8 ms·
>> A prosecutor, Micah Fergenson, though, said JPMorgan “didn’t get a functioning business” in exchange for its investment. “They acquired a crime scene.” I do
by TuringNYC 1y ago
>> A prosecutor, Micah Fergenson, though, said JPMorgan “didn’t get a functioning business” in exchange for its investment. “They acquired a crime scene.”
I do not understand how an acquisition this big got thru due diligence without noticing all the fake users. Anyone in corporate M&A know if it is normal to spend this much money without inspecting the goods? Seems like the most basic of OLAP queries and two days of effort would reveal very suspicious userbase.
- upupupandaway 1y agoOne previous company I was CTO of got acquired by Amazon and they spent 60 days going through everything, including every line of code. I doubt a fraud of this caliber would have gone unnoticed with that kind of due diligence.
- vjvjvjvjghv 1y agoSometimes I wonder if there is a lot of scrutiny in small things but when things get large and complex they basically give up and wave it through. I see a similar thing at my work in medical devices. In theory we have to validate all libraries we are using. So if you want to share some code you have to create a ton of documents. But when we use something like nodejs with hundreds of dependencies the whole process basically gets handwaved away because validating everything would be too much work.
- brandall10 1y agoIt's not that complex, there was nothing technical here. You could say this was 'social engineering' at some level. She pushed back against access to the customer list claiming privacy laws as a shield. JPMorgan was overly eager and didn't want to blow up the deal by challenging her.
- chatmasta 1y agoI wouldn’t be surprised if they waved it through because “who would be dumb enough to provide us a fraudulent list of customers?” She was always going to be discovered once they tried to market to the list. So I could see them speedrunning due diligence under the assumption that, if it’s totally fraudulent, it will be obvious eventually and then we’ll sue her. The deal is not large enough to affect our bottom line, and the obvious risk of defrauding us makes it unlikely she’s defrauding us.
- wat10000 1y agoIn programming, this is called bikeshedding. You present plans for some massively complicated industrial plant, and people will mostly skim it. Then you want to build a small bike shed for construction workers to use during the project, and now that they're presented with something understandable, everyone involved has to have input and the whole process drags out.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- jlarocco 1y agoThe article says the judge called them out for not doing enough due dilligence. The fact that they didn't do enough research doesn't mean it's okay to scam them, though.
- ajross 1y agoRight, it doesn't change the direction of criminality. But nonetheless JPM is out that money regardless (maybe some will get clawed back, but probably most of it was spent). "I got scammed and the perp is going to jail" isn't a good excuse to tell your boss about you lost $175M, either. Lessons abound here. Slow down on the tech habit folks, especially if you're an investment bank and not a VC incubator.
- fsckboy 1y ago>JPM is out that money regardless ... probably most of it was spent an MBA entrepreneur who starts a business and sells it to you for $175 million through normal channels is not likely to spend the money. this wasn't a fund wiring scam.
- HWR_14 1y agoUnless they spent it on crypto or buying property in a country that won't let you claw it back.
- deleted 1y ago[deleted]
- yokumfloster 1y agoShe never had the full proceeds in her possession. Remember, she had investors. She was venture-backed startup. She likely only had somewhere between 10% and 25% of the equity at the time that she sold the company.
- TuringNYC 1y ago>> She never had the full proceeds in her possession. Remember, she had investors. She was venture-backed startup. She likely only had somewhere between 10% and 25% of the equity at the time that she sold the company. How does this work for the VCs? Does JPMorgan claw back money from the VCs? What if the VCs distributed to their LPs...does money get clawed back from the LPs?
- bix6 1y ago$175M isn’t that big for JPM. It’s only 0.02% of its market cap.
- NickC25 1y agoThey also have $4.3T in AUM. $175M for them is quite literally pennies to them.
- brandall10 1y agoShe pushed back on any direct vetting of the list using privacy laws as a shield and JPMorgan didn't challenge it due to competitive pressure to get the deal done ASAP. Clearly, if only 10% of the list was real, it would be pretty easy to validate that with a small random sample.
- jerf 1y agoThe way that due diligence would have discovered this was not to take the list and start doing spot checks on it. The way due diligence should have found this is that it should have been written all over the financials. What do you mean you have 4 million customers and a support staff of 20? What do you mean you have 4 million customers but your revenue is {clearly too low}? What do you mean you have 4 million customers but your website spend is {clearly too low}? It's over an order of magnitude. It should be written all over the company. Experienced DD should have smelled a rat within about 2-3 hours, although nailing it down could take much longer. The logical conclusion I draw is that there was no experienced DD done. In isolation this would a tough claim, however, I look around and I see a lot of Wall Street activity on this time frame that shows no evidence of Due Diligence being done and it seems to be part of a pattern. (The question of why there was no DD is a separate one.)
- brandall10 1y agoThe problem here is this wasn’t about MAU. JPMorgan wanted a verified student data asset they could market to, so stale accounts were fine. Diligence focused on whether Frank had “records” (name, email, DOB, etc.), not whether those records were active. Beyond that, JPMorgan didn’t want to push too hard and risk blowing up the deal as there was competitive pressure. Calling out “these numbers seem odd” could have spooked Jauvice, and they figured the reps & warranties in the contract gave them enough protection if things went south.
