22 ms·
Frank founder allegedly defrauded JPMorgan out of $175M hit with federal charges
- pg938hkd 3y ago[dead]
- Scubabear68 3y agoThe gist of what she is alleged to have done: “An internal investigation revealed that Javice and Frank chief growth officer Olivier Amar — referred to as "CC-1" in the federal charges — paid a New York data science professor $18,000 to create nearly 4 million fake accounts in order to juice Frank's user numbers, JPMorgan alleged in its lawsuit. Amar later bought a list of student email addresses from a marketing firm for $105,000 in order to make those accounts seem more credible, JPMorgan alleged”.
- PaulWaldman 3y agoDid they really pay a professor $18K to use a Faker library to generate 4 million records?? That's wild.
- eloff 3y agoIf they’re that incompetent that they need to fake their database and think it’s a good idea, there’s little surprise that they’re also too incompetent to realize that task is only a couple hours of coding.
- mostlystatic 3y agoYou pay extra to hide the crime: """ After the August 3, 2021 Zoom meeting, the Data Science Professor returned a signed version of Frank’s NDA. The Data Science Professor’s usual hourly rate was $300. Javice unilaterally doubled the Data Science Professor’s rate to $600. [...] Specifically, on August 5, 2021 at 11:05 a.m., the Data Science Professor provided Javice an invoice for $13,300, documenting 22.17 hours of work over just three days. The invoice entries show that the bulk of his time was spent on the main task that Javice retained the Data Science Professor to perform – making up customer data. The Data Science Professor’s invoice indicated that he performed “college major generation” and “generation of all features except for the financials” while creating “first names, last names, emails, phone numbers” and “looking into whitepages.” In response to the initial invoice, Javice demanded that he remove all the details admitting to how they had created fake customers – and added a $4,700 bonus. In an email to the Data Science Professor at 12:39 p.m. on August 5, 2021, Javice wrote: “send the invoice back at $18k and just one line item for data analysis.” In total, Javice paid the Data Science Professor over $800 per hour for his work creating the Fake Customer List, which is 270% of his usual hourly rate. The Data Science Professor provided Javice the revised invoice via email seven minutes later at 12:46 p.m., commenting “Wow. Thank you. Here is the new invoice.” """ https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rNlNVTl.6yh8/v0 https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/rNlNVTl....
- yowzadave 3y agoI wonder why the Data Science Professor isn't named/charged as an accomplice. Maybe they are acting as a witness for the prosecution?
- my_usernam3 3y agoPlausible deniability is my non professional guess
- skeeter2020 3y agoit sounds like his initial invoice was quite clear in the work completed, then updated at the client's request. So while you can argue moral grounds for not doing this work, I don't think there's illegality, i.e. conspiracy.
- pciexpgpu 3y agoI mean if you are a professor and knowledgeable in how the startup uses the data, it’s hardly justifiable that “oh crap i didn’t know they were using it for illegal purposes”. They were totally complicit allegedly.
- romellem 3y agoThis is spoken to [in the full complaint][1]. The data scientist was told Frank really did have 4 million users, and the scientist only needed to generate this "synthetic data" as a way to "anonymize" their "real" data. I.e. the scientist was duped: JAVICE told Scientist-1 [...] that she had a database of approximately 4 million people and wanted to create a database of anonymized data that mirrored the statistical properties of the original database (the “Synthetic Data Set”). [After JAVICE sends Scientist-1 the data], Scientist-1 understood that the data available via the Access Link Email - **a data set of approximately 142,000 people** (emphasis added) - was a random sample of a larger database which contained data for approximately 4 million people. In fact, that data represented every Frank user who had at least started a FAFSA. [1]: https://www.justice.gov/usao-sdny/press-release/file/1577861/download https://www.justice.gov/usao-sdny/press-release/file/1577861...
- bedatadriven 3y agoI read in an earlier report that their own developers refused to do the task. [1] Not clear if the professor knew what the fake data was being used for. [1]https://www.bloomberg.com/opinion/articles/2023-01-12/jpmorgan-says-frank-was-fraud https://www.bloomberg.com/opinion/articles/2023-01-12/jpmorg...
- dboreham 3y agoThat's pretty reasonable imho. Probably took several days of back and forth to establish what they wanted. Then a day to knock up the script, generate the output. Now several more days of back and forth about whether it's what they really wanted. Pad a bit for the risk that they never pay, possibility of legal action in the future, etc.
- josephd79 3y agoSo they paid someone 18k to just create a random list of fake email addresses? HAHA stupid
- vkou 3y ago1. It was way more than fake e-mails. 2. It's perfectly reasonable to ask someone to create a 'test' dataset for you. Just don't tell them that you're going full fraud with it. 3. People working for software firms get paid to create test datasets all the time. 18k for an outside one-time consultancy is not an insane number.
