Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Apple Worker Arrested On Kickback Charges

Paul Shin Devine allegedly disclosed company secrets to Asian suppliers in exchange for payments of more than $1 million.

An Apple worker has been arrested on charges he allegedly took kickbacks of more than $1 million over a period of several years from the company's Asian suppliers in exchange for inside information about the iPhone maker's product lineup.

A federal grand jury has indicted Paul Shin Devine, 37, of Sunnyvale, Calif., along with Singapore-based alleged accomplice Andrew Ang, on 23 counts of wire fraud, money laundering, receiving kickbacks, and other charges, according to the San Jose Mercury News, which first reported the story on Friday.

Apple has also filed a civil lawsuit against Devine, who was a supply-chain manager at the company.

The investigation was led by agents from the Internal Revenue Service and the Federal Bureau of Investigation. An Apple spokesperson said the company is cooperating with the investigators.

"Apple is committed to the highest ethical standards in the way we do business," a spokesman told the Mercury News. "We have zero tolerance for dishonest behavior inside or outside the company," the spokesman said.

The newspaper reported that the companies that allegedly paid the kickbacks were not identified by name in the federal indictment. The indictment indicates they are based in various countries in Asia, including China, South Korea, Taiwan, and Singapore. The bulk of Apple's electronics manufacturing is done in those countries.

The vendors, which manufacture parts and accessories for the iPhone and iPod, supposedly benefited from the arrangement as, armed with insider information, they were better able than their competitors to tailor their products to Apple's needs and anticipate future demands.

Devine and Ang allegedly established an elaborate series of front companies and offshore accounts to cover up income received from the scheme. Devine is set to appear Monday afternoon in U.S. Northern District Court in San Jose to face the charges.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
6 Small-Business Password Managers
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/8/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11931
PUBLISHED: 2019-11-14
A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prio...
CVE-2019-18980
PUBLISHED: 2019-11-14
On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The o...
CVE-2019-17391
PUBLISHED: 2019-11-14
An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in the first stage bootloader of the ESP32 chip allows an attacker (with physical access to the device) to read the contents of read-protected eFuses, such as flash encryption and sec...
CVE-2019-18651
PUBLISHED: 2019-11-14
A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote attackers to execute malicious and unauthorized actions (e.g., delete application users) by sending a crafted HTML document to a user that the website trusts. The user needs to have ...
CVE-2019-18978
PUBLISHED: 2019-11-14
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.