- TuringNYC 1y ago>> The problem here is this wasn’t about MAU. JPMorgan wanted a verified student data asset they could market to, so stale accounts were fine. Diligence focused on whether Frank had “records” (name, email, DOB, etc.), not whether those records were active. This isnt about inactive data, they had an outside data scientist create an artificially generated usage dataset!
- cactusplant7374 1y ago> Seems like the most basic of OLAP queries and two days of effort would reveal very suspicious userbase. What would those queries look like?
- deleted 1y ago[deleted]
- jon-wood 1y agoSELECT COUNT(*) FROM users would have been a start from the sound of it.
- cactusplant7374 1y ago> Meanwhile, Amar purchased a list of 4.5 million real college students and their data from ASL Marketing for $105,000. Frank executives later supplemented that list — which only had email addresses for a portion of the students — by purchasing more data from an information services company. https://www.highereddive.com/news/jpmorgan-chase-alleges-ed-tech-firm-faked-student-accounts-frank/640325/ https://www.highereddive.com/news/jpmorgan-chase-alleges-ed-...
- TuringNYC 1y agoSELECT USER_ID,COUNT(*) FROM WEBSITE_CLICKSTREAM GROUP BY USER_ID
- sontek 1y agoSELECT COUNT(*) FROM users WHERE date_deleted IS NULL AND date_last_activity >= CURRENT_DATE - INTERVAL '120 days';
- duxup 1y agoI don't think that would work, the stories said they generated fake data. There would be users presumably.
- chatmasta 1y agoIf you read the details in some of the earlier articles about this, they avoided plenty of due diligence. But she also went to great lengths to prevent them from completing that due diligence. And for the minimal due diligence she did permit them to undertake, she only ever sent them fraudulent data and documentation.
- diognesofsinope 1y agoThere was an article on Bloomberg or WSJ that said the Director in the acquisition had a Teams chat where she said "sometimes you don't need to do due diligence at all" lol
- tverbeure 1y agoBack in the nineties, Philips was days away from signing a licensing deal for a revolutionary video compression technology that compressed whole movies down to 8KB. The former Philips CTO was a strong believer. And then the inventor died and nothing ever came of it. To be a fly on the wall during due diligence meetings between Philips engineers and management. https://lowendbox.com/blog/the-man-who-was-paid-e113000-for-his-code-which-compressed-entire-movies-in-8kb-of-disk-and-then-he-died/ https://lowendbox.com/blog/the-man-who-was-paid-e113000-for-...
- pinewurst 1y agoOnce upon a time, I was strenuously recruited by a startup with similar, if not quite as extreme, codec promises. When I understood that my job would be rigging demos while trying to realize the non-software founder’s “algorithm”, I pretty much had to fake my own death to escape them. Shudder…
- cheema33 1y agoVideo codec compression scams remained popular even in early 2000s. I worked for a very large public tech company. One of the top 10 in that era. And they fell hard for scammers from Las Vegas that promised revolutionary audio/video compression. We had to sign all sorts of NDA and couldn't look under the hood of what they delivered to us under penalty of breach of contract and all that stuff. I "accidentally" ended up looking under the hood and couldn't believe what I found. I reported the findings to my manager and told him to do what he wanted to with that information. Long story short, the whole project got shut down and about 200 people working on project lost their jobs. Myself included. Luckily I quickly landed at a better place working on more meaningful things.
- danielmarkbruce 1y agoYou often don't get to "inspect the goods" at a user by user level. Put yourself in the shoes of a non-fraud company where the asset is your customer set. Do you let JPM go through line by line confirming each one? No, you do not. You give redacted data or aggregate data. In eyeballs/non-paying user businesses, this is just going to happen sometimes. In practice you don't get to do the diligence you want to do sometimes.
- TuringNYC 1y agoDoesn’t the Data Room solve this? https://carta.com/learn/startups/equity-management/data-room/ https://carta.com/learn/startups/equity-management/data-room...
- danielmarkbruce 1y agoNo. There is no magic in buying/selling businesses, just put yourself in the shoes of the seller. JPM promise not to ever use that customer list you put in the data room should the deal fall over? How would you ever know if they did? You wouldn't trust a potential buyer and in practice companies do not. They'll put information in the data room, but not customer level details unless anonymized at which point you are back where you started as far as validating users. So you are left with various legal/contractual solutions - things like "representations and warranties" (ask chatgpt about them), escrow agreements etc etc. And when it all goes to hell you go to court with your contract and attempt to get the money back. Such is life.
- jcims 1y agoI'm sure there are those that have had different experiences, but I've been party to several M&A due diligence exercises (including >$1B) at a large financial and there is *tremendous* pressure (on both sides) to move quietly (MNPI baby), quickly and not destroy your relationship with the acquired entity in the process. The business wants the sale to close, you're looking for issues that could be leveraged in the deal and/or actual show-stoppers. The interactions are clumsy as they are managed through third party portals that keep the data locked down and in escrow. The sell-side entity still has every right to protect their intellectual property until it's parceled in a contract, so you're not going to get access to shit (unless they are stupid I suppose). It's going to be in an audit-like situation where you are going to ask someone for samples (which obviously can be groomed) or doing screen shares and taking screenshots or similar. The fact that the acquirer is large is somewhat immaterial, the teams 'under the tent' doing the investigation are going to be relatively small on both sides, including folks from the business trying to close the sale, internal/external counsel and singular SMEs from relevant domains.
