Reuters journalist who allegedly conspired with Anonymous hackers is suspended

Filed Under: Featured, Law & order, Security threats

Matthew KeysA Reuters journalist has been indicted by a US federal grand jury for allegedly handing over the login credentials of his former employer, Los Angeles Times parent company Tribune Co., to people claiming allegiance to the hacker movement Anonymous.

Reuters.com, which currently employs 26-year-old Matthew Keys as a deputy social media editor, suspended him with pay on Friday.

An employee at the company's New York office said that Keys's workstation was being dismantled and that his security pass had been deactivated, according to subsequent reporting from Reuters.

The US Department of Justice announced the indictment [PDF] on Thursday.

Keys was indicted on three criminal counts:

  • Conspiracy to transmit information to damage a protected computer,
  • Transmitting information to damage a protected computer, and
  • Attempted transmission of information to damage a protected computer.

Prosecutors claim that Keys promised to give hackers access to Tribune Co. websites, and that one went on to deface a story on the company's Los Angeles Times website.

From a Department of Justice statement:

"Keys identified himself on an Internet chat forum as a former Tribune Company employee and provided members of Anonymous with a login and password to the Tribune Company server... After providing log-in credentials, Keys allegedly encouraged the Anonymous members to disrupt the website."

The exact wording of said encouragement, according to the indictment, being Keys telling the hackers to "go f**k some s**t up."

Part of indictment against Matthew Keys

On Thursday, Keys tweeted that he had found out about the indictment the same way most of us did: via Twitter.

The story told by court filings is of a disgruntled former employee who acted as a double agent with Anonymous hackers, working both with them and against them.

The case began in December 2010, when Keys allegedly provided the login credentials for a computer server belonging to KTXL FOX 40's corporate parent, the Tribune Company.

The indictment maintains that Keys identified himself on an Internet chat forum as a former Tribune Company employee and that he handed over a login and password for the server.

According to the indictment, the hacker ultimately defaced a Los Angles Time news story, changing its headline, byline and sub-headline to include the name "CHIPPY 1337".

Also, a line in the article was changed to read:

"House Democratic leader Steny Hoyer sees 'very good things' in the deal cut which will see uber skid Chippy 1337 take his rightful place, as head of the Senate, reluctant House Democrats told to SUCK IT UP."

The indictment further claims that Keys chatted with the hacker who claimed credit for the defacement, offering to try to regain access for him after system administrators fended off the hacker and locked him out.

When he learned of the hacker's ultimate success in defacing the Los Angeles Times page, Keys allegedly responded, "nice."

It's a long and twisty story, involving famed (and subsequently busted) former Anonymous top dog Sabu having outed Keys back in March 2011.

Buzzfeed has done a great job of pulling together all the intricacies of Keys's story, including an image of the defaced Los Angeles Times new story, a blog post from Keys about losing his job at the local FOX Affiliate in Sacramento, California, and more, including this statement from Keys's current employer, Thomson Reuters:

"We are aware of the charges brought by the Department of Justice against Matthew Keys, an employee of our news organization... Thomson Reuters is committed to obeying the rules and regulations in every jurisdiction in which it operates. Any legal violations, or failures to comply with the company's own strict set of principles and standards, can result in disciplinary action. We would also observe the indictment alleges the conduct occurred in December 2010; Mr. Keys joined Reuters in 2012, and while investigations continue we will have no further comment."

Will Keys get fired from Reuters? Should he?

Reuters logoBuzzfeed checked in with a Reuters employee who said that yes, if Keys is found guilty of divulging login credentials while at Reuters, he will have violated the company's Trust Principles, which is grounds for immediate dismissal.

What if Keys is found guilty of working with Anonymous only before Reuters hired him?

It's hard to imagine any reputable news venue countenancing the type of betrayal alleged in these charges.

If I were a Reuters editor or lawyer, I'd be finding ways to ensure Keys didn't come back from his suspension in the eventuality of a guilty verdict.

This case may look a little muddy given that journalists working undercover can act as double agents, but the fact is, Keys wasn't working for the news outlet at the time of the breach he allegedly helped to bring about.

As far as what non-journalists can take away from this, the lesson is this: priority No. 1 should be to shut down accounts for terminated employees.

Shuttering accounts should be a priority, but it often isn't.

You can't assume that a disgruntled former employee won't open up your systems to spammers, plant malware, or replace the CEO's presentation with porn.

If found guilty, Keys is looking at a maximum of 10 years in prison and a fine of up to $250,000.


, , , , ,

You might like

4 Responses to Reuters journalist who allegedly conspired with Anonymous hackers is suspended

  1. Keith · 499 days ago

    He'll be canned if he's found guilty. He'll lose his job not because he violated some corporate honesty program but because Reuters won't be able to trust that he won't do the same thing to them. I'll go one step further and say that if he's found not guilty he will keep his job but be monitored heavily for a while.

    One would think that a social media editor would have a better understanding of appropriate things to type into a chat room.

    The whole issue about Tribune not removing credentials when an employee leaves is ridiculous in this day.

  2. Charles · 499 days ago

    I appreciate the article, but there's a lot of sensationalism going on here. #1, I don't see where any actual "hacking" took place. Company failed to disable it's login. Disgruntled guy gave login info to a chat room full of people who could be "Anonymous", FBI agents, or whoever. Some guy used the login info to "tag" an article, and then they talked about it afterwards. No hacking. We've had these "disgruntled employee" issues as long as there's been employees with computers. #2, we're seriously going to destroy a guy's life and put him in prison for a decade because he posted a login on the internet? Yes, Keys should be fired and summarily ridiculed, threatened with legal action within an inch of his freedom, maybe given a misdemeanor and a fine. But if he actually spends time in prison for this it will be a total waste of taxpayer's money.

  3. herzco · 499 days ago

    "Will Keys get fired from Reuters? Should he?"

    Hopefully yes!

  4. Guest · 499 days ago

    Normally when an employee leaves a company logins and passwords are changed. Way to go Tribune/LA Times.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

About the author

I've been writing about technology, careers, science and health since 1995. I rose to the lofty heights of Executive Editor for eWEEK, popped out with the 2008 crash, joined the freelancer economy, and am still writing for my beloved peeps at places like Sophos's Naked Security, CIO Mag, ComputerWorld, PC Mag, IT Expert Voice, Software Quality Connection, Time, and the US and British editions of HP's Input/Output. I respond to cash and spicy sites, so don't be shy.