7 ms·
Ask HN: If your SaaS was used to commit a financial crime, what should you do?
Hypothetically, if your Solo-Founder SaaS was used a suspicious customer based in Russia to access a USA financial institution.
- mrintellectual 5y agoHypothetically, you should report what happened and hire an attorney ASAP.
- jffry 5y agoBut not in that order. Hire the attorney, and ask them about whether and how and where to report. An attorney will know how to navigate this in a way that protects you.
- Laura69 5y ago[flagged]
- DrWhax 5y agoYou can always reach OCCRP securely using our Securedrop instance: https://www.occrp.org/en/become-a-whistleblower/ https://www.occrp.org/en/become-a-whistleblower/ You might know us from the recent SuisseSecrets (https://www.occrp.org/en/suisse-secrets/ https://www.occrp.org/en/suisse-secrets/) as well as covering russian laundromats through european banks: https://www.occrp.org/en/laundromats/ https://www.occrp.org/en/laundromats/ you can also reach out through jurre[@] occrp dot org
- dc-programmer 5y ago1. Delete this post 2. Lawyer up
- steve_g 5y agoContact your favorite lawyer first.
- milesdyson_phd 5y agoSeek counsel prior to anything else
- AlwaysRock 5y agoYeah take this post down and contact a lawyer who specializes in financial crimes. You shouldnt be taking legal advice from the internet.
- cellis 5y ago> You shouldnt be taking legal advice from the internet. Why not? I always find this "don't take advice from non-lawyers" to be annoying when I've listened to a lot of really idiotic theories by lawyers. And who knows, you might also find some lawyers right here on HN.
- elil17 5y agoA lawyer has attorney-client privilege. Writing a HN post, on the other hand, produces public evidence which could be used against you in court.
- torstenvl 5y agoThere are indeed plenty of us here on HN. But you still shouldn't take legal advice from the Internet. There are only two possible outcomes to such a thing: (a) you are not entirely forthcoming about all potentially relevant details in that public forum and therefore the advice cannot be relied on in your particular situation; or (b) you are entirely forthcoming about all potentially relevant details in that public forum and therefore you've waived at least some of the protections of confidentiality and privilege.
- dragonwriter 5y ago> > You shouldnt be taking legal advice from the internet. > Why not? Lack of expertise. Likelihood of conflict of interest. Lack of accountability. Lack of (because you almost certainly won't be willing to disclose enough, and if you did that has its own problems for your legal situation in many case) adequate information about the relevant facts. (That's not to say you can't get legal information on which you can follow up from the internet, but there is a big difference between that and legal advice.)
- csee 5y ago
- themodelplumber 5y agoKeep your notes on it handy. Contact your legal rep or team. When something similar happened to me I was eventually contacted by the California computer crimes task force, IIRC. Very simple phone call, asking for notes I kept on the situation. Polite. Then I got looped into the prosecution's long and kind of annoying email chain to everybody involved before there was an eventual going-nowhere of it all. Surprising but that's what happened. So you never know but some basic diligence is typically a good idea. This is not legal advice.
- cjf4 5y agoHire a lawyer.
- deleted 5y ago[deleted]
- danso 5y agoI wouldn't leave this up
- low_common 5y ago
- ackbar03 5y agoIs it inappropriate to say that I'm jealous your SaaS is good enough to be used by Russians for financial crime? I mean your gonna take this post down anyways right?
- prichino 5y agoWhy do you care? Don't assume and ask a lawyer. Ban the user for not following TOS and should be good
- elliekelly 5y agoThis is terrible advice. When there is a US financial institution and a country currently subject to sanctions involved there could be OFAC/AML/BSA implications. In some instances there is an affirmative obligation to report suspicious activity. And depending on what (if any) PII was accessed there could also be an affirmative obligation to notify impacted customers or state AGs. Hiring a lawyer (where OP can give a full a candid disclosure of all relevant facts) is the only reasonable advice OP can get. Maybe it's absolutely nothing and OP can ban the user for TOS violations and be done with it. But maybe it's not. No one here has enough information to make that assessment with any degree of certainty whatsoever.
