Below is the story of how The Natural Sapphire Company outsourced web development work to India, paid the developer over a million dollars, and now is being cyber attacked and terrorized by the same developer.

Shortened Version:

In 2004, Prashant Telang, owner of Transpacific.in, a website/software development company in Mumbia, India was hired by www.TheNaturalSapphireCompany.com to develop their website and database.  Over the years, Prashant Telang increased their monthly cost for the four developers in his office until it was $20,000 a month!  Every time The Natural Sapphire Company tried to fire Prashant, or lower their costs, he would “punish” their company by breaking parts of their site, or bringing it down in full.  Finally, in December 2010, NSC got in touch with 2 ex-employees of TransPacific who showed where some of the back doors and kill switches were.  In January, NSC fired Prashant.  The next day, the attacks began:

The cyber terrorism Prashant has initiated against us include:

(1) Using back doors he created in The Natural Sapphire Company’s  site to: delete the database, delete files, bring down the site, change pricing to be 75% off, sql injections, etc. which caused the website to be TOTALLY down for 1 month of lost sales  .  Jan 2011 – March 2011

(2) Stealing the domain www.NaturalSapphireCompany.com (which was a redirect site www.TheNaturalSapphireCompany.com owned for 6 years for customers who forgot to add “the”), forwarding NSC’s customers to his own site, and posting malicious lies to dissuade them from shopping with the real Natural Sapphire Company.   Prashant stole it by taking over the registration account.  It is now offline pending NSC’s court case against Prashant Telang.  Jan 2011

 (3) Registering the software that was created and paid for The Natural Sapphire Company as his own, then issuing a DMCA to NSC’s host to have their website taken down.  Sep 2011

(4) Creating an Evan@NaturalSapphireCompany.com (which is our CIO’s name, but with the stolen domain) and pretending to be him to get info from vendors.  March 2011

(5) Attempting to sell NSC’s source code to their competitors (rumors have been told, and he has boasted about it, but it is unknown if he has been successful at this).  All 2011, 2012

(6) Going to every blog, forum, news outlet, etc that has ever mentioned NSC and posting more unfounded comments about the company on those pages.  All 2011, 2012

(7) Creating numerous posts on scam and complaint sites with horrible lies about NSC.  All 2011, 2012

(8) Daily harassment in emails and live chats on the NSC website.  All 2011, 2012

(9) Emailing the entire company’s employees saying that they were going out of business.   All 2011, 2012

(10) Using his past database access to email their customers pretending to be NSC and telling them not to shop with us.  All 2011.

(11) Creating numerous sites that attack NSC’s reputation  and provide SEO to his spiteful posts.   All 2011, 2012

(12) Installing two kill switches in NSC’s custom database software that they paid over a $1 million for and which he activated the day after he was fired… which then wouldn’t allow NSC to open the software or (for the people that had left the client on the day before) stopped them from syncing to their database.   Pre 2011 and launched Jan 2011.

(13) Breaking into NSC’s consultant’s Gmail account, getting their VPN and server password and then crashing their inhouse SQL server.  In addition, then posting that consultant’s personal emails on the web.   Jan 2011

(14) Tried to steal customer information and order info by hiding code in NSC’s website that BCC’d email addresses he was in control of.    Pre 2011 and Jan 2011.

(15) Adding NSC’s email servers to spam black lists so their emails could not get to our customers.   June 2011

(16) Demanding extortion payments of between $80,000 and $1,000,000 to stop his attacks.  All 2011, 2012

(17) Attacking NSC’s Wikipedia page daily to false claims about fraud with the company and redirecting traffic to their stolen site until wiki editors deleted the page in disgust.   June 2011

(18) Clicking NSC’s PPC ads on Google to cost them hundreds of dollars per day in false clicks.. over $60,000 in the last 5 months.  NSC has now shown evidence to Google showing his boasts of the attacks, his methods, and how they have gotten past Google filters.  NSC’s legal team is now working with Google to help their prosecution case against him as well.   April 2011 – Today

Here is a small example of the posts Prashant has created under false names with fictitious stories.  You can see the same case of a dozen or more bogus reviews on their Yelp.com page (under “filtered”) http://www.yelp.com/biz/the-natural-sapphire-company-manhattan

 

The reason for this website is simple.  To push India into prosecuting Prashant Telang.  Numerous attempts have been made with the Indian Consulate, but after one year, they have not even opened an investigation.  This website is NOT an attack against India or Indians.  This is simply a true story of how an American company outsourced to an Indian company, which is now performing cyber terrorism and extortion against this American company with no legal restrictions by the Indian government.

