. According to this recent article from MSN Money, their revenue in 2005 exceeded $1 billion., with projections for 2006 looking to be up 7 to 9%. More on the FTC fine, via Business Week:
FTC Fines ChoicePoint Over Data Breach

January 26, 2006
BusinessWeek
By Harry R. Weber
AP Business Writer

The Federal Trade Commission said Thursday that data warehouser ChoicePoint Inc. will pay $15 million to settle charges that its security and record-handling procedures violated consumers' privacy rights and federal laws. The FTC said it had fined the Alpharetta, Ga.-based company $10 million -- the biggest the agency has ever imposed -- and that Choicepoint would pay an additional $5 million that will be used to compensate consumers.

Company shares sank nearly 7 percent on a day it also reported a more than 29 percent decline in its fourth-quarter profit. Choicepoint had revealed last year that its massive database of consumer information was accessed by thieves. The data breach involved thieves posing as small business customers who gained access to ChoicePoint's database, possibly compromising the personal information of 145,000 Americans. The FTC said the number now stands at 163,000. The company discovered the breach more than four months before disclosing it to the public in February 2005. ChoicePoint has said authorities asked it to keep the information secret initially.

Authorities have said at least 750 people were defrauded in the scam that has fueled consumer advocates' calls for federal oversight of the loosely regulated data-brokering business. The FTC said the number of victims now stands at about 800, but ChoicePoint has noted that charges brought in Los Angeles against one of the thieves involve only 16 victims. The company also is a defendant in several lawsuits and complaints arising from the breach, and several government agencies are investigating.

"The message to ChoicePoint and others should be clear: Consumers' private data must be protected from thieves," Deborah Platt Majoras, chairman of the FTC, said Thursday in a statement. The $10 million fine is the largest ever levied by the FTC, Majoras said during a news conference. Previously, the largest FTC fine was for $7 million against medical device maker Boston Scientific Corp. related to competition issues, she said. "This is an important victory for consumers," Majoras said.

The settlement requires ChoicePoint to implement new procedures to ensure that it provides consumer reports only to legitimate businesses for lawful purposes, to establish and maintain a comprehensive information security program and to obtain audits by an independent third-party security professional every other year until 2026.

The company, which is also is the subject of a pending Securities and Exchange Commission probe, did not admit to any wrongdoing in the FTC probe. ChoicePoint collects data on individuals, including Social Security numbers, real estate holdings and current and former addresses. It has about 19 billion records, and its customers include insurance companies, financial institutions and federal, state and local agencies.

The SEC is examining stock trades by Derek Smith, ChoicePoint's chief executive officer, and Doug Curling, chief operating officer. Curling and Smith made a combined $16.6 million in profit in the months after the company learned of the data breach and before the breach was made public. ChoicePoint has said the stock trading was prearranged and approved by the company's board.

Company officials said Thursday they continue to cooperate with the SEC probe. They did not give details of the status of the probe. The settlement came hours after the company reported its fourth-quarter profit fell to $27.68 million, or 30 cents a share, in the quarter ended Dec. 31 compared to a profit of $39.22 million, or 43 cents a share, for the same period a year ago. The results missed Wall Street expectations.

Excluding one-time expenses related to the data breach announced in February 2005, ChoicePoint said it earned $39.74 million, or 44 cents a share. On that basis, analysts surveyed by Thomson Financial were expecting earnings of 45 cents a share. Revenue rose 11 percent to $257.85 million, compared to $232.46 million a year ago.

For all of 2005, ChoicePoint said it earned $140.66 million, or $1.53 a share, compared to a profit of $147.96 million, or $1.62 a share, for the same period a year ago. Twelve-month revenue rose to $1.06 billion, compared to $918.71 million in 2004.

ChoicePoint said it expects 2006 full-year internal revenue growth to be in the 7 percent to 9 percent range, exclusive of any acquisitions. ChoicePoint shares fell $3.10, or 6.7 percent, to $43.20 in midday trading on the New York Stock Exchange.
The original article appears here.

