The head of information security at a U.S. company that runs lotteries is alleged to have gained access to the secure room where computers generate the numbers used for the drawing. He is said to have won more than $14 million as a result.
Breaking in was difficult even for him, as the room was a glass enclosure accessible only to two people at a time. He was officially granted access to adjust the time on the computers, and at exactly that moment the security cameras stopped recording continuously. Normally they did, and the IT professional was one of the few who could change those settings.
Self-destructing rootkit
The IT professional is alleged to have used a USB stick with an algorithm that allowed him to choose the “random” numbers. That software was not found on the computers that generated the random numbers. But according to prosecutors, the man boasted that he had built a self-destructing rootkit.
The scheme went unnoticed for a long time because lottery employees are not allowed to play themselves. A month after “the time was adjusted,” the information security officer secretly bought a ticket on which he could choose the numbers himself. He tried to cash in the $14.3 million he won almost a year later via a company in Belize. He was arrested in January 2015.
Authorities earlier released a video of the man buying the winning ticket in an effort to identify him.