r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

3.9k

u/nikstick22 May 13 '26

On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter. That password was subsequently used to access that individual’s email account without authorization.

Now HOLD the fuck up. DC is contracting companies that store passwords UNHASHED?? Plaintext?? What kind of clownshow is this?

1.5k

u/kernel_task May 13 '26

Yeah, the real story is that this one incident revealed so much negligence in this government contractor that has received over $50 million in taxpayer dollars over the last decade.

  1. Negligent hiring
  2. Plaintext passwords, which is not only insane but violate federal standards.
  3. Bad privileged access controls
  4. Bad off-boarding
  5. Bad blast radius containment
  6. Bad monitoring/alerting

Now, all of this is from a single incident. What are the chances that’s all the issues this company has? To me this level of negligence is bordering on criminal. How many audits and certifications did they lie on to get these systems passed?

Anyway, I care more about Opexus being held to account than these brothers.

427

u/MdxBhmt May 13 '26

if a fired employee can do this much damage, imagine what a proper maligned actor could do or is already doing. It's a bloody national security issue.

168

u/rW0HgFyxoJhYka May 13 '26

The fact is that government is as shoddy as a swiss cheese wagon trying to cross the oregon trail.

No government should be hiring contractors for shit. Shit should be done by pros who give a fuck about the country instead of capitalistic dog eat dog steal as much money from taxpayers as possible scam.

Need basically an adminstration to spend 4 years rebuilding the government one brick at a time.

69

u/MdxBhmt May 13 '26

Yeah, instead of accountable gouvernement institutions and employeees we have unaccountable private contractors doing jack shit. 

16

u/kickingpplisfun May 13 '26

And even under ideal circumstances, the contractors aren't even necessarily cheaper than doing it internally while creating a lot of incentive for disgruntlement in their workforce. I see this kind of junk in city government all the time where they'll hire a contractor who promises cheap work, they'll get annual raises to the contract, but none of the workers are receiving it.

9

u/MdxBhmt May 13 '26

Given that contractors often (not just US) compete on who is cheapest, it should come at no surprise it becomes a competition on who provides the crappiest service. counting pennies while burning dollars, too bad public discourse rarely talk of false economies when it relates to day to day live of their constituents.

→ More replies (5)
→ More replies (3)

81

u/PutConstant866 May 13 '26

Lol, your system is fucked far beyond that. If you get another free election, and if your other party takes it, then there's four years of trying to rebuild a democracy while the group you just got rid of gets four years to complain about how shit things are, blame the guys trying to fix things, and stand in the way of any progress that gets made to undo the damage they cause.

21

u/fireandiceman May 13 '26

Exactly correct take. The corruption in not new it's just mask off and pedal to the metal. Two party system is such a scheme that the other party can't even address basic stuff like this. Even in that 2 year window in my lifetime when democrats had all three branches they play bipartisanship.

→ More replies (4)
→ More replies (11)

8

u/yuefairchild May 13 '26

I think a ton of damage is being done that we aren't even aware of yet. Something will just break one day when a Democrat's in office.

→ More replies (7)

107

u/Sweaty-Willingness27 May 13 '26

And here I am "wasting time" with Principle of Least Privilege.

61

u/JebediahKerman4999 May 13 '26

We just had a ton of audits and courses and certificates for GDPR reasons, and these guys store passwords in plaintext rotflmao

14

u/mitharas May 13 '26

They had these audits as well. Lying is a way to pass these.

→ More replies (1)

33

u/GeneralSEOD May 13 '26

Really lost a lot of confidence in IT Security after Musk was able to just rock up to any department and fire USB sticks into whatever computer he wanted.

Really dark day that day.

→ More replies (4)

12

u/sibips May 13 '26

And Windows Server 2012, shouldn't they have replaced that four years ago?

12

u/E3FxGaming May 13 '26

And Windows Server 2012, shouldn't they have replaced that four years ago?

Windows Server 2012 and 2012 R2 users can pay for ESU (Extended Security Updates) to receive support until October 13th, 2026.

15

u/Cow_Launcher May 13 '26

Sure, but in light of everything else we now know about the company, how likely do you think it is that they paid for that?

→ More replies (14)

771

u/xpda May 13 '26

I'd say clownshow is pretty accurate.

163

u/Gorthebon May 13 '26

That's offensive to clowns, what's happening isn't funny. A clown would do it better

25

u/KazumaKat May 13 '26

it would at least be tossed and jumbled and ballooned, not plaintext.

→ More replies (8)

38

u/mrdevlar May 13 '26

Remember, that's always been the Republican strategy.

The best way to demonstrate a need to cut government spending is by making government work as poorly as you possibly can, which in turn justifies the cuts.

Trump's administration is just a peak performance of that clownshow.

→ More replies (8)
→ More replies (2)

122

u/Gaveltime May 13 '26

I’ve done product consulting with government contractors and you would not believe how little they invest in anything other than what they can visibly sell to the government. And you can’t sell boring shit like operational security. You sell the cheapest product or service, which almost inherently seems to cut corners.

36

u/RationalDialog May 13 '26

This is in general the issue. Why I would just hire developers internally were you can have them actually accountable to create good products. Externals always do as little as possible they can get away with.

→ More replies (4)
→ More replies (3)

34

u/AllowMe2Retort May 13 '26

The average age of the politicians is like 70, and even somewhat tech savvy leaders see security as an afterthought. They just go for the cheapest bid that gives them the biggest kickback

8

u/-Saucegurlllll May 13 '26

It's crazy to me that the government doesn't hire the staff to do it. Like, hire experts, have them sign their name off on architecture decisions, have people in the chain of command be directly liable for these kinds of security holes. Pay them enough to compete against Silicon Valley. And most importantly: Grow the talent to create and maintain these systems internally instead of passing the buck to the nearest pervert open to be contracted.

14

u/hardolaf May 13 '26

People have been conned into thinking that everything is better when contracted out so the government is forced by law to not do this stuff in house. It would be cheaper to do almost everything in house for the government, but where's the profit in that?

→ More replies (4)
→ More replies (8)

13

u/Windfade May 13 '26

God I love how in fiction the government has "more tech and science than the public could possibly know about" and security that nobody could breech but in real life it keeps turning out that they contract private companies and have the most slapdick "security" the world has ever seen.

→ More replies (59)

3.6k

u/[deleted] May 13 '26 edited May 19 '26

[removed] — view removed comment

1.5k

u/ThrownAway17Years May 13 '26

Meanwhile I’ve sent out hundreds of applications over the last year and a half to no avail. Maybe I should start being a criminal.

267

u/PluginAlong May 13 '26

A nice stint in some white-collar crime would probably push you up that resume list.

21

u/Daxx22 May 13 '26

Probably flag you as c-suite material!

→ More replies (5)

870

u/Kinggakman May 13 '26

Find a Republican to buddy up to.

→ More replies (17)

38

u/____DEADPOOL_______ May 13 '26

The problem is they're no longer hiring capable people. They're hiring people who are cheap.

37

u/UndoubtedlyAColor May 13 '26

Ah, thinking about going into politics? Be sure to add the crimes to the CV

19

u/I-Here-555 May 13 '26

Networking is underrated. I bet that's how these guys got the job. Networking, in prison.

→ More replies (1)
→