Detailed Version:

In 2004, a New York company, TheNaturalSapphireCompany.com (NSC) hired Prashant Telang, owner of TransPacific.in (TPS) in Mumbai, India to create a website and internal database software. NSC owned the source code for both the site and the software. The designs for both projects were created in the NY office and sent to TPS to code.

Over the years, the cost for TPS skyrocketed. NSC was soon paying $20,000 a month for coding! That’s $240,000 a year for a simple website and database! Many months would go by that NO work was done, but still NSC would have to pay. Every time NSC tried to lower the cost, the website or database would encounter multiple failures. Prashant would say that it was because there were not enough programmers working on the account. Also, he would punish NSC by firing programmers in the middle of a task, and then say that the task would remain unfinished as that programmer was the only one that could do that programming task.  Since programmers would always go missing, NSC wasted time and money on multiple non-completed projects.

For example, after a year of attempting to have Amazon.com let NSC create a store on their website, they were granted access. But, when NSC asked Prashant to create code so their inventory could be uploaded to Amazon.com, he balked, calling Amazon.com a waste of time because consumers did not shop on the site. After a month of NSC insisting that Prashant create the Amazon.com code, he finally relented and had one member of his staff work on the project. After 3-4 months, NSC finally began to see some items uploaded to Amazon. Then, Prashant sent another exorbitant bill.  NSC said they would not pay such inflated prices, and Prashant retaliated by firing the employee who had completed the Amazon.com project without retrieving the code or gaining knowledge of how NSC’s inventory items were syncing with Amazon’s site.  So, after 4 months, and $80,000 in cost, NSC had no code and no Amazon store.

NSC also tried to hire developers in NY to assist TPS and NSC with various half-completed projects, including the Amazon.com project, but when they asked for missing parts of the source code, Prashant would claim that they were ignorant and refuse to work with them.

In the last few years, TPS made more and more mistakes and errors with the website and database. Finally, in December of 2010, during NSC’s largest holiday sale, TPS made a huge error and corrupted NSC’s database.  The damage from the error was extensive, and took over a week to fix. Prashant admitted the mistake was his fault, but NSC had had enough. They could no longer do business with a company that was too expensive and unreliable.  Prashant was informed that NSC was going to source their development work elsewhere. Prashant accepted the fact that his client was leaving, and said he understood the reasons behind NSC’s decision. To help ease the separation, NSC sent Prashant an additional $12,000 for any expenses (the outstanding balance was already paid in full).

The Attacks Begin:

Prashant accepted the $12,000 from NSC.  However, he then demanded an additional $100,000 in order for NSC to end their business relationship.  This extortive sum was preposterous, and NSC immediately blocked Prashant from accessing their office network, database, and website. The next day, NSC’s website failed and its database application stopped working. Prashant then sent an email to NSC saying that he had left out important source code from his required deliveries, and if NSC wanted it to get its website working again, the company would have to pay his extortion fee.

Every time NSC tried to get its site back up, Prashant would crash it again. Because Prashant had intimate knowledge of NSC’s entire server setup, Prashant knew exactly which database tables and files to access to bring down the website. During his time working for NSC, Prashant had deceptively created multiple “backdoors” (secret ways of accessing the website’s code) in the site. NSC found this malicious code and attempted to close these backdoors, one by one. NSC also found a “kill switch” in their database software.  This “kill switch” was a set of instructions within the database’s code.  It instructed the database to look for a file on the TPS website in India. If that file was removed, the database would not open or sync.  There are no legitimate reasons for these backdoors or kill switches, except to damage and disrupt NSC’s database and their business.

The discovery of this kill switch within NSC’s database shed light on an earlier error that NSC had encountered.  About a year before, for an entire day, NSC was unable to open their database.  There had been no updates or changes to the software or the code.  The database simply had stopped working.  At the time, Prashant had claimed that the issue was not a result of anything he or his developers had done.  An NSC employee noticed that Prashant’s own TPS website in India was also temporarily down, and asked if that could potentially be the cause of NSC’s database outage.  Prashant immediately dismissed this question, and for good reason.  There were no legitimate reasons for the two outages to be linked.   There should never have been any association between Prashant’s company website and NSC’s database.

