A former developer at Eaton, a power management company, has been sentenced to four years in prison for installing malware on the company’s servers.
The court’s decision came after Davis Lu, aged 55, had spent over a decade at Eaton, where he advanced to the role of senior developer.

Following a company restructuring that led to his demotion, Lu took drastic measures by creating a “kill switch” designed to activate if he lost access to the company’s network.
The malware he developed was a Java program that created an increasing number of threads in an endless loop, ultimately consuming enough resources to crash the server.
Acting Assistant Attorney General Matthew Galeotti from the Justice Department’s Criminal Division stated that Lu betrayed his employer’s trust by leveraging his access and technical skills to damage company systems, resulting in significant financial losses.
Despite his technical background, Lu’s actions were poorly executed, as he named his malware IsDLEnabledinAD, which stands for “Is Davis Lu enabled in Active Directory.”
He also used his corporate credentials to upload the malware, demonstrating a lack of basic operational security.
After Eaton terminated Lu’s employment on September 9, 2019, and revoked his network access, the Java program he created was triggered.
This caused severe disruptions, preventing thousands of employees worldwide from logging in and leading to the loss of some corporate data. When Lu was required to return his corporate laptop, it revealed that he had been using it to carry out his malicious plan.
Investigators found that he had searched for ways to delete data, gain higher access privileges, and hide his activities, along with having deleted a significant amount of encrypted information.
Less than a month after the malware incident, federal agents arrested Lu. Although he confessed to his actions, he still chose to go to trial.
Unfortunately for him, a federal jury in Cleveland found him guilty of intentionally damaging a protected computer. He received a four-year prison sentence along with three years of supervised release.
Brett Leatherman, assistant director of the FBI’s Cyber Division, expressed pride in the work of the FBI cyber team that led to Lu’s sentencing.
He emphasized that this case serves as a strong warning to anyone thinking about engaging in similar illegal activities. It also highlights the need for organizations to identify insider threats early on.
As reported by reporters, insider threats can inflict significant damage with relative ease. Advanced firewalls, artificial intelligence tools, and malware monitoring systems are not enough to protect an organization if the individual managing them decides to act maliciously. Eaton has chosen not to comment on the sentencing.
Other Stories You May Like