Av rating:
Total votes: 55
Total comments: 10


Richard Morris
The Seven Billion Dollar Man
29 January 2008

When the incredible news broke, last week, that a trader at the third-largest bank in France, the Société Générale, had allegedly managed to over-ride the entire compliance mechanism of the bank, implemented at immense cost by a department of 2000 IT compliance 'officers', to cause a massive $7 billion loss, it sent waves of panic throughout the IT industry, as well as the money markets. So we sent our roving reporter, Richard Morris, to try to find out what went wrong.

'what people fail to realize 'is that when security systems are breached you don't automatically tighten security because it can in some ways make the problem worse'. '

Jeremy Hibbet, forensic accountant PwC

Evil Kerviel?

Last week was a roller-coaster ride for Jérôme Kerviel, the 31-year-old Parisian. In four days, he went from being 'the shadowy IT genius' and the 'French Nick Leeson', to being dubbed 'the Che Guevara of finance' with an ever increasing online fan base and several proposals of marriage.

Support sites opposing his arrest, and groups calling for Kerviel to be awarded the Nobel prize for economics, an honorary doctorate in IT and pleas for a movie tracking his antics have been springing up on the Internet ever since the record loss-making rogue trader's name emerged on Thursday.

US sites are already selling T-shirts to his most ardent fans.

As is now widely known, the bank fired several other staff when the scandal emerged and encouraged Jean-Pierre Lesage, head of IT and human resources for the corporate and investment banking section to fall on his sword. But publicly all the blame has been heaped on Kerviel .

Early reports suggested that Kerviel had started out developing the intricate 'Compliance' computer systems used to control the positions that traders across the bank could take out in markets around the world. He was a member of a vast team of 2000 Compliance experts, designed to prevent precisely this type of fraud

The Société Générale compliance system was previously regarded as a very complex mechanism, the best in the business

The day after the scandal broke, the media reported that Kerviel knew exactly how to manipulate it. In early 2005 he moved from compliance to a trading job as a hedger - essentially paid to reduce the bank's risk by taking out opposite positions to the ones being run by the traders.

His salary was not in the stratosphere of high-flying City traders. He was on €100,000 (£75,000 or $150,000) . His trading limits would have been small, in the tens of millions of euros.

The bank maintain that Jérôme Kerviel had started taking one-way positions by faking the offsetting arbitrage positions about a year ago, and that he then, supposedly, faked necessary approvals through several levels of hierarchy. His positions were “in the money” (profitable) until December

Around December, he seems to have removed all the limits on his personal trading positions and created fictitious customer accounts. Through December he seems to have taken out a series of bets that the markets would fall - and closed them all out so that by the end of the month he was even.

In January, we are told, he decided to do the opposite, buying the markets through futures contracts in the expectation that the markets would rise. They did anything but and he seems to been got caught out. His position 'went negative' in January and 1.5B Euros by Sunday night; that loss was more than tripled by market conditions and Société Générale's handling of the affair, when the positions were hastily unwound on Monday.

Suspicions linger that Société Générale has not revealed the full story of Kerviel's massive $7 billion fraud. The story released by the bank is unconvincing. All transactions are required by law to go through security software and be double checked by another officer for fraud control and then again at the beginning of the trading day against some other factors to establish airtight control. Several people are involved in the auditing process in order to minimise any chance of fraud. Over the last few days the bank's chairman, Daniel Bouton, has admitted that some of Kerviel's deals had triggered warning signs in recent months but the trader had 'managed to convince the IT controllers that it was just a simple error on his part'.

It seems to be generally agreed that Kerviel was apparently able to unpick or switch off all control and counter checks. In addition, he master-minded a way of covering his trading. He apparently created fictitious trades designed to neutralise the big bets he was making so that the bank's systems appeared to show that everything was in balance. In banking-speak, his positions were outwardly 'hedged'.

According to some reports he changed his position often. He would input a transaction that would trigger a control in three days but before that happened he would replace it with a different one.

'He would admit he had made a mistake, the transaction would be cancelled and he would replace it by another one that would be controlled by another department,'' Bouton said. 'He wasn't making more mistakes than other traders.'