For at least a week straight in January 2011, the NSC website was completely down until the biggest backdoors were closed. Since then, Prashant has continued to attack the site 3-4 times a week, for three months, bringing the site down for hours or a full day, until a new backdoor was found and closed. During this time, Prashant sent continuous emails to NSC taunting them and repeating that he will destroy the company.  In desperation, NSC blocked all of India from accessing the website by blocking all of India’s IP range.  Prashant then bypassed this measure by using an anonymous proxy server to access the NSC site. He has proven that he is willing to do anything to cause problems for NSC, be it deleting all of NSC’s websites images, crashing the website, or lowering all of NSC’s inventory on the website by up to 70%.

New Forms of Attacks:

Finally, in the end of March 2011, after 3 months of continuous attacks, the NSC website was finally locked down and Prashant was unable to attack the site directly. NSC could still see his footprints as he tried loading injection queries attacking specific spots in their database, but his attempts were unsuccessful. Deciding on a new method to attack NSC, Prashant emailed some of NSC’s vendors from “Evan@NaturalSapphireCompany.com” (missing “the” in the main domain’s name) pretending to be the CIO of the company and asking for contact information. NSC’s primary domain is TheNaturalSapphireCompany.com.  NaturalSapphireCompany.com was another domain NSC owned for customers who forgot to put in “the” at the beginning of their primary URL.  NSC realized that when they had fired Prashant, he had immediately changed the registration on NaturalSapphireCompany.com to become his own, effectively stealing the website.  In order to rectify this issue with the website, NSC had to spend $10,000 on a law firm and dispute panel to get the stolen domain back. In the meantime, Prashant began posting false stories of credit card fraud and picture deceit on multiple forums on the internet, and then linked them all on the front page of www.NaturalSapphireCompany.com. He would look for every forum post, blog, or article that mentioned NSC, create a post pretending to be a concerned citizen, and then post links to NSC’s stolen domain with his malicious content on it.

NSC filed with the National Arbitration Forum, a source for disputing domain ownership.  NSC showed that the domain was purchased using NSC’s credit card, they provided emails from Prashant showing that the domain was bought for NSC, proved that the domain was registered for the last 4 years in NSC’s name and pointed to NSC’s primary website, and showed evidenced that after Prashant was terminated, the domain was stolen and malicious content against NSC was uploaded. Prashant responded to these claims with unsworn testimony and falsely claimed that developing a gemstone business was his idea, that NSC stole his current employees, that he has a FBI case against NSC, that NSC stole their own source code from him, that he is already suing NSC in court in India, etc. Unfortunately, because of Prashant’s lie about a current court case, the judge presiding over the dispute dismissed the case as a trademark issue and said that NSC should dispute the case in court.

So, again, NSC spent thousands of dollars to review the case with the NAF showing in more detail, that this case has nothing to do with trademarks – it is simple theft – and that there is no open case with any court system in any country. Again, the judge dismissed the case due to the fact that NSC did not provide any new trademark evidence even though NSC showed full proof of theft.

Prashant has not taken any breaks from harassing NSC. He has continued to create new posts around the internet with vicious lies such as NSC selling him a $5,000 ring containing a $100 piece of glass, posting altered internal documents that only he had had access to, etc.  He defaced and edited NSC’s Wikipedia page by changing the link to NSC’s official site to the URL he had stolen, linking to the fake posts he had created, and then pushing admins to delete the NSC Wiki page claiming that there was no significance to the company.

Prashant continues to send anonymous, threatening emails such as: “see your SEO getting killed in next 1 month through our automated robot let me ensure you that i will not rest till i close down your company”.  All of this harassment is coming from a man who NSC paid over a million dollars since 2004 for a website and a database. A man that held NSC hostage over the years, threatening to sabotage and shut down their website and their business.

Attempts For Help:

NSC hired a law firm in India to try to fight for their case locally.  Wire transfers for thousands of dollars were sent to their Indian lawyers to properly file the case’s documentation and legal evidence with the Indian Cyber Crimes Division.  After many weeks of waiting, there was no headway with the case. NSC pressed the lawyers for answers about why their case was not being processed with the Cyber Crimes division.  Eventually, NSC was told that if they wanted their case to be seriously considered, they would have to pay bribes, starting with $1,000.  NSC was given the cell phone number and personal email address of the chief of the Cyber Crimes Unit in Mumbai, Mr. Sunil Ghosalkar, (+919870335533 cyberpolice.srg@gmail.com), and was told to contact him if they wanted to pay to “make something happen.”  NSC reeled at how seemingly corrupt the Indian legal system could be.  NSC refused to pay any sum.  Because of this, and because Prashant’s father was the assistant commissioner of police in Mumbai, no case was ever filed against Prashant Telang.