-- MDT

Labels: ,

0 Comments.
Post a Comment
1/24/2006
Settlement of Vanlev Securities Suit Brings Increased Transparency to Drug Maker, Bristol-Myers Squibb
The Daily Caveat has posted previously about Bristol-Myers Squibb's continuing legal issues. This week saw a notable settlement in securities class action case brought against the pharmaceutical giant in relation to the never marketed hypertension drug Vanlev. Word of the settlement first appeared months ago but only recently have the exceedingly interesting details been made public.

The plaintiffs alledged in the case that BMS did not play straight with investors when reporting potential problems with BMS's long-in-the pipeline supposed high-blood-pressure uber-drug, Vanlev. While BMS had seemed willing to take this case to trial, Bruce Carton at Securities Litigation Watch called it correctly back in June'05 when he predicted that the case would settle out. The suit, brought on behalf of Amalgamated Bank settled for $185 million dollars.

Potentially severe side-effects and the drug’s ultimately ho-hum performance relative to products already on the market meant that Vanlev would never make it to the street. But according to attorneys at lead plaintiff firm Labaton Sucharow, that didn’t stop BMS from coasting for a few quarters on the good word of mouth Vanlev had been getting. Their complaint alledged that BMS withheld negative findings in early 2000, prior to the announcement that the drug was DOA.

Now what makes this case and the terms of this settlement more intriguing than your usual run of the mill securities investigation is the product involved. Bristol-Myers Squibb doesn’t make some obscure techno-widget that fits inside your computer, toaster or flat-screened television - they manufacture the drugs that are designed to make and keep us all well. Thus, not half so interesting as the high dollar figure are the other mandates of the settlement, to which BMS will be bound for the next decade.

Along with the close-to $200 million dollar figure involved in the settlement, the court has mandated a variety of new procedures for BMS's drug development and disclosure process that go beyond simply censuring overzealous execs. While you won't find hide nor hair of any mention of a legal settlement on BMS's website, what you will now find is a publicly accessible database for their clinical trial disclosures, warts and all which will include any and all drugs approved for marketing to the public.

BMS is bound to the terms of this agreement for ten years and, get this, any change that could potentially reduce the level of disclosure must be approved by the former lead plaintiffs in the case, Amalgamated Bank. Again, not that you will find mention of this on BMS's website. They do tout their Clinical Trial Communication Commitment they just don't happen to mention that their "commitment" was apparently court-mandated.

View the Labaton press release on Vanlev settlement terms.

-- MDT

Labels:

0 Comments.
Post a Comment
1/12/2006
Do it Yourself Due Diligence
Business Week is featuring a brief article suggesting that investors would be well served by doing their own due diligence before trusting their finances to an investment advisor.

This uncontroversal advice goes without saying, I think - that one should seek both anecdotal opinions and conduct a personal review of potential regulatory and legal issues that might be an early warning sign of porential recklessness or illegalities is hardly earth shattering news. However, is should be noted that in no way does this sort of preliminary review replace a proper due diligence investigation.

The savvy or sophisiticated investor certainly does not consider "googling" adequate DD in making an investment decision. Google (or your search engine of choice) is an imprecise tool and, while it might produce some quick hits that may warn one away from a bad egg or risky deal the volume of responses can also hide crucial tidbits amid a sea of search returns. Moreover, there is no guarantee that any relevant details may show up in Google.

As the article rightly points out, one should supplement Google with other resources - litigation databases, indices of regulatory filings and the like. But this is only where a proper investigation begins. For those opportunities that pass this "whiff test" having professionals review the matter for other potential liabilities is essential. A thorough background review of the entities involved comprised informed by database info as well as on-site court searches and first person interviews / references checks is the surest way to avoid horror stories such as the recent HMC debacle.

The article:
Hedge Funds: Do-It-Yourself Due Diligence - A little sleuthing online can turn up information that may signal trouble ahead

January 16, 2006
By Anne Tergesen
BusinessWeek

Hedge funds generally don't make it easy for investors to get information about their inner workings. But the 80-odd investors in the most recent hedge fund to collapse, tiny HMC International Fund of Montvale, N.J., could have saved themselves trouble and money simply by using the Internet to do some due diligence on HMC's managers.

One, Bret Grebow, left a trail of legal problems that include a property lien, an arrest on charges of possessing drug paraphernalia, and failure to repay much of a loan to a former employer.