- Scubabear68 1y agoI've been involved in a lot of due diligence efforts, from the tech side but I've seen all angles of it as the deals are often fast and intense and the various teams have to often coordinate to a degree (tech, legal, financial, tax, etc). It is fairly common for the people initiating the acquisition to really want to close it in a hurry, and they do due diligence only as a check mark in someone's list. As someone else here mentioned, there is enormous pressure to close, and any red flags are often redirected, reworded, or even occasionally just squashed. The further away a company is from something like private equity, who does acquisitions like we eat breakfast every day, the more likely you are to see rushed and potentially botched due diligence. Someone like a big bank may well have the main proponent not know anything at all about acquisitions or due diligence, and just wants to "get 'er done". It is also very common for people to come in after-the-fact and do a second diligence, and while doing that diligence to hear one or more people opening the conversation with "I warned them about this before the acquisition...". At the end of the day, particularly in a big public corp, people are focused on their bonuses and total comp, and people like that aren't going into a due diligence looking for red flags and "no's".
- tootie 1y agoI remember when HP announced their plan to acquire Autonomy. I was very familiar with their tech and their status in the industry at the time and knew they were approaching irrelevance with no chance to boost sales of anything. They completed the deal anyway, which was followed by HP firing their CEO, lawsuits for misrepresenting their financial status and a complete writedown of the total acquisition cost. It seemed so obvious to me and my colleagues were doing integrations and software procurement and yet HP was completely blinded by everything besides their fabricated balance sheet.
- atombender 1y agoReading about Autonomy, it always confused me that Mike Lynch was found guilty of fraud in the UK but exonerated in the US — what's your take on that?
- pseudolus 1y agoDifferent burdens of proof. The fraud charges in the US were criminal in nature which required a showing of guilt beyond a reasonable doubt. The fraud in the UK arose in the course of a civil trial with a lower burden of proof (balance of probabilities).
- atombender 1y agoWhat's the general consensus, do you know? It seems maybe fraud occurred, but was difficult to prove conclusively?
- lokar 1y agoThis was covered in "Money Stuff" (a free newsletter at Bloomberg, which is fantastic). "Other financial firms, such as Capital One, considered buying Frank but declined after looking at a sample of the company’s user data."
- duxup 1y agoHow much depth does due diligence really involve? I'm involved with a company taking some investment from the outside. We're really just sending them copies of our documents and data. IF someone chose to blatantly lie on that paperwork (we're not), I'm not sure how much they could spot. In the meantime this outside group isn't querying out DB that's for sure, but even then in the example of this case, they actually generated fake user data and records. I'm not saying you're wrong generally, but I think a lot of due diligence really does trust that someone wouldn't blatantly fake ... everything.
- Mistletoe 1y agoChecks article. >summer of 2021 Ah, I see. Probably afraid someone else would snatch up Frank before they could in the summer of mania.
- marcus_holmes 1y agoThis. Why bother going through DD properly if you can just sue the seller later if it turns out everything isn't what you expected? I get that this is about the seller lying during the sale process, which is appropriate imho, you shouldn't be able to just lie about stuff like this. But it's the DD team's job to spot this stuff, that's what DD is all about. I notice the judge criticised the bank as well, which is a step in the right direction.
- seanhunter 1y agoI've been part of due diligence from both sides of the table both in investment situations and cases of M&A activity. You're not really set up to detect out and out fraud like this. For one thing there might be a limited subset of data you really have access to (eg in this type of situation they may not have been in a position to see all the row level customer records before signing because they were competing for business in those customer segments so it is reasonable to restrict access. You might get aggregate data that looks sane and have to go on that for instance. Secondly you may not actually have the time needed to check things out properly. There's often deadline pressure where the deal has to complete by a certain date or it triggers break clauses or some other party gets a right of refusal or whatever so often the clock runs out even if you would otherwise be able to do the analysis.
- aenis 1y ago- a fraction of the board gets all gung ho on buying something - board-1 gets marching orders to do due diligence. those people are typically aware of the sentiment in the board. they delegate to their underlings and share what they think the board wants, - if you say no, you are guaranteed to upset one of your bosses. if you say yes, its typically a positive (your boss is happy), - most M&As are typically bad ideas. Its typically nobody's fault when the thing is written off by the next management and nobody seems to mind that much. People who waved through the due dilligence are proper executives by then and the cycle continues. Incentives are mis-aligned, and on top of this there is usually (a) not a lot of time and (b) a veil of secrecy. Missing those fake emails does not surprise me.
- Wojtkie 1y agoI'm not surprised. Was part of an acquisition by a large F100 company. There were some "interesting" accounting calculations that we discovered 2 years after.