A California man accused of eluding authorities across the country, through an alleged scheme of identity theft and passport fraud, is facing several related charges in Maine’s federal court.
Matthew Charnay, 40, was indicted in U.S. District Court in Portland last fall on five felony counts, including aggravated identity theft, false statements in passport applications, and false representation of a social security number. Charnay is also accused of using the aliases “Andros Vassilikos” and “Erik Meyer,” according to court records.
Over the last six years, prosecutors believe Charnay has operated under at least four false identities, including those he stole from two individuals, whose names he later changed in…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