Grebow and co-manager Robert Massimi now face Securities & Exchange Commission charges of securities fraud and the misappropriation of more than $5.2 million of the $12.9 million invested in HMC. The managers "sent investors false monthly account statements that portrayed their investments as profitable when, in reality, Grebow was systematically looting the Fund's trading account," the SEC alleges in a Dec. 21 complaint filed in the Southern District of New York. Among the items the duo is alleged to have paid for with investor funds are rent and furniture for a Manhattan apartment.

What warning signs were detectable? A search of public databases -- including those maintained by Google (), LexisNexis, and various federal, state, and county courts -- dredged up enough dirt on Grebow to cause alarm. The record includes arrests in 1994 and 1995 in Arizona -- where Grebow attended college, according to HMC's Web site -- on charges of possessing marijuana and drug paraphernalia and damaging property worth less than $100. According to the Pima County Justice Court in Tucson, the drug-related charges were dismissed in July, 1996. Grebow pleaded guilty to a lesser charge -- unlawful acts regarding alcohol -- and was fined $284. According to the court, there is an outstanding warrant for Grebow's arrest on the damage charge because of his failure to complete a drug education course. "It was staggeringly easy to get this information," says Michael Allison, CEO of International Business Research of Princeton, N.J., a company that performs background checks on hedge funds and managers (Personal Business, Nov. 21, 2005).

That's not all. In 2002, Grebow's former employer, defunct New York brokerage Bluestone Capital, won a judgment against him for not repaying a loan of more than $118,000, says Eric Streich, an attorney who represented Bluestone. Grebow has since repaid $3,212, he says. Court records also show an October, 2004 judgment against Grebow for failing to pay his former wife, Jamie Grebow, some $127,000 in support. An attorney who represented Jamie Grebow didn't return calls. Bret Grebow's attorney declined to comment on the SEC charges or his client's past. With hedge fund blowups becoming common, do some sleuthing before you write a check.


The original article appears here.

-- MDT

Labels: , , , ,

0 Comments.
Post a Comment
1/04/2006
Expanded Access to National Archive Records
According to a recent AP report, Daily Caveat former employer, The National Archives, is planning to expand access to its holding by providing an online free-text search of its full database. Read more about it here.

Spotted in the latest issue of The Virtual Chase.

-- MDT

Labels:

0 Comments.
Post a Comment
11/10/2005
Estonian Investment Firm Settles with SEC on Insider Trading Charges
Here's a long feature from the Baltic Times on the continuing tale of two young traders from Estonian Investment Firm who alledgedly conspired to gain an advantage on trades by hacking into Business Wire's embargoed press release database and accessed not-yet-released announcements from U.S. public companies.

The firm in question, Lohmus Haavel, had previously suspended five traders including, Oliver Peek and Kristjan Lepik who have been previously named in the SEC probe. Rain Lohmus, a company founder, has also stepped down as his account was used in teh illegal trading. While the SEC probe against verious Lohmus employees is continuing, the company has reached an out-of-court settlement with the SEC. Full - and The Daily Caveat means FULL - details follow:
Investment firm reaches settlement with SEC, avoids lengthy investigation

November 11, 2005
By Kairi Kurm
Baltic Times

TALLINN - Lohmus, Haavel & Viisemann, the Estonian investment firm whose employees were accused by the U.S. Securities and Exchange Commission of using insider information on stock trades, reached an out-of-court agreement with the market watchdog and thereby avoided a possible embarrassing hearing that had been scheduled for Nov. 8.

“Last night an agreement was made to cancel the court session and ease the arrest of assets,” Rain Tamm, LHV Group board chairman, said on Nov. 8, adding that a U.S. judge would have to approve the settlement. Tamm stressed that the agreement did not automatically imply LHV’s guilt.

Piret Loone, an Estonian representing LHV through Shearman & Sterling in the U.S. court, released a statement saying that the agreement was an important step forward but didn’t guarantee that the company’s accounts, arrested last week by a U.S. court, would be freed up. LHV officials said they wanted to cooperate with both the Estonian Financial Supervisory Authority and the U.S. SEC in order to clarify all accusations related to the firm.