- BoorishBears 3y agoThe difference between software people and business people: Software People: Ha they paid 18k for fake emails! Business People: .. (nothing, they think nothing of spending 18k to push through a 175MM deal.)
- solalf 3y agoAmar’s LinkedIn profile description says: “ Enjoying what comes next” I guess it’ll be prison?
- ac29 3y agoSDNY press release here: https://www.justice.gov/usao-sdny/pr/former-start-ceo-charged-175-million-fraud https://www.justice.gov/usao-sdny/pr/former-start-ceo-charge...
- romellem 3y agoThis is what everyone should be reading, including their attached full complaint. A key piece of evidence is around whether Frank had 4.25 million users or 300k. Javice (Frank's CEO) alleges JPMorgan Chase (JPMC) is misrepresenting what she provided, saying she merely anonymized the data by making it "synthetic" to a third party for verification to avoid sending PII to JPMC before the deal closed. Here's the problem though: it (allegedly) wasn't anonymized data - it was fake data, and later when JPMC asked for the real data after the company was bought, Javice bought data for ~4 million students from a third party vendor for ~$100k, combined the data to build the "final database," and JPMC very quickly realized that most of the data was no good.
- crop_rotation 3y agoThe story is really wild. I read the Matt Levine take on it and it immediately reminded me of Theranos (off course not exactly identical, but still).
- A_D_E_P_T 3y agoFor what it's worth, the Matt Levine article is here: https://archive.ph/j5JBq https://archive.ph/j5JBq And it is a wild story! It's probably going to get the miniseries treatment. The Uber/Theranos/WeWork shows were pretty popular, after all, so I'd bet that a second batch is coming with FTX, Frank, and that Korean guy who went on the lam in Montenegro. Hah.
- tmpz22 3y agoThe titles write themselves. "Frankly fradulent" "When Frank tanked" "Frank robs the Bank"
- spartanliving4u 3y agowhat Korean guy?
- disqard 3y agoThey're probably referring to Do Kwon's arrest in Montenegro: https://www.bbc.com/news/technology-65058533 https://www.bbc.com/news/technology-65058533
- duxup 3y ago> began to question the authenticity of the startup's purported 4 million users after an email marketing campaign ended in "disaster," according to the bank's lawsuit and a filing by prosecutors. Out of 400,000 emails sent to Frank users, more than 70% bounced back and only 103 were opened, the bank claimed. This seems entirely inevitable since the emails were largely not actual customers… Very strange.
- koolba 3y ago$175M could have easily paid for a bunch of domains to run MX servers. You don’t even have to keep the email. Just accept it and send it to /dev/null. Maybe a fancier scam would be parsing for links and randomly fetching them with headless chrome. But I doubt that’d be required.
- gruez 3y ago> $175M could have easily paid for a bunch of domains to run MX servers. You don’t even have to keep the email. Just accept it and send it to /dev/null. You don't think it would be at all suspicious that most of the emails in the customer list are using weird custom domains rather than the popular ones like gmail.com or outlook.com?
- tommek4077 3y agoJust create a big email provider with that kind of money. You might even get a legimate business out of this ;)
- lordnacho 3y agoThat's it, you create an email provider that purports to be the place where young people go to get email, lining up your next sale.
- koolba 3y agoCould even end up like that movie plot where the bank robbers setup a bake shop next door to drill into the vault, but the front ends up being profitable.
- kasuki 3y ago[dead]
- ChrisMarshallNY 3y agoThis exact kind of fraud, is just what AI should be good for. I made 10K fake users for testing the app I'm developing now. I used thispersondoesnotexist.com, and about a half hour's worth of PHP programming, to make an open-ended user generator. I only need 10K users, and it takes about an hour or so to generate them, but I'm sure that this type of thing could be easily scaled. "Hey, ChatGPT, can you give me the SQL for five million users, with the schema published here?"
- kbos87 3y agoThis has non nefarious uses too. In a b2b context it’s often prohibitively time consuming to generate really good but non-real demo data.
- apercu 3y agoMakes boundary testing a lot easier.
- spop 3y agoI'm working on a platform that lets you generate fake users, but for the purpose of product research: https://notionsmith.ai/ https://notionsmith.ai/ You describe an idea and get very realistic users that you can chat with. Hooking that up to an email account could have been very convincing... Typing in Frank's elevator pitch: "Frank is a financial platform that helps college students manage their financial aid and student debt. Frank offers a free solution that allows you to streamline your FAFSA application, educates you about what FAFSA does and what parts of the application are important, and helps you potentially get additional money." Gives some cool results
- erik_seaberg 3y agoMaybe we need lorem ipsum but for a user profile table. No reason it should be unique if you aren’t trying to learn anything from statistics.
