Sandia backhacker wins $4.3 million judgment against Sandia Labs

ALBUQUERQUE – Shawn Carpenter, who was fired by Sandia National Laboratories in January 2005 for conducting backhacking operations against intruders he discovered on Sandia networks, won a $4.3 million wrongful discharge suit against the labs today. Backhacking occurs when networks are attacked and someone on the hacked network responds with a counterhack or attack.

Carpenter, who worked in Sandia’s computer security operations organization, started detecting attacks against Sandia networks in 2002, according to court records in the 2nd District Court of New Mexico. Carpenter brought the attacks to the attention of Sandia and other government agencies, including the Army Research Laboratory and the FBI.

Carpenter’s attorney, Thad Guyer, said testimony during the trial, which started Feb. 5, showed that Carpenter detected computer attacks from China, Brazil, Italy and Romania against Sandia systems. Guyer declined to say whether the attacks from China were state-sponsored, adding that he believed the attacks from the other countries were done in support of terrorist organizations.

Despite Carpenter’s discovery of widespread hacking from abroad against Sandia networks, the lab decided to rein him in. This occurred, Carpenter alleged in the suit, despite the fact that he was cooperating with the FBI and the Army research lab in his backhacking investigation.

In January 2005, Sandia terminated Carpenter for insubordination and for using Sandia information outside the lab. Carpenter said in the suit that the insubordination charge arose because he refused to comply with Sandia directives that he not disclose information “relating to serious breaches of national security to anyone inside or outside Sandia,” such as the FBI or the Army research lab.

Guyer said the $4.3 million in punitive damages and $350,000 for psychological stress that Carpenter won in the suit proves that Carpenter did the right thing with his backhacking, which Sandia had alleged violated the law. A panel of 13 jurors heard the case.

Guyer said Carpenter’s persistence in pursuing attackers in cyberspace despite Sandia’s increasing resistance makes him a true U.S. hero and a patriot. He added that the Carpenter case resonates with FBI warnings issued before the September 2001 attacks about potential terrorist threats that were ignored.

Sandia was disappointed by the verdict and is considering an appeal, a spokesman said.

Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.