The SEC has claimed that the firm’s employees profited from trade on U.S. public companies by using more than 360 confidential press releases belonging to Business Wire, a real-time business news agency used by brokers and traders around the world. The watchdog believes that the traders may have racked up some $7.8 million in profits on the illegal trades.

The employment contracts of Kristjan Lepik, Oliver Peek and three other employees suspected in the illegal trades, have been suspended. Peek was a member of LHV’s investments services team, and Lepik an LHV partner and head of the bank’s trading department. Rain Lohmus, one of the firm’s founders, and whose account was reportedly involved in illegal trading, stepped down from his position as chairman of the firm’s council.

Many were surprised to learn that Lohmus had also been a client of Oliver Peek. “Usually we do not comment on our customers’ data, but we found that it was important to say [Lohmus was involved],” said Tonis Haavel, one of the firm’s founders. Lohmus left for Moscow on Nov. 2, the morning news of the scandal broke, and didn’t return before Nov. 4. Haavel couldn’t say if Lohmus had been aware of possible illegal trading.

According to one report, Lohmus opened a $2-million account with LHV Trader in April this year, with the money eventually being deposited with U.S.-based Interactive Brokers. As a result of subsequent transactions, the size of his account swelled to $8.3 million by November.

According to the SEC, the illegal trading activity involved five different accounts, including those of Peek and Lepik. Peek reportedly received $2 million and Lepik $200,000 in nine months this year. “The in-house investigation is ongoing, and we are giving [the SEC] the information they request. It is very voluminous,” Haavel told The Baltic Times.

The firm LHV claims that young the men were trading as private individuals. In every statement, it emphasizes that the investment bank had nothing to do with any possible illegal trading of its former employees, and that the company has in no way profited from any such trading.

Still, the accusations have damaged the company’s reputation. Several customers have pulled their funds from LHV’s accounts, and Vilniaus Akropolis, Lithuania’s largest mall operator, cancelled its contract with LHV. Vilniaus Akropolis had been planning an IPO with the firm.

The SEC has frozen the accounts of about 180 LHV customers. Currently only those who used the LHV Trader investment services on the U.S. market through certain brokers cannot receive their money.

“Our lawyers have spoken to [the SEC]. The commission is in principle ready to unfreeze the accounts of our other clients. When it will happen, we don’t know,” Haavel said, adding that LHV has a total of 4,500 customers. “According to the securities’ act, companies like us keep clients’ assets totally separate.”

The firm’s partners have pledged to increase owners’ equity to $1 million if necessary to cover the claims. The SEC investigation was launched after a drug company, InKine, noticed a spike in trading on its shares on June 23, just before news was released about a planned merger. About 46 percent of the volume came from Estonian traders, who earned some $300,000 by selling the shares immediately after the merger was announced.

The same scheme was used in July when various earning announcements were released by eBay and Yahoo. In those cases, even larger sums were used. Business Wire made a statement defending the integrity of its data system, stating that traders could not have acquired secret access. Still, Tamm told the press that Peek and Lepik may have come across a security gap in Business Wire’s system.

Estonia’s Financial Supervision Authority has started a separate supervisory procedure into the matter. Meanwhile, a U.S.-based hedge fund manager, speaking on the condition of anonymity, told The Baltic Times that she had assumed on June 23 that whoever placed the order was related to InKine, Salix, one of the investment banks advising on the deal, or perhaps lawyers who had worked on the transaction.

“I just knew someone got very lucky that day, and I assumed it wasn’t luck that prompted them to take that big of a piece of some biotech firm in Philly no one had ever heard of before,” she said. “I had no idea who placed them. Just that someone sure was very timely and bold.” In the fund manager’s opinion, had the traders been “less greedy” on InKine, they never would have been caught, since the total share volume that day would have been within “normal” ranges.

She said that their other deals would have never aroused suspicion anywhere except among the inside compliance people of LHV and U.S. brokers Cyber Trader and InterActives. The latter are supposed to alert regulators if a client is making too many so-called “in-the-money-trades” ahead of major news stories, she said.

Jakob Frenkel, a former SEC enforcement lawyer and former U.S. federal criminal prosecutor, told The Baltic Times, “In cases like this, the SEC probably will demand penalties of $15 – 20 million, plus recovery of the profits from trading. But the SEC will first need to build its case and bring into the grasp of the U.S. courts the individuals charged.”

