Cisco Settlement Sees Whistleblower Vindicated

"I mean, this was a pretty decent accomplishment," James Glenn said Thursday in a phone interview.

Advertisement
By Associated Press | Updated: 2 August 2019 11:50 IST

A computer security expert who has won a trailblazing payout in a whistleblower lawsuit over critical security flaws he found in October 2008 in Cisco Systems video surveillance software thought his discovery would be a career-boosting milestone.

James Glenn imagined at the time that Cisco would credit him on its website. The software was, after all, used at major US international airports and multiple federal agencies with sensitive missions

Advertisement

"I mean, this was a pretty decent accomplishment," Glenn said Thursday in a phone interview.

Instead, he was fired by the Cisco reseller in Denmark that employed him, which cited cost-cutting needs. And Cisco kept the flaws in its Video Surveillance Manager system quiet for five years.

Advertisement

Only Wednesday, when an $8.6 million settlement was announced and the lawsuit he filed in 2011 under the federal False Claims Act unsealed, was Glenn's ordeal revealed — along with the potential peril posed by Cisco's long silence.

The law lets whistleblowers report fraud and misconduct in federal contracting — for selling flawed products, essentially — and collect financial rewards when claims succeed. Glenn's attorneys said his is the first cyber-security case successfully litigated under the FCA.

Advertisement

Cyber-security expert Chris Wysopal of Veracode said the case breaks new ground by making it clear that security vulnerabilities now fall into the flawed product category.

"This allows for a new type of bug bounty for security researchers if vendors drag their feet, continue selling their products to governments without notifying of the risk they know about and not fixing their flaws," he said.

Advertisement

The exploit Glenn, 42, discovered would have given an attacker full administrative access to the software that managed video feeds, letting them be monitored from a single location, the lawsuit says. It could also potentially allow unauthorised access to sensitive connected systems.

That meant an intruder might have taken control of or bypassed physical security systems such as locks and fire alarms, which are regularly connected to camera systems.

"An unauthorised user could effectively shut down an entire airport by taking control of all security cameras and turning them off," the suit says. Airports affected included Los Angeles International and Chicago's Midway, it says.

"You could penetrate the entire system. And you could do that without any trace. And have complete backdoor access to the system whenever you wanted," said Michael Ronickher, an attorney representing Glenn with the firm Constantine Cannon.

The software was also used by the Department of Defense Biometrics Task Force Headquarters, the US Secret Service, the Department of Homeland Security, the Army, the Navy, the Marine Corps, the National Aeronautics and Space Administration and the Federal Emergency Management Agency — as well as police stations, prisons, schools and by Amtrak at its stations, the lawsuit says.

"I feel vindicated, but not in the celebratory sense," said Glenn, who gets 20 percent of the settlement payout, with the rest going to the federal government, 15 states and the District of Columbia.

"I think in terms of the punishment level for the other party maybe it's not that significant," he added.

Cisco issued a statement Wednesday saying it was "pleased to have resolved" the dispute and that "there was no allegation or evidence that any unauthorised access to customers' video occurred" as a result of the product's architecture. But it added that video feeds could "theoretically have been subject to hacking."

Ronickher, Glenn's lawyer, noted that the suit does not address all the international locations that bought the Cisco software, which he said include the Auckland airport, New Zealand's largest.

When Glenn discovered the flaws, he immediately alerted Cisco, but the U.S. technology giant did not acknowledge them until 2013, when it issued a security alert about "multiple security vulnerabilities " in the software.

That notice came two years after federal authorities began investigating.

The reseller, NetDesign, fired Glenn in March 2009, his lawyers say.

Two years later, after Glenn's sister notified the FBI and the lawsuit was filed claiming Cisco had defrauded U.S. federal, state and local governments who purchased the software system.

On July 22, the plaintiffs settled with Cisco in a case brought in New York's Western District.

Glenn's lawyers and Cisco both announced the $8.6 million settlement amount the plaintiffs are due.

Glenn, the son of a Marine originally from Virginia, now lives in Bulgaria and has been working for the same company since 2011, which he declined to name.

He said he is married, with one child.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cisco
Advertisement

Related Stories

Popular Mobile Brands
  1. Best Mobiles Under Rs. 40,000 in India
  1. Samsung Galaxy Z Flip 8 Roundup: Launch Date, Expected Price, Specifications
  2. Redmi Note 17 Pro Global Variant Reportedly Appears on NBD Database Alongside Poco Model
  3. Google Pixel 11a Codename Reportedly Spotted in Phone App
  4. Huawei Mate XT 2 Leaked Patent Reveals New Tri-Fold Design and Folding Mechanism
  5. Airtel Unlimited 5G Data Subscribers Reportedly Cannot Share 5G Data via Mobile Hotspot: Here's What We Know So Far
  6. Lenovo Legion C700 Teased as a Cloud Gaming Handheld Ahead of August Launch
  7. Marvel's Wolverine Gets New Trailer That Will Play Ahead of Christopher Nolan's The Odyssey in Select Theatres
  8. Airtel Quietly Removes Rs. 549 Individual Postpaid Plan in India; Rs. 699 Plan Becomes Next Upgrade
  9. Poco M8 Power, Poco X8 India Launch Timeline Tipped; Could Arrive as Rebranded Redmi Note 17 Series
  10. Samsung Galaxy S25 Series Could Get Galaxy S26’s Horizontal Lock Camera Feature With One UI 9 Update
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.