An IT employee, Ashley Liles (28), was sentenced to over three years in prison for attempting to blackmail his former employer during a real-life ransomware attack that targeted the company.

Liles, who worked as an IT security analyst at an Oxford-based company, exploited his position to steal the money the ransomware after a successful attack on the company.
To defraud the company and his employer, he impersonated the ransomware gang that was blackmailing them and attempted to redirect the ransom paymentsby switching the ransomware gang's cryptocurrency wallet to another one under his control.
See also: Spain: Authorities arrest Ukrainian hacker for scareware attacks
“Unbeknownst to the police, his colleagues and his employer, Liles launched a separate and secondary attack against the company,” the initial press release from the Regional Organized Crime Unit (SEROCU) states.
“He accessed a board member’s private emails over 300 times, and altered the original extortion email, changing the payment provided by the original attacker”.
Authorities also say the former IT employee created an email address that closely resembled the one used by the attackers, using it to mislead the employer and put further pressure on him to ensure he received the ransom.
Despite this, the company refused to pay the ransom to the attackers (or indeed to the employee who had changed the crypto address), and during this period internal investigations revealed that Liles had access to confidential emails from his home.
See also: Hacker believed to be a member of the OPERA1ER group arrested
Liles tried to escape by erasing all data from his personal devices when he learned of the investigations, but SEROCU investigators seized computer and found incriminating evidence.

Liles initially denied the charges, but during a recent hearing at Reading Crown Court, he finally pleaded guilty. He was sentenced to three years and seven months in prison “for blackmail and unauthorized access to a computer with intent to commit other offences.”
Under UK law, unauthorized entry into a computer can result in a prison sentence of up to two years, while blackmail is punishable by a maximum sentence of 14 years.
See also: Singapore: Suspects arrested for Android banking malware fraud
The imprisonment of the former IT employee and other hackers highlights the serious consequences of cybercrime. Cybercrime can harm businesses, individuals and society in general and carries significant penalties. This IT employee took advantage of his knowledge and position in the company and tried to use, to his advantage, a real attack that targeted his company. This incident shows us that many times, threats do not only come from outside!
Source: www.bleepingcomputer.com