Frenkel, who is now with Shulman, Rogers, Gandal, Pordy & Ecker, added, “Of greater concern should be whether the SEC is working with U.S. federal or Estonian criminal prosecutors with the objective of criminal prosecutions and jail as the consequence. The allegations are of the type that would suggest the SEC will try to get criminal prosecutions too.”

The fund manager said that, if those traders cooperate, they might only pay a civil fine and avoid prosecution. “I think the Estonian securities regulators will deal with them, unless the Department of Justice wishes to make ‘examples’ of them.”

Other local investment bankers panicked about what the scandal could do to the industry’s reputation. Allan Martinson, managing partner of Martinson Trigon Venture Partners, said, “I can’t see a single person who won from this case. LHV lost, and the work of many years disappeared. Investors lost, Estonia lost, even the U.S.A. lost. This loss is a fact. What caused the loss, a crime or a work accident, is not that important. The effect of the LHV story is bigger than the conviction or justification of two boys,” he said.

As the U.S. fund manager said, “In a way, I respect how bright those boys were. I hope they cooperate - much more leniency is given to those who admit they made a mistake and clean up their act –at least over here [in the U.S.A.]. The regulators are overworked, and they hate it when people lie or refuse to cooperate. It makes them have to work much harder which means other matters get overlooked.”
The original article appears here.

-- MDT

Labels: , ,

0 Comments.
Post a Comment
11/02/2005
SEC Hammers Estonian Financial Services Firm
The SEC is seeking emergency action against the Lohmus Haavel & Viisemann. In a an admirably creative, if illegal scheme employees at Lohmus successfully hacked Business Wire's embargoed press release database to get a jump on market announcements. From the SEC press release:

"We acted today to stop a clever and pernicious securities fraud and to preserve funds for investors. This case highlights that even when fraudsters invent new ways to violate the securities laws, the Commission will track them down and stop them, wherever they are located," said Daniel M. Hawke, Associate District Administrator of the Commission's Philadelphia District Office.

The Commission's complaint alleges that, in June 2004, Lohmus became a client of Business Wire for the sole purpose of gaining access to Business Wire's secure client website. Once defendants had access, they surreptitiously utilized a software program, a so-called "spider" program, which provided unauthorized access to confidential information contained in impending nonpublic press releases of other Business Wire clients, including the expected time of issuance.

The complaint further alleges that the information fraudulently stolen by the defendants has allowed them to strategically time their trades around the public release of news involving, among other things, mergers, earnings, and regulatory actions. Using several U.S. brokerage accounts, the defendants have bought long or sold short the stocks of the companies whose confidential press release information they have stolen, and purchased options to increase their profits.

Named in the Commission's complaint are the following defendants.

Lohmus Haavel & Viisemann, headquartered in Tallinn, Estonia, is an investment bank established in 1999. Lohmus, which also has offices in Latvia and Lithuania, provides corporate financing, private equity, asset management, investment services, and structured financing services to the Eastern European market.

Oliver Peek, age 24, is a citizen of Estonia currently residing in Tallinn. Peek is employed by Lohmus and works for its investment services team.

Kristjan Lepik, age 28, is a citizen of Estonia currently residing in Tallinn. Lepik is a partner at Lohmus.

Read the rest here.

-- MDT

Labels:

0 Comments.
Post a Comment
10/05/2005
Choicepoint Trying New Security Protocols
Via the SeattleTimes.com:

ChoicePoint tries to regain trust


October 3, 2005
By Brian Bergstein
The Associated Press

In August, the police in Corona, Calif., got a surprising phone call. The caller said an auditor needed to examine the department's facilities and take pictures inside. To the security-conscious police, the photo demand seemed ridiculous, especially given its source: the data broker ChoicePoint, one of the department's information suppliers. A Corona crime analyst refused the request and asked to speak to a ChoicePoint supervisor. She never heard back.

The episode reveals the delicate balance ChoicePoint is trying to strike as it recovers from a staggering identity-theft scandal in which con artists posing as customers accessed personal information on 145,000 Americans. As it seeks to show iron resolve against fraud, the data giant is struggling not to alienate key customers in the process.

