Richard Liriano
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Richard Liriano, also known by the alias Richard Liriano, is a former information technology employee who operated from the United States of America. He worked at a New York City‑area hospital where he held administrative privileges that allowed him to access internal systems. His activities came to light after an FBI‑led investigation that resulted in a federal prosecution and a sentence of thirty months in prison.
The actor’s targeting was confined to the healthcare sector, specifically a single hospital located in New York City. He primarily focused on female coworkers, exploiting his position to monitor and extract data from their personal accounts. His strategic objective, as documented in court filings, was to obtain and retain personal information for his own personal use, which included accessing email, social media, cloud storage, tax records and explicit media. The intrusions led to measurable financial impact, with the hospital incurring over three hundred fifty thousand dollars in remediation costs to repair network damage and improve security.
Liriano’s tactics involved the misuse of his legitimate administrative access to install unauthorized malicious software, notably keyloggers, on colleagues’ computers. These tools captured usernames and passwords, enabling him to compromise approximately seventy email accounts and subsequently log into associated personal and social media profiles. He used the stolen credentials to search for and copy private photographs, videos and documents onto his own workspace computer. The cumulative effect of these actions caused network disruptions that necessitated extensive remediation efforts by the victim organization.
Attribution information indicates that Liriano acted independently; no connections to state‑sponsored groups or criminal consortia were presented in the publicly available sources. His prosecution was conducted by the United States Attorney’s Office for the Southern District of New York, with assistance from the Federal Bureau of Investigation and the New York City Police Department. The case was handled by the Complex Frauds and Cybercrime Unit, culminating in a guilty plea and the aforementioned prison sentence.
The most notable operation attributed to Liriano spanned from approximately 2013 through 2018, during which he repeatedly accessed and exfiltrated sensitive personal data from hospital employees. This episode serves as the primary publicly reported example of his malicious activity and illustrates the consequences of insider threat abuse of privileged access within a healthcare environment.
Incidents
Attributed incidents are available to members.
1 incident