'He wasn't making more
mistakes than other traders.'

But other bankers wonder if Soc Gen had much looser management risk controls than it has admitted to. If these positions had been concealed for up to a year, the bank's risk-management and cash-position systems should surely have detected and reported this. European Central banks have already imposed regulatory rules including Basel II and IAS 39 and IAS 32 whose sole purpose is to build transparent systems that can measure and report the real risk and cash position of a bank. If the bank's story is true, there must have been long-standing fundamental flaws in their control systems, audits and computer security.

One British expert in the risk management systems of banks said candidly:

To pull off this kind
of fraud is not necessarily
that difficult

'To pull off this kind of fraud is not necessarily that difficult. Systems like Société Générale's make checks but they are only done on exceptional trades and by all accounts these were not exceptional trades.

If the management system believes that the trader is not doing anything out of the ordinary, then the system won't flag it. If you are not exceeding the account's limits, you will not be checked. That I would guess is what happened here.

'He could have hacked into the system in a number of ways. Look it like this - the answer is that all database management systems have functions that enable them to control lots of databases and of course they hold the information on all data in their own database tables.

'Every DBMS in the world has these tools for database administrators. I would guess that Kerviel stacked up a number of fake identities, added these to the database, and used passwords and log-ins to hack into the SocGen server to cover his tracks.

'Both the bank and the media point to Kerviel being a Machiavellian genius to have carried this out. Well, I don't think that is necessarily true. Different systems act in different ways. Each one can display its own vulnerabilities and strange quirks.

'The more complex a system the larger number of bugs it has - everyone with a little IT knowledge knows that .

'If the internal fraud technology software hasn't been updated regularly or is out of date and not bug-free, then it would be relatively easy for someone with good IT skills to do this.

' I think we may find that the system was 'deviant' in some way, that it only signalled things were wrong if large hedges were made. Kerviel may just have exploited that weakness.'

Another banker who wished to remain anonymous said that the greatest significance of this episode is that it shows the vulnerability of a mighty national bank (Société Générale was the third largest in France) to the mischief-making of a single rogue trader.

'It is eerily reminiscent of the Barings merchant bank disaster of February 1995 - something which was supposed to have prompted all banks to put into place better security, management control systems and better controls on the activities of their trading desks. That simply hasn't happened,' he said.

Losing one's Barings

For readers without a long memory what follows is a short recap of Baring's sudden and catastrophic loss which was primarily due to the unauthorized activities of its star futures trader Nick Leeson.

Leeson managed to deceive his employers for nearly three years by reporting fictitious profits while concealing huge losses which had virtually nothing to do with the shadowy world of derivatives trading but a systematic failure of technology.

Shortly after arriving in Singapore in the early summer of 1992 to work as the general manager of Singapore International Monetary Exchange (SIMEX,) Leeson's luck in the markets ran dry. To hide the losses from his bosses in London and keep his relatively well-paid job, he instructed a junior DBA to create an error account, number 88888 - a number considered very lucky in Chinese numerology.

He then asked a systems engineer to modify the security software so account 88888 remained off the system and away from internal security audits by other staff.

While at the face of it Leeson seemed to be a highly successful manager by obtaining discounted derivatives he was in fact deliberately mispricing trades and hiding the losses in the secret account.

From the autumn of 1992 he was made chief trader and began making un-authorised speculative trades that at first made large profits and then nose-dived. The bad debts were hidden in the 88888 account.

Had Barings investigated rumours that some of the bank's trades were suspicious Leeson would have been exposed before his losses brought down his bank. By the end of 1992, the losses were £2 million which ballooned to a massive £208 million by of 1994. Leeson attempted to recoup his losses but all his attempts failed.

After Leeson fled Singapore the losses escalated to £827 million ($1.5 billion) twice the bank's operational capital. It was declared insolvent on February 26 1995.

Suspicious Activities in your Breaches

Jeremy Hibbet, a forensic accountant and expert on risk management for PwC says that what people fail to realize 'is that when security systems are breached you don't automatically tighten security because it can in some ways make the problem worse'.

'Look, system security depends on not having the most elaborate or complex system in the world. That's fine for external threats when hackers can disable a server through a SQL injection but internally certain staff can always access passwords.