Indeed, the Alpharetta, Ga.-based company has cut off some customers entirely, including debt collectors and other small businesses that once were able to obtain full background reports on people from ChoicePoint. Other customers — including news organizations such as The Associated Press — are finding the last four digits of Social Security numbers masked in ChoicePoint reports.

Such moves — which have won praise — are expected to trim company revenue by up to $20 million a year and earnings by up to 12 cents per share. (Overall, ChoicePoint earned $1.62 per share in 2004 on sales of $884 million.) Meanwhile, customers who still get access to the most sensitive data, including driver's license numbers, are being subjected to site visits and other audits to ensure they are who they say they are — even if those customers are the police.

In fact, the company recently discovered that an unauthorized Miami police officer had used someone else's log-in and password to mine ChoicePoint records. The officer was relieved of duty. Law enforcement accounts for 5 percent of ChoicePoint's revenue — most sales come from companies that use ChoicePoint to assess job, insurance or other consumer applications — but it is a high-profile segment, often touted by the company as proof that society benefits from its amassing of so much data on individuals. The FBI alone queried ChoicePoint files 1.2 million times last year.

Private investigators also are being subjected to new scrutiny. ChoicePoint stumbled early in the crackdown when representatives called many private eyes and asked them to fax over personal and professional information about themselves, according to Brian McGuinness, a Miami investigator who heads the National Council of Investigation and Security Services. "That was kind of ill-conceived," he said. "You're asking these investigators who are very aware of scams to send this sensitive information to some number," without first sending a letter or other confirmation the call was legitimate.

Some riled private eyes called for a ChoicePoint boycott. But ChoicePoint responded by clarifying the process, McGuinness said. Other investigators see the aggressive audits as an overreaction or a public-relations ploy. Cynthia Hetherington, a private investigator in New Jersey, had to send ChoicePoint a copy of her investigator's license twice. The company agent also wanted bank-account information "and stuff that has nothing to do with my credentials or the nature of my business." "It's absolutely intrusive," she said. Hetherington remains a ChoicePoint customer, but she and many other investigators are quick to note rival providers with fewer hassles.

Indeed, when ChoicePoint stopped selling detailed background reports to debt collectors, there were plenty of other options, said Ramona Featherby, who runs a San Diego collection firm and is president of the California Association of Judgment Professionals. She cited such names as Merlin Information Service, LexisNexis' Accurint, LocatePlus and Westlaw. "They have taken a sledgehammer to the ant ... [by] cutting off databases from one industry entirely, no matter how long they've been in business, no matter how pristine their record," Featherby said of ChoicePoint.

After ChoicePoint called for interior pictures of the Corona police department, discussion ensued in an online forum frequented by law-enforcement personnel. Carol DiBattiste, ChoicePoint's new privacy and compliance officer, responded to the group in a message that dismissed the story. "While the requirement for site visits is true, contrary to rumors, ChoicePoint is not performing site visits that require photographs or access to sensitive facilities," she wrote.

But the photo request was no mere rumor. DiBattiste acknowledged that ChoicePoint's checklist for site inspectors did include internal photos. But she said she ordered it not apply to customers in government and law enforcement because photos could endanger the offices' security. Apparently, she said, the Corona police got their call before the policy had been rescinded. She said she did not believe any police agencies actually had the inside of their offices photographed, though she added: "I can't guarantee that 100 percent."

ChoicePoint had inspected some customers who got personal data in the past, but stepped up the system after February's identity-theft disclosure, one of many high-profile data breaches to surface this year. That fraud — which resulted in at least 750 identity-theft cases — sent ChoicePoint's stock tumbling 24 percent in the ensuing weeks. About two-thirds of that lost value has been regained.

Many ChoicePoint customers now get inspections when they open a new account or re-sign a contract for sensitive data, DiBattiste said. Making the visits is necessary because "an identity thief could make believe he's the local sheriff in a town of 2,000 people," she said. The inspector does not access customers' computers or databases, she said. The auditor spends less than an hour confirming that the customer is legitimate and appears to have reasonable security practices.

