Very professional, the prosecutor put in real effort in handling the case
2025-03-19
The procuratorial organs of Fuzhou City attach equal importance to cracking down on crime and addressing the root cause in case handling, and build a 'firewall' to protect information security. At the same time, the prosecutors also discovered the problem of the relevant data storage media not being seized, and promptly blocked the loopholes through protests. Multiple measures were taken to ensure that enterprises can steadily move forward on the road of development, which is a vivid manifestation of 'handling every case with high quality and efficiency', "said the person in charge of a private technology company (hereinafter referred to as Company A) in Fuzhou City, Fujian Province, to a reporter from the Rule of Law Daily who came to interview. What made the person in charge of Company A express such feelings? Originally, Company A mainly engaged in digital asset security custody services, serving over 4 million clients and was awarded honors such as "High tech Enterprise" in Fujian Province. The occurrence of a major information leakage incident plunged Company A into crisis for a period of time. Yang once worked as a security supervisor at Company A and handled a large amount of confidential information. After resigning, he felt unhappy in his work and life and wanted to make "quick money" by stealing data from his original company. Starting from August 2023, Yang, who had resigned, illegally stole a large amount of server information from Company A by using the information he had acquired during his tenure, such as setting super passwords, without authorization. Soon, the technical personnel of Company A discovered through monitoring and early warning that there were a large number of abnormal information download records on Company A's server during a period of time. Digital assets have characteristics such as non exclusivity and ease of replication. Once they are stolen, their impact will spread exponentially. Due to Yang's good understanding of the company's internal security system, we are concerned that he may have retained some data after this incident occurred. Therefore, we hope to retrieve the relevant data to recover the losses The person in charge of Company A said. Company A immediately conducted an investigation and reported to the police. It is understood that Yang was arrested by the police in the month of reporting the case before he could process the stolen information. Through the joint establishment of the Investigation Supervision and Cooperation Office by the public prosecution authorities, the People's Procuratorate of Gulou District, Fuzhou City quickly learned about the situation of the case and immediately conducted consultations and judgments with the police to intervene and guide the investigation in advance, accelerate the progress of case handling, and strive to maximize the protection of user information security. This is the first time our company has encountered such a case, and we don't have much idea about how to cooperate with the case investigation at the moment The person in charge of Company A expressed confusion to the prosecutor in charge of the case, Lin Ting. In response to this, prosecutors and technical personnel jointly compared the content of the data information, clarified the classification and directory, and conducted a penetrating review and analysis of the relevant data from the system level, network connection level, and data level, promoting the accurate fixation of relevant evidence by investigative agencies and laying a solid foundation for case handling. On the other hand, Company A commissioned a professional organization to test and repair the relevant database. Because Yang is very familiar with our system, we need to modify the previous rules, "said the technical personnel of Company A. During the handling of the case, the Gulou District Procuratorate fully applied the criminal policy of balancing leniency and severity, which facilitated Yang to compensate Company A for the testing and database repair costs, and obtained the understanding of Company A. In July 2024, after being prosecuted by the Gulou District Procuratorate, Yang was sentenced to 3 years in prison, suspended for 4 years, and fined 10000 yuan for the crime of illegally obtaining computer information system data. Although Yang did not appeal, the prosecuting attorney found that the judgment did not address the seizure of the computer host and hard drive involved in the case. If these carriers containing data information are returned to Yang, it is very likely to cause information leakage, "Lin Ting said. In response to this, the Gulou District Procuratorate has put forward a protest opinion after research. After appraisal, Yang hacked into Company A's server through the computer host involved in the case, downloaded data from it, and saved it to the hard drive involved in the case. The computer and hard drive were tools used to commit criminal acts and belong to 'personal property used for criminal purposes'. The judgment should be handled in accordance with the law. And this case belongs to the omitted judgment item. According to the relevant provisions of the Criminal Procedure Law, we supported the appeal opinion proposed by the Gulou District Procuratorate in early September 2024 Introduction by Weng Linling, the handling prosecutor of Fuzhou People's Procuratorate. Quickly, the Intermediate People's Court of Fuzhou supported the appeal of the Fuzhou Procuratorate, and the relevant computer hosts and hard drives involved in the case were confiscated in accordance with the law. Blocked the risk of information leakage for Company A from the source. Although this case has been handled properly, there may still be a risk of information leakage for the company in its future operations. How should we respond The responsible person of the relevant enterprise expressed concern. In response to this, the Gulou District Procuratorate issued a risk warning letter to the enterprise in January 2025 based on the problems discovered in the case, proposing three normative suggestions for access control, system updates, and remote management, and doing a good job in handling the "second half of the case". It is suggested that our company's VPN (Virtual Private Network) has weak password issues and critical systems have not been included in the bastion machine management. These suggestions are very professional, indicating that the prosecutor has put in real effort in handling the case The person in charge of Company A praised it. At the same time, the Gulou District Procuratorate has been invited multiple times to visit the enterprise and conduct legal lectures on topics such as employee confidentiality system and trade secret protection, in order to enhance employees' awareness of confidentiality. At present, Company A has revised and improved its relevant systems in accordance with the content of the risk warning letter, and the company's safety management level has been significantly improved. (New Society)
Edit:Ou Xiaoling Responsible editor:Shu Hua
Source:Legal Dairy
Special statement: if the pictures and texts reproduced or quoted on this site infringe your legitimate rights and interests, please contact this site, and this site will correct and delete them in time. For copyright issues and website cooperation, please contact through outlook new era email:lwxsd@liaowanghn.com