The co-founder of Aspiration, Joseph Sanberg, was sentenced to 14 years in prison on Monday after defrauding investors and lenders of over $248 million.
The startup, an eco-friendly digital banking company boasting fossil fuel-free investments, carbon offsets for gas purchases, and a debit card with cash-back benefits for shopping at clean companies, was founded by Sanberg and Andrei Cherny. Cherny left the company in 2022 and has not been charged.
Sanberg, an Orange County native, pleaded guilty to wire fraud in October after being arrested in March last year. Aspiration subsequently filed for bankruptcy and liquidated all of its assets by July.
Sanberg and venture capitalist Ibrahim AlHusseini, who also faces charges, together forged a series of bank statements in order to obtain loans. From 2020 to 2021, the pair forged AlHusseini’s bank statements to show millions of dollars in…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