IT staff turn off the checks
to allow some trades to go ahead

It doesn't matter how complicated or highly functional a security tool is, all systems rely on good training, management and having a thorough knowledge on their inherent weaknesses.

'It's not always about spending vast amounts of money on clever software or hardware, it's more a question of learning more about the vulnerabilities of any one system, which why good DBAs are worth their weight in gold.

'Traders know that in some cases IT staff turn off the checks to allow some trades to go ahead. That is how any trader whether he is earning $150,000 or $7 million and upwards can evade risk controls.

Kerviel's ability to vaporize the bank's capital represents a massive dereliction of SocGen's responsibility to look after its customers money.

Regulators around the world will be seeking reassurance that the same flaw does not exist in their banks.

'But it will, of course. Where it might differ is that IT staff and regulators investigate any suspicious activity early on. Human error is the one thing that will let down any fraudster,' adds Hibbet.



This article has been viewed 4447 times.
Richard Morris

Author profile: Richard Morris

Richard Morris is a journalist, author and public relations/public affairs consultant. He has written for a number of UK and US newspapers and magazines and has offered strategic advice to numerous tech companies including Digital Island, Sony and several ISPs. He now specialises in social enterprise and is, among other things, a member of the Big Issue Invest advisory board. Big Issue Invest is the leading provider to high-performing social enterprises & has a strong brand name based on its parent company The Big Issue, described by McKinsey & Co as the most well known and trusted social brand in the UK.

Search for other articles by Richard Morris

Rate this article:   Avg rating: from a total of 55 votes.


Poor

OK

Good

Great

Must read
 
Have Your Say
Do you have an opinion on this article? Then add your comment below:
You must be logged in to post to this forum

Click here to log in.


Subject: Bad Day
Posted by: Phil Factor (view profile)
Posted on: Tuesday, January 29, 2008 at 8:10 AM
Message: A shareholder group has filed a complaint that an American member of the board of SocGen, Robert Day, dumped shares worth £95 million on January 9th and 10th, before the news broke, and SocGen's shares subsequently fell to a three-year low. Mr Kerveil has now been charged by French police on three counts, abuse of trust, forgery and computer hacking.
The French president has called on Daniel Bouton to resign.

Subject: Who can we trust
Posted by: Mike Gale (view profile)
Posted on: Wednesday, January 30, 2008 at 10:04 PM
Message: This is scary.

Whatever way you look at it a large swathe of bank management deserves the guillotine. I'm guessing they knew about it and let it happen. Failing that they're criminally stupid.

Now these guys are probably better than the political appointees who run our societies. What hope is there??

Subject: Everyone loves you when you're 'in the money'
Posted by: Phil Factor (view profile)
Posted on: Thursday, January 31, 2008 at 2:20 AM
Message: More interesting news keeps trickling out. According to leaked statements given to the police, Jérôme maintains that it was impossible that management didn't know what he was up to and, because he was 'in the money' for a long time, they turned a blind eye.

"I am convinced that [my superiors] were aware of my positions,"

"I cannot believe that my superiors were not aware of the amounts I was committing. It is impossible to generate such profits with small positions,"

"This leads me to say that when I am making money, my superiors shut their eyes on the volumes committed,"

"As long as we earn money and it's not too visible, nobody says anything,"


Subject: Management
Posted by: Dr. Bob Hacker (not signed in)
Posted on: Thursday, January 31, 2008 at 10:12 AM
Message: Here is the solution:
1. Hire more folks with a non-technical education and give them immense authority without any experience.
2. Pay the related CEO's in 7 digit salaries and benefits.
3. Buy lots of insurance so you can file for 3x the actual loss.
4. Screw the stockholders because they have no power.
5. If you can catch a bad manager, slap the wrist!

Subject: Smokescreen
Posted by: John Bailo (not signed in)
Posted on: Thursday, January 31, 2008 at 11:11 AM
Message: The whole thing sounds like a smokescreen.

As you say he made "no more mistakes" than other traders.

That means his 9B loss is probably masking some 900B losses in and around the industry.