- deleted 5y ago[deleted]
- 8bitbuddhist 5y agoI wouldn't leave this up. Maybe create a retrospective post once the case is over if you want to help others, but don't share details (even minute details) publicly until you've talked to a lawyer first.
- gnicholas 5y agoIf you email hn@ycombinator.com, they may be willing to take this down for you, assuming you can't currently delete it on your own. I understand they do this very occasionally, when there is good reason to do so. Good luck!
- ASalazarMX 5y agoInteresting dichotomy between the people upvoting and the people recommending deletion. Surprisingly, no one has flagged this.
- chii 5y agoit's because this type of situation is interesting, and is often not talked about much publicly. The cost of information leak is borne by the poster, but the value of the information is gained by those readers. Thus, there's asymmetric benefit.
- jamal-kumar 5y agoif you needed a recommendation for legal representation: https://www.torekeland.com/ https://www.torekeland.com/
- conductr 5y ago> Mid-term, I am going to add detailed logging of all customer activity, and a workflow to analyze these logs. I'd recommend not changing anything about how your app functions until you follow the common advise here. Ask your attorney when you can make code changes. You may be destroying evidence even if it's just "the path they took"
- throwawaymanbot 5y ago
- _xnmw 5y agoHow can a solo founder SaaS "be used" to access financial institutions? Do you mean simply creating a bank connection through an API like Plaid? People in Russia may have bank accounts in the US, you know?
- lesbianbezos 5y agoWhat are you trying to do?
- _xnmw 5y agoAs a fintech founder myself, I'm trying to understand how on earth a SaaS can be used to commit a financial crime. Is this a hacking tool?
- stets 5y agodelet this op
- tempnow987 5y agoIgnore all the folks saying don't ask this question. Dealing with fraud / abuse issues is not uncommon. Generally you do a few things. If something makes you feel uncomfortable, and your agreement allows it, close out the customers account. Just like facebook / google and friends, I've found it better NOT to get into a lot of back and forth or just point to a generic policy (ie, overseas accounts not supported). If you need to refund money, make sure you only refund to same payment method. Ie, a credit card refund should not go out by check. I've seen scammers use this with a stolen card, then try and get the refund by check. A few months later card owner contests bill. If you refund back to same card, then when owner protests, the money is already back, nothing to protest. Consider a hold on funds if you are concerned that they will be returned to issuing entity if you a in the middle on a payment flow. If so you want to make sure your money handling stuff is compliant anyway with KYC and transfer licensing needs.
- dogman144 5y agoDump and save all your logs tied to this, and try to go back as far as possible as it pertains to this user and related infra they used. Start an excel sheet w/ <time>, <action done> and <result> on the headers, and log everything you do as part of figuring out what to do about this, i.e (Feb 17, asked what to do on hackernews, took advice and called a lawyer). Put it in a gdrive. Essentially, establish an audit trail of you doing the right thing once you realized what was going on. Get a lawyer involved, and then ring up the local cyber crimes unit and be prepared to dump all this evidence. There's a lot of interplay b/t security teams and law enforcement over this stuff so it's not unusual. They'll be happy you reported. Anyone can use a SaaS platform, worst case you might get a rude awakening on the need to do KYC/AML or some sort of user onboarding regulations that you weren't aware you had to follow. This is all about due diligence and if you did it once you knew you had to. Using intermediary infrastructure to dodge OFAC sanctions or w/e like this is isn't uncommon. The uncommon part is being able to get knowledge on the intermediary infra (your saas), so you're doing a solid by reporting it and providing logs.
- eddieh 5y agoCall the FBI! You shouldn't be talking about this publicly either. You could be compromising the future investigation.
- grue_some 5y agoThis is the main lawyer that handled PIA's (Private Internet Access) legal challenges: https://www.linkedin.com/in/jarsenault https://www.linkedin.com/in/jarsenault Being a VPN, they would get contacted about a lot of stuff like this. He is a decent guy from my personal experience and maybe he would be a good contact if you don't already have a lawyer handling this.
- smarri 5y agoSubmit a suspicious activity report to local law enforcement