NSC also tried contacting the FBI Cybercrimes Unit multiple times.  Online forms were filled out, many phone calls were made, and the FBI never replied back.

The Indian consulate in New York City contacted NSC in April 2011, saying that Prashant was claiming that NSC stole his employees. Prashant had claimed the same thing in the domain disputes and his emails, saying that NSC actively hired employees away from his company when he was fired.  NSC has evidence showing that this claim is an outright lie. Prashant had 2 employees that were of importance to NSC.  They worked faster, and their work was more complete, than any of Prashant’s other employees.  In 2010 they both left Prashant’s company, TPS, to work for other companies in India. NSC begged Prashant to keep both of these employees, even telling Prashant to offer them a cash bonus to stay with TPS. Prashant claimed that these workers were insignificant, were not needed, and to send him the money for himself. After realizing they needed help to leave the nightmare that was Prashant, NSC contacted these 2 ex-employees.

What NSC found out from these employees about working for Prashant was shocking. While Prashant had claimed that there were 8-15 employees working for NSC full time, there were only 2-3. They were aware that Prashant was lying to NSC about the amount of workers and amount of work being done for them. They also knew the location of most of Prashant’s backdoors and kill switches in the code in NSC’s database and website. Sure enough, when Prashant was fired, he enabled the kill switches and backdoors. Without these 2 ex-employees, NSC would have gone out of business. According to NSC’s contract with Prashant, he was supposed to send them the full source code on a monthly basis. He only sent it 3-4 times a year after being harassed for it.  While Prashant had claimed he had sent NSC the full source code for their website and software, he had left out major parts.  Luckily, after weeks of 18 hour days, NSC was able to recreate these missing pieces. Prashant found out that these 2 ex-employees had helped NSC, and has sworn to find these two people and punish them. To further his intentions, Prashant has lied to the authorities on many occasions claiming that these employees were part of his staff when he was fired. This was all explained to the consulate, whom, once satisfied that a crime hadn’t occurred against an Indian citizen (Prashant), told NSC that there was nothing the Indian consulate in NY could do for them further.

Where We Stand Now:

NSC has LOST HUNDREDS OF THOUSANDS OF DOLLARS in the time that the website was down due to Prashant’s attacks, to the cost of lawyers and developers needed to pay emergency funds to get the site operational, to the loss of sales to India due to blocking their IPs, and now due to lost sales from his slanderous remarks all over the internet.

In the wake of this disaster, NSC has hired in house developers, and is now using American companies for their coding needs. Companies may be dazzled by the cheaper labor costs associated with outsourcing, but the reality of outsourcing means increased costs from managing incompetent work, the danger of code/property theft, and numerous other detracting factors. The most dangerous problem is that there are no laws to protect your company when outsourcing overseas.

Some people may ask why NSC did not severe ties with Prashant and TPS earlier. Because e-commerce is a relatively new development, imagine the scenario of a brick and mortar store.  You hire a contractor to build you a specialized building for your store.  Once he has completed the building, you realize that he didn’t draw up any building schematics, only floor plans that he insists are complete and accurate. You don’t know where pipes are running, cables were laid, etc.  Your contractor is the only one who knows the exact layout of your store. To do any new work, you can only use him.  But, every time you request an upgrade to one part of the building, another part breaks down. When you try and bring outside contractors in to fix those areas, your contractor refuses to explain what he has done, or where anything is.  In order to stop doing business with this contractor, you would have to build an entire new building from the ground up, with no old blueprints of what has been done previously. Finally, he accidently destroys a major section of your building and you fire him.  To retaliate, he uses holes he purposefully created in your walls to cause your building to fall down.  You keep trying to prop your building back up, but he keeps knocking it down. Luckily, you find 2 of his former workers that know where the most significant holes are, so you have those patched.  No longer able to physically harm your building, your contractor decides to harm your reputation in your neighborhood.  Now, he goes around town posting signs with horrible lies about your company.

This is where NSC now stands.  If NSC had worked with a non-outsourced company, this contractor could have been sued and arrested, but because he is in India, he is under the protection of a country that refuses to prosecute him for serious crimes.

The Natural Sapphire Company sees NO other alternative now, but to go to the media and let them know the price of doing business with India. NSC has full evidence of all Prashant’s attacks, extortion attempts, theft of domain, and proof of his slander. This is a huge story about the cost of outsourcing with India and the fact that NO ONE in the police or government is willing to rectify these injustices.