3 ms·
The article also says > JPMorgan became interested partly because of the potential it saw in Frank’s supposedly huge list of satisfied clients. The bank believ
by ipsento606 2y ago
The article also says
> JPMorgan became interested partly because of the potential it saw in Frank’s supposedly huge list of satisfied clients. The bank believed those future college graduates could become lifelong bank customers
Generating a fake user accounts database would only conceivably work if you expected the purchaser to never attempt to contact any of the business's users, which seems a ludicrous expectation.
- irjustin 2y agoThe problem fundamentally is during a sale you don't get access to the actual DB. DD you typically only get a subset of data, so whoever you contact or even physically visit, it all could be fake people answering the phone or even at a fake address impersonating whoever they need to. For $175m of fraud, it's definitely worth to set that up. The core problem here is - the US lacks the ability to realtime verify identity against a centrally government controlled DB. US would never allow this under privacy rules, but that's what it would take to really identify a particular person.
- stevage 2y ago> the US would never allow ... Any sentence of this form needs to be treated with the utmost skepticism these days.
- noisy_boy 2y agoI find it hard to believe that there are no third party providers that can do such spot checks by selecting a random sample from the data under an NDA.
- irjustin 2y agoNot one where you can guarantee the actual person. Having SS number doesn't get you contact details and thusly at the mercy of the one who wants to fraud you
- phonon 2y agoThey did have a third party "verify" the data, Acxiom. https://fortune.com/2023/04/11/synthetic-data-millennial-founder-charlie-javice-frank-jpmorgan-fake-customers-fraud-trial/ https://fortune.com/2023/04/11/synthetic-data-millennial-fou...
- noisy_boy 2y agoThanks for the link: > At JPMorgan’s insistence, Javice said, she completed the task “over a couple of days and nights.” The professor uploaded Frank’s “customer list”—which now contained the synthetic data—to Acxiom on the morning of Aug. 5, the bank said. Acxiom analyzed the data and provided its report to JPMorgan later that evening. Acxiom destroyed the underlying data as its contract required, Javice said. Three days later, on Aug. 8, JPMorgan agreed to buy Frank for $175 million. Acxiom declined comment. Analyzed the data and gave report the same evening? What the hell? How on earth Acxiom is not on the hook? Is incompetence a defence? And how can they avoid going bankrupt if they choose that defence because nobody will give any work to a company that admits it? I'm now more intrigued about the Acxiom side of story.
- lemax 2y agoI'm not sure that's the "core problem", it sounds like companies should do diligence on a data asset if that's what they're after.
- irjustin 2y agoHow can you do diligence against it when you expect the other party to be defrauding you?
- fisherjeff 2y agoIn every deal, there’s a lot of trust involved leading up to closing that neither side is full of shit. Post-close, though, there is just no world in which a scam like this is not going to be (eventually) found out, and obviously there are legal remedies for that. I feel like this is, roughly speaking, the system working as intended: Minimal friction to avoid slowing down the 99.9% of deals that don’t involve fraud, and reasonable deterrence for the remaining 0.1%. I’m sure there are lots of ways to prevent deals like this from closing in the first place, but I doubt most are worth the cost.
- vkou 2y ago> reasonable deterrence for the remaining 0.1%. Given the Trevor Milton pardon, I wouldn't count on that. At this point, you can't rely on legal remedies, you just have to be lucky that the person fucking you over doesn't have the right kind of friends.
- fisherjeff 2y agoOkay that is very fair. But civil penalties do still likely mean you can claw a good amount of your money back if you catch the fraud quickly enough.
- DeathArrow 2y agoWere I a large investor buying something I would: 1. Ask them to let a few of my men to dig into the source code and database in their presence. 2. Hire a company to do investigations, speak with their employees, former employees, customers, investors and businesses partners 3. Use an escrow service, a trusted third party which will verify their claims 4. State in the contract that if the deal goes through and if I discover more than 1% of their claims is fake, they own me double the money But in this case, the article states JP Morgan was sent all the fake data. They just didn't care to verify it. That is either stupidity or JP Morgan have some careless employees which don't risk anything if their employer loses lots of money because they don't do their jobs, so it might be nepotism.
- phonon 2y agoThey did have a third party "verify" the data, Acxiom. https://fortune.com/2023/04/11/synthetic-data-millennial-founder-charlie-javice-frank-jpmorgan-fake-customers-fraud-trial/ https://fortune.com/2023/04/11/synthetic-data-millennial-fou...
- iamleppert 2y agoYou clearly have no practical experience because no company would agree to those terms. You can get access to source code, but the provision about “owe me double” is straight out of a comic book.
- mvdtnz 2y agoFraud doesn't stop being illegal at the moment of the sale, as you can see from this case.
- yieldcrv 2y agoThe thing that stands out to me about indicted and convicted fraud cases is how they always spell out “all you had to do was” Like with onecoin, all they had to do was have a blockchain and it would have been the same standard of non-indictable fraud as everyone else Here all she had to do was harvest from data brokers
- ameliaquining 2y agoShe did harvest from data brokers. The AP article doesn't really get into this, but the SEC complaint (https://www.sec.gov/files/litigation/complaints/2023/comp-pr2023-74.pdf https://www.sec.gov/files/litigation/complaints/2023/comp-pr...) explains: "Knowing that JPMC would have access to Frank’s real and much more limited student data after the close of the acquisition, Javice and another high-ranking Frank executive (the “Frank Executive”) began an effort to create a list of real names that they could pass off as Frank’s customers. To that end, the Frank Executive arranged for Frank to pay $105,000 to a third party data compiler for its in-college student data. Javice arranged for Frank to pay $75,000 to a different data compiler to augment the list the Frank Executive bought with email and phone number data."
- Centigonal 2y agoShe actually tried! In the original complaint, JPMC's lawyers wrote that Javice & Co generated their "user database" by securing a leads list from one data broker, and then turning around and asking a second data broker to enrich it with users' personal information to make it look like a customer list. She hired a college professor freelance to add in synthetic data wherever the data from the brokers was lacking. If the data brokers she worked with had high quality leads, maybe it would've taken longer for them to get caught. :p
- bambax 2y agoYes, absolutely. It is ludicrous. But I think the real reason is those people attempting fraud are fundamentally psychopaths: they can't think correctly about a future where they're being caught. They fix the present, one lie at a time, and get an immediate, narcissistic personal reward every time they fool someone. They also think rules don't apply to them, and most of the time they're right, as they most often get away with it.