Jonathan Ly
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Jonathan Ly, also known by the alias Jonathan Ly, is a former information technology employee who worked in the Hotwire.com division of Expedia in the United States of America. He was identified as a 28‑year‑old senior IT technician at the time of his criminal activity, which occurred between 2013 and 2016. Ly used his position to obtain passwords and remotely access the electronic devices of Expedia’s chief financial officer and head of investor relations. By doing so he was able to view confidential emails and documents that contained non‑public information about the company’s upcoming announcements. The stolen information enabled him to execute a series of highly profitable stock‑option trades that generated approximately $331,000 in illicit profits. His actions continued after he left Expedia, as he retained a company laptop without authorization and used it to maintain access to executives’ devices while impersonating other employees. The scheme was uncovered through Expedia’s enhanced monitoring practices, which prompted the company to involve the FBI and led to Ly’s guilty plea to securities fraud in a U.S. District Court in Seattle.
The activity demonstrates a clear financial motive, as Ly’s objective was to profit from insider trading rather than to conduct espionage, disruption, or any other strategic goal. His targeting was limited to a single private‑sector organization in the technology and travel sector, specifically Expedia, and there is no evidence that he pursued victims outside the United States. The tactics he employed relied on credential theft and the abuse of legitimate remote‑access capabilities that were already available to him as an IT technician. He did not deploy malware or custom tools; instead he used stolen passwords to log into executives’ devices and to read their email and document repositories. Persistence was achieved by retaining corporate hardware after his departure and by manipulating system logs to make it appear that other staff members were performing the accesses. Detection relied on the victim organization’s internal monitoring, which flagged the anomalous access patterns and triggered a law‑enforcement investigation.
Following the investigation, Ly agreed to repay the $331,000 in illegal profits as well as $81,592 that Expedia incurred for the intrusion investigation, and he accepted a SEC settlement requiring payment of $375,907 including interest. He pleaded guilty to securities fraud, a crime that carries a maximum penalty of twenty‑five years imprisonment and a $250,000 fine, and was scheduled for sentencing on February 28, 2017. The U.S. Attorney’s office described the conduct as a particularly egregious breach of trust and privacy, emphasizing the violation of both corporate and employee confidences. No public attribution links Ly to any state‑sponsored group, criminal consortium, or broader hacking campaign; he acted as an individual insider. The case remains a notable example of how privileged insider access can be abused for financial gain when monitoring controls are not sufficient to detect credential misuse.
Incidents
Attributed incidents are available to members.
1 incident