DiBattiste wouldn't give specifics. But one thing the Corona police were told was that the inspector would need to ensure that workstations where ChoicePoint databases were accessed were not left unmonitored. Although ChoicePoint contends that few, if any, customers have defected rather than submit to inspections, DiBattiste acknowledged that the auditing is a work in progress. For one, ChoicePoint now lets customers apply for a waiver, which DiBattiste must approve, if they have a long relationship with ChoicePoint or already have been contacted recently by someone from the company.

As senior counsel with the Electronic Privacy Information Center, Chris Hoofnagle has been a ChoicePoint critic. He says the company deserves credit for its inspections, though he wants them to go further. "I think ChoicePoint should randomly audit users of the database," he said, "and make them show why they pulled a file of an individual."

The original article appears here.

-- MDT

Labels: ,

0 Comments.
Post a Comment
10/04/2005
GAO Finds SEC Slow to Distribute Fines
And speaking of the GAO...

Via Reuters:
Congress' Arm says SEC Slow in Disbursing Fines

Oct 3, 2005
Reuters

The U.S. Securities and Exchange Commission has returned to investors only a small fraction of the $4.8 billion collected under a post-Enron program for penalizing violators of securities laws and returning the money to those harmed, said a congressional watchdog on Monday. The Government Accountability Office (GAO), Congress' investigative arm, also criticized the SEC for shortcomings in efforts to track collections of fines imposed on violators, as well as for its management of stepped-up collection efforts.

The GAO said in a draft report that the SEC has vigorously exploited the Fair Fund program adopted by Congress as part of a reaction to the corporate scandals that started in 2001. The program gave the SEC new power to return to investors money paid out as punishment by corporate wrongdoers. "However, to date, only a small amount of the funds have been distributed. According to SEC, distribution is often a lengthy process … We also found that SEC lacked a reliable method by which to identify and collect data on Fair Fund cases," the GAO said in the draft report's findings.

The GAO said the SEC estimated that as of April 2005 it had designated $4.8 billion in penalties and disgorgements to be returned to harmed investors. But only about $60 million had been distributed and another $25 million was being readied for disbursement at the time of the GAO's review, the GAO said.

Pennsylvania Democratic Rep. Paul Kanjorski said he was pleased the GAO found that the SEC had made some progress on collecting fines, and that some Fair Funds had been disbursed. But he said, "I am deeply troubled by the difficulties the agency has encountered in expeditiously returning these funds to American investors." He and Massachusetts Democratic Rep. Barney Frank called for congressional hearings to be held on the issue. Both lawmakers sit on the House of Representatives Financial Services Committee, which oversees the SEC.
The original article appears here, courtesy ABC news.

The GAO has also recently chided the SEC for insufficient regulation of mutual funds as well as poor database security.

-- MDT

Labels: , ,

0 Comments.
Post a Comment

GAO Finds Government Contractor Database Flawed
Regular readers of The Daily Caveat are probably aware of my fandom of the GAO, the congressional oversite body for government spending and program implementation. GAO reports provide some of the most interesting reading to come out of the federal bureaucracy and often point the way to problems that don't filter their way into the mass consciousness until much later. One recent report may garner some attention, given the Bagdad on the Bayou theme that has started to emerge on editorial pages in the wake of Iraq-style no-bid contracts being awared for hurricane disaster relief projects.

The GAO recently published a paper [PDF required] highlighting the poor performace of the federal government's database of excluded constractors. The database is designed to prevent the rehiring of contractors who have been found guilty of past abuses of their government contracts. Federal agencies are obligated to check potential contractors against the database, in order to, in the GAO's own words,
"...help ensure excluded contractors do not unintentionally receive new contracts during the period of exclusion, the Federal Acquisition Regulation requires contracting officers to consult the Excluded Parties List System --a government-wide database on exclusions--and identify any competing contractors that have been suspended or debarred."
According to the Washington Business Journal, the GAO found that due to problems with the database, "Some government contractors that have been suspended or debarred because of past problems may be getting new contracts..." The GAO also found that, "Nearly 99 percent of the records in the database do not include contractor identification numbers, a GAO sampling found. Without that number, agencies have to search the database by the contractor's name. Some contractors may slip through the cracks if their name has changed, according to GAO."