- throw_m239339 3y agoI mean you can go even further, you can use ChatGPT to make these fake people answer real emails from JP Morgan. You can completely fake people online. Of course JPM wouldn't have gotten any business from these bots, but it would have been harder to prove that these 4 millions emails were fraudulent. 100% Fake business, fake customers. $175M valuation. What I don't get is why JPM didn't realize that this company had no revenue, unless they completely cooked the books.
- bamazizi 3y agoReally surprised at lack duedeligenoe on the part of acquirers, JPM team!!! My immediate reaction to when JPM found out they'd be duped after running an 'email campaign' was, hmmm, maybe well deserved, should have done your homework! I want to put the blame solely on the executives, lawyers and team that drove the acquisition forward. Obviously we can open the floodgates of conspiracy theories. Maybe, some from JPM team may have been on this...
- deleted 3y ago[deleted]
- mostlystatic 3y agoI wondered about that when reading the Money Stuff article about it a while ago. What should they actually have done differently? One of the issues was that "she could not share her customer list due to privacy concerns". So maybe JPM could have pushed back against that more? """Javice also cited privacy concerns in sharing Frank’s customer data directly with JPMC. After numerous internal conversations, and in order to allay Javice’s concerns, JPMC agreed to use a third-party data management vendor, Acxiom, to validate Frank’s customer information rather than providing the personal identifying information directly to JPMC."""
- cldellow 3y agoI was involved in some diligence when a prior company was considering an acquisition. The numbers they claimed vs the numbers we could trust from their various SaaSes were pretty fishy. It was a small deal - more like $1M. We didn't pursue them, they don't exist any longer. The gap here was _huge_. If I was the JPM diligence team, I might have asked them for read-only access to their product analytics. They claimed something like 10K FAFSA applications/day. This should show up nicely in their analytics tools. Yes, they could fake these visits--but it would be much harder to fake that you're getting 10K visits from appropriate regions, at appropriate times of day, with appropriate dwell times, with appropriate distribution of completion rates.
- nradov 3y agoIn most jurisdictions it would generally be possible for the seller to hire outside counsel to validate customer metrics claims under attorney-client privilege without violating consumer privacy laws or customer agreements. The outside attorney could then provide a letter to the buyer attesting to what they found without revealing any specifics about individuals. Of course that would delay the deal, and the buyer here seems to have been irrationally eager to close the acquisition.
- jjgoldman 3y agoSounds very clearly that JPMC was defrauded, and at the same time did a very poor job of due diligence in a 9 figure acquisition. How did a financial audit not uncover the dramatic mismatch in actual vs. purported activity? How does a transaction value of $41 per user (x 4.25M users) not translate to an auditable revenue stream? This doesn't look good on either party.
- loandbehold 3y agoJavice interfered in due diligence in a very sophisticated way. JPMC tried to verify user data but Javice claimed they couldn't provide user personal information "due to privacy concerns". In the end Javice was able to convince due diligence team by engaging in multiple layers of fraud. Sure due diligence team could've done a better job, but Javice was a sophisticated adversary. It's not like due diligence team didn't have any concerns. But they wanted to balance their concerns against possibility of passing a good deal due to formality.
- mbesto 3y ago> JPMC tried to verify user data but Javice claimed they couldn't provide user personal information "due to privacy concerns". DD guy here. This is the most plausible explanation. When you're under LOI there is a lot of back and forth, which ultimately guide how the purchase agreement gets formulated. So if this was the case, then they would have made the trade off of "ok she's not letting us see the list, but we'll make sure the SPA is ironclad about this". Ultimately deals then get some money locked into escrow or RWI to soften the blow of the cost implication. At the end of the day, let's say you're JPMC and the company that you acquired did exactly what Javice did. You have an SPA that binds you legally (meaning, if they caught lying post close, they'll get sued), how on earth would you think someone was dumb enough to try to get through diligence, then operate the company post close, and NOT expect to be found committing fraud.
- symlinkk 3y ago[flagged]
- josephd79 3y agoWhen are people going to learn you can't "fake it until you make it" anymore. "Allegedly" She's going to go to jail now.
- oh_sigh 3y agoPeople really need to learn if you get a huge pay day via fraud, then take your cash and head over to a country on rocky diplomatic terms with the US and no extradition treaty, and be generous with your hosts.
- galacticaactual 3y agoPeople really need to learn to not do fraud.
- oh_sigh 3y agoWell, fraud has been happening for the entirety of recorded history, so that seems like a tough lesson to learn.
- mrbombastic 3y agoThis is one person who basically fabricated their entire user base and got a $175 million acquisition. They got caught because the degree of the fraud was egregious and obvious. JPM it seems didn’t do almost any due diligence. The lesson to me here is that there are probably plenty of people faking it until they make it and doing just fine.
