Information Security 4 min read

How a Former Ops Manager Illegally Escalated Privileges to Steal and Sell Code Worth 8 Million Yuan

In a 2018 Beijing police operation, a former operations supervisor illegally raised his system permissions, downloaded three proprietary project source codes from a tech company, and sold them for nearly eight million yuan, leading to the arrest of two suspects after extensive digital forensic investigation.

Efficient Ops
Efficient Ops
Efficient Ops
How a Former Ops Manager Illegally Escalated Privileges to Steal and Sell Code Worth 8 Million Yuan

Under the coordinated "Clean Net 2018" initiatives of the Ministry of Public Security and the Beijing Municipal Public Security Bureau, the Haidian Police Department intensified efforts to maintain online order, combat hacker crimes, and protect the legitimate rights of internet enterprises. By integrating network and criminal investigation resources, they swiftly uncovered a case in which a former employee illegally elevated personal permissions, stole critical company data, and sold it for nearly eight million yuan, resulting in the arrest of two suspects.

On July 25, 2018, the Haidian Police Support Brigade received a report from a local technology company stating that on March 14, 2018, employee Chen, along with others, violated company policy by independently enabling multiple critical project permissions, downloading three internally developed project source codes, and selling them for profit. Chen, a former operations supervisor, used illicit methods to increase his system operation privileges, accessed a large amount of core code he was not authorized to view, downloaded it using his own account, and after leaving the company, exported the code for illicit sale.

The police promptly formed a special task force in collaboration with the criminal investigation unit. By analyzing the company's electronic logs, investigators discovered unauthorized backend database access, illegal privilege escalation for a specific account, and subsequent download of multiple core data sets. The team collected, examined, and preserved relevant evidence.

Through detailed electronic evidence analysis, investigators identified the suspect as the former operations supervisor Chen. After downloading the code, Chen colluded with others to sell it for substantial profit. With ample evidence, the task force arrested Chen and his accomplice Sun on September 6, 2018, at an office building in Shangdi, Haidian District.

During interrogation, Chen admitted that, under the direction of company supervisor Sun, he illegally elevated privileges to steal company data just before his departure and sold it for eight million yuan. Forensic examination confirmed that the illegally sold code matched the company's original source code.

Sun has been arrested on suspicion of copyright infringement by the Haidian Procuratorate, and the case remains under further judicial review.

Source: Capital Net Police Official Account.

Case Studyinformation securitychinaPrivilege Escalationcybercrimedata theft
Efficient Ops
Written by

Efficient Ops

This public account is maintained by Xiaotianguo and friends, regularly publishing widely-read original technical articles. We focus on operations transformation and accompany you throughout your operations career, growing together happily.

0 followers
Reader feedback

How this landed with the community

login Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.