Feeds

Microsoft frisked blogger's Hotmail inbox, IM chat to hunt Windows 8 leaker, court told

Ex-employee charged with revealing trade secrets

The Power of One Brief: Top reasons to choose HP BladeSystem

An ex-Microsoft worker faces criminal prosecution in the US over allegations he leaked work-in-progress Windows 8 software to a French blogger.

Russian national Alex Kibkalo was arrested in Seattle, Washington, on Wednesday, charged with the theft of trade secrets, and held in custody without bail.

Kibkalo, who worked for Microsoft in Lebanon and Russia, allegedly gave his employer's confidential files to an unnamed blogger, according to a criminal complaint [PDF] filed by prosecutors.

The French blog writer had a particular interest in posting screenshots of pre-release versions of the Windows operating system.

In the complaint, an FBI special agent revealed details of an internal probe by Microsoft's anti-leak team, dubbed the Trustworthy Computing Investigations department, following a tipoff from a source: it's claimed the firm looked through its servers and uncovered evidence that Kibkalo had emailed the blogger's Microsoft-hosted Hotmail account to leak "proprietary and confidential trade secrets."

Grab of the complaint PDF

Email accounts probed ... the relevant passages from the Kibkalo allegations describing how Microsoft's Trustworthy Computing Investigations (TWCI) team was tipped off about the blogger's Hotmail address prior to accessing it for clues (click to enlarge)

The confidential data was allegedly shared via Kibkalo's personal Windows Live SkyDrive account between July and August 2012 while he was still an employee. The cache was said to have included pre-release software updates for Windows 8-powered devices, a copy of the Microsoft Activation Server Software Development Kit, and unreleased versions of Windows Live Messenger.

Access to the development kit would be a boon for hackers trying to reverse-engineer the code used to thwart software piracy, the court in Washington was told. The alleged theft of the activation server software is the subject of the trade-secret theft charge against Kibkalo.

The defendant, who was based in Lebanon at the time of the alleged leak, apparently used a virtual machine on a Microsoft-hosted server to facilitate the transfer of the purloined files. This data was offered to the blogger in emails sent from a mail.ru account to the writer's Hotmail inbox, the court was told. The pair nattered about the illicit exchange using Microsoft's MSN chat system, it was claimed.

The alleged use of Microsoft's communications and storage technology for such an exercise was a dumb move as it made it easier for Redmond's sleuths to piece together their case: the software giant, on its own initiative, leafed through the blogger's Hotmail account and instant-messenger chatter logs in a bid to out the leaker, according to special agent Armando Ramirez's report to the court.

The company's investigators reckon Kibkalo turned against Microsoft after scoring a poor performance review after working for the firm for seven years. The Redmond sleuths confronted him in September 2012, and then went to the FBI with their evidence the following July.

The software architect, who is no longer a Microsoftie and was working for a US-based company at the time of his arrest, is also suspected of leaking Windows 7 files to a blogger he initially met on an online forum, the Seattle Post-Intelligencer reports.

The blogger implicated in the case reportedly admits publishing the information he received as well as selling Windows Server activation keys on eBay.

"We take protection of our intellectual property very seriously, including cooperating with law-enforcement agencies who are investigating potential criminal actions by our employees or others," a Microsoft spokesman said in a statement to reporters.

The case is filed as USA v. Kibkalo in the Western District of Washington. ®

Bootnote

Would-be whistleblowers, or anyone sensitive about their privacy, take note: the terms of service for Hotmail and other Windows Live things includes the line: "You consent and agree that Microsoft may access, disclose, or preserve information associated with your use of the services ... [to] protect the rights or property of Microsoft or our customers."

Designing a Defense for Mobile Applications

More from The Register

next story
Adam Afriyie MP: Smart meters are NOT so smart
Mega-costly gas 'n' 'leccy totting-up tech not worth it - Tory MP
'Blow it up': Plods pop round for chat with Commonwealth Games tweeter
You'd better not be talking about the council's housing plans
Arrr: Freetard-bothering Digital Economy Act tied up, thrown in the hold
Ministry of Fun confirms: Yes, we're busy doing nothing
ONE EMAIL costs mining company $300 MEEELION
Environmental activist walks free after hoax sent share price over a cliff
Help yourself to anyone's photos FOR FREE, suggests UK.gov
Copyright law reforms will keep m'learned friends busy
Apple smacked with privacy sueball over Location Services
Class action launched on behalf of 100 million iPhone owners
UK government officially adopts Open Document Format
Microsoft insurgency fails, earns snarky remark from UK digital services head
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.