- delfinom 3y agoWell you can, just don't try to pull that with a one of the biggest banks in the country.
- fn-mote 3y agoHow much due diligence really occurred here? I have no problem with charges being filed, but seriously... it's not like the buyer was some kind of low-budget mom and pop shop or community bank. I'm just not very sympathetic to JPMorgan for being scammed in a situation where being wary should be standard.
- mrbombastic 3y agoYeah I am always astounded at stories like this, you acquired a company for 175 million dollars and didn’t even peak at some real data?
- ffggvv 3y agothat’s pocket change for them. probably just file it under DEI budget for supporting a female founder
- fisherjeff 3y agoI mean from what I understand, they did peek at the “real data”, it’s just that it was convincingly fabricated.
- mrbombastic 3y agoWhen I say real data I mean data that was not handed to you by people who have 175 million reasons to fake it. Like another commenter added try to talk to some of their customers, in this case even trying to email them seems like it would have been enough.
- toss1 3y agoYou need to do more than "peek at" the real data, at least if you are buying a business for actual revenue and not for it's potential as an idea. You need to follow at least some threads all the way down to the ground truth. First, ask for 20 references of successful happy customers, talk to all of them, and do some verification. Then demand to see all the "real" data and select a random sample of 50 emails and track them all down to real people (or not), and ask the people at those endpoints what is going on. Yes, this would take a week for a handful of interns/junior employees and one senior staffer. But you are about to invest $175 million. It is worth a bit of actual effort, not just a bunch of handwaving over expensed dinners. This should be a career-ending move for anyone involved at Chase. ( Remember: should =/= is )
- meltyness 3y agoJPM is in private equity? That's concerning.
- delfinom 3y agoJPM has been trying to spread its roots into private equity and VC for a long time. You can bet your socks that they were giddy when SVB went under.
- postexitus 3y agoyes, but this was not private equity business - it was actually acquired to supplement the existing chase business(es) aiming at students.
- hunglee2 3y agoCrazy how a bad mail merge campaign was the trigger which ID'd the fraud - 400,000 emails sent, 103 opened, an open rate of....0.0002565%...
- datpuz 3y agoWhat was the end game here? Is there any universe where someone does something like this and gets away with it?
- ctvo 3y ago> What was the end game here? Is there any universe where someone does something like this and gets away with it? The Frank founder went to work for them after this closed. It doesn't look like she thought she did anything wrong here otherwise you'd think she'd get as far away from the mark as possible. When fake it until you make it and hustle culture goes horribly wrong.
- stefan_ 3y agoThe irony of this is if you google "JPMorgan indictment" you will find lots of criminals, getting away with it all the time.
- nradov 3y agoPeople get away with lesser versions of this type of scam all the time. Buyers don't want the bad publicity so if the loss isn't material then they just write it off and salvage whatever value they can find. You hear rumors about this kind of stuff that never shows up in the news, and when large companies buy startups it's even kind of expected that the financials are at least a little bit fake. This case was particularly egregious because the loss was material enough that even JPMorgan would have to publicly disclose it rather than sweeping it under the rug.
- mrmcd 3y agoPrevious reporting on this (when the JPM civil suit was filed) mentioned that JPM didn't care about the fafsa forms business at all. They bought them entirely to get a big pile of marketing leads to sign up young people for banking services early in their adult life before they're signed up with other banks, through a brand they're already familiar with. Considering how many "$200 to open a new checking account!!" junk mail fliers Chase sends me, $41/lead must've seemed like a bargain. She probably thought they would just be subsumed into a massive corporation, that JPM had shitty metrics and monitoring on their marketing campaign, and nobody would notice most of their emails were going nowhere.
- finfrastrcuture 3y agoFrauds like this one all-too-often wrap and camouflage themselves in some social good. Its so revolting, and brings down not only the cause but the people suffering from whatever the subject is (e.g. students applying for financial aid, cancer patients getting their blood tested, etc.) Its unfair and awkward but ventures which heavily push the mission like this one should be pushed harder on their fundamentals by the investor / startup community.
- dboreham 3y agoFirst: the worst name for a company ever? Is it a person named Frank? Or a founder with a frank personality? Or a story about the kind of sausage called a Frank? Anyway, wasn't there some business behind the supposed 4M users? You can fabricate 4M users in a csv file and insert them into your production DB, but shouldn't there be some revenue associated with those users, and couldn't the acquirers have looked to see if that revenue existed?
- jononomo 3y agoI don't understand this fraud. The whole point of a fraud is to try to "get away with it", but I'm missing that part of the story. What did this girl think was going to happen?