Subject: Respect the IT worker! He's more powerful than you think.
Posted by: Anonymous (not signed in)
Posted on: Thursday, January 31, 2008 at 12:51 PM
Message: So because his managers must have known, he feels he's justified? Throw him to the lions!

It does go to show the power that IT workers can have and that they should warrant a little more respect within an organisation. This guy could do this because he knew the IT system from the inside and sounds like he prepared a few backdoors in readiness for his switch to a trading career.

Subject: Let me see you do it
Posted by: Anonymous (not signed in)
Posted on: Friday, February 01, 2008 at 10:18 AM
Message: "It doesn't matter how complicated or highly functional a security tool is, all systems rely on good training, management and having a thorough knowledge on their inherent weaknesses. "

I've been in development for 20 years and there are always ways to track things that even an expert doesn't catch. If you write software to do something and don't write it good enough, you will always have issues. I'm sure I could come up with a bunch of things that could have caught this issue and I know very little about the banking industry. I do know bits an bytes though inside and out, and it's hard to fake a 1 being a 0. The thing is to make sure everyone sees the 1 being a 0 and that is not hard at all. I would say many folks were turning a blind eye on this one.


Subject: Software
Posted by: KamalBudhabhatti (not signed in)
Posted on: Saturday, February 02, 2008 at 5:20 AM
Message: Do you know which software the bank was using for its operations ?

Subject: Software
Posted by: Richard Morris (not signed in)
Posted on: Saturday, February 02, 2008 at 6:05 AM
Message: Unfortunately no I don't. Last week Le Monde and MediaPart released portions of a transcript from an interview that police conducted with Kerviel. The 31-year-old reportedly admits that he falsified documents and hacked into the bank's computer system to quiet suspicions by internal control units about his fake trades. He argues the bank's managers must have known what he was doing, because the volume of his trades and his profits were higher than a trader in his department typically made. "As long as we were making money and it wasn't too obvious and was working, no one said anything," Kerviel told the police.

If he's telling the truth, then even the best security software might have failed. Similarly, good technology can be no match for human shortcomings: Kerviel's actions did raise some red flags, but bank officials apparently put more faith in their employee than the warnings.

Subject: Supposition!
Posted by: Anonymous (not signed in)
Posted on: Monday, February 04, 2008 at 3:09 AM
Message: "'Every DBMS in the world has these tools for database administrators. I would guess that Kerviel stacked up a number of fake identities, added these to the database, and used passwords and log-ins to hack into the SocGen server to cover his tracks."

Who is making this wild guess? It's being quoted at DatabaseWeekly.com

Likelihood is that there was no 'magic' about it. He probably used passwords the whole team knew, processes the whole team used and ignorance the managers were happy to maintain.
What do you honestly expect?

 

















Level Playing Field
 The Federal Government in the States accepts tenders for their IT projects from a wide-range of... Read more...

Women in IT: Change at Every Level
 In the past, straight-forward sexism was a real problem in the IT industry – women in IT were... Read more...

Second Life: A Virtual World of Real Money
 As more and more people invest in alter egos to live a pseudo life online in Linden Labs' latest... Read more...

Andrew Tanenbaum: Geek of the Week
 Andrew Tanenbaum has had an immense influence on the way that operating systems are designed. He... Read more...

Ross Anderson: Geek of the Week
 Professor Ross Anderson is one of the foremost experts in Computer Security in the world. He has... Read more...

Linus Torvalds, Geek of the Week
 Linus Torvalds is remarkable, not only for being the technical genius who wrote Linux, but for then... Read more...

Driving up software quality - the role of the tester
 Have you ever wondered what a software tester does? Helen Joyce, test engineer at Red Gate software... Read more...

Coming Out as a Cancer Survivor - A Guide for Software Developers
 A personal perspective on the responsibilities of a cancer-surviving software developer Read more...

The Computer that Swore
 Database Developers occasionally get crazy ideas into their heads. Phil Factor should know; He... Read more...

The Writing on the Wall
 Phil Factor offers an intriguing theory on why so many, hugely complex, government IT projects fail. Is... Read more...

Over 150,000 Microsoft professionals subscribe to the Simple-Talk technical journal. Join today, it's fast, simple, free and secure.

Join Simple Talk