The GAO describes the problems a bit further in their report summary:
"...as of November 2004, about 99 percent of records in EPLS for the 6 agencies we reviewed in depth did not have contractor identification numbers--a unique identifier that enables agencies to conclude confidently whether a contractor has been excluded. In the absence of these numbers, agencies use the company's name to search EPLS, which may not identify an excluded contractor if the contractor's name has changed. Further, information on administrative agreements and compelling reason determinations is not routinely shared among agencies. Such information could help agencies in their exclusion decisions and promote greater transparency and accountability."
Check out the full Washington Business Journal article here. The GAO report summary is located here and the full report can be found here. Warts and all, the Federal Contractors Abuse Database is searchable here.

-- MDT

Labels: ,

0 Comments.
Post a Comment
9/14/2005
Sycamore Networks Reveals Employees Flasified Records
Via TelephonyOnline.com:
Sycamore: Former employees falsified records

By Ed GubbinsSeptember 13, 2005

Sycamore Networks filed restated financial reports for the fiscal years 2000 through 2004 to increase net losses this week, after an internal investigation of stock option grants issued between 1999 and 2001 revealed that some employee records were deliberately falsified to affect the value of stock option grants. According to documents filed by Sycamore with the U.S. Securities & Exchange Commission, that internal investigation showed that the start dates on six employee records were “deliberately modified” to yield a lower exercise price for their stock options, Sycamore said, and six existing stock option grants were deliberately cancelled and reissued to allow a lower exercise price.

The investigation also focused on options that were granted under an April 14, 2000 program in which the number of options granted was probably not determined until April 26, 2000. The company also failed to record accurate charges for three stock option grants that continued to vest after the owner’s employment status changed. And one stock option grant was improperly reported in an inadvertent accounting error. “The employees directing the stock option program in the period from 1999 to 2001 are no longer employed by the company,” Sycamore said in the filing.

In June 2001, Sycamore offered its employees a chance to exchange their existing stock options for a tenth as much restricted stock. The company exchanged 17.6 million options for 1.7 million shares of restricted stock, recording $12.6-million in deferred compensation in the process. However, in the first and last quarters of its 2002 fiscal year, the company laid off a total of 464 employees, and some of that restricted stock was cancelled, as restricted stock was subject to forfeiture if an employee left the company before the stock vested. Therefore, the $12.6-million in deferred compensation was reduced to $7.3 million. Six months later, when the company expected to grant options to purchase 15.9 million shares, they instead granted 12.6 million, as a result of the workforce reductions.

When the original stock options were exchanged, the company stopped reporting compensation costs for them. The value of the restricted stock offered in exchange was calculated as of the dates they were granted and recognized over their vesting periods. “This treatment was incorrect since it failed to also include the unamortized stock compensation balance that remained on the original stock options,” Sycamore said. As a result, the company restated its compensation expenses for 2004, 2003 and 2002 with increases of $94.4 million, $110.1 million and $187.5 million, respectively.

The restatement had a negligible effect on Sycamore’s earnings for the 2004 fiscal year (which ended July 31, 2004), but it increased the company’s net loss for the fiscal years 2001, 2002 and 2003 by $29.9 million, $1.6 million and $0.8 million, respectively. Sycamore said it has taken several steps to correct the weaknesses in its accounting practices revealed by the investigation. It adopted a process to certify employee start dates, it revoked the stock administration group’s access to the stock option database and it rescinded the power of executive officers to authorize broad-based stock option grants. In addition, in July 2003, stock administration duties were placed under the direct supervision of the corporate controller.
The original article appears here.

-- MDT

Labels:

0 Comments.
Post a Comment
9/07/2005
New Copyright Office Database to Launch Oct 1
The ever indispensible Virtual Chase had a note recently about the launch of a new public database being launched by the U.S. Copyright Office. The new resource, called eCO Search will be searchable for all mander of copyright documents dating back to 1978. The new database will most likely resude here where the Copyright Office offers a few additional details:
eCO Search offers new features including keyword searching and the use of a single database containing records for monographs, serials, and recorded documents. All of the approximately 20 million records for registrations and recorded documents in the current system will be migrated to the eCO Search database, a similar system used by other parts of the Library of Congress for searching collections.

Should be a great resource. The original Virtual Chase post can be read here.

-- MDT

Labels:

0 Comments.
Post a Comment


all content © Michael D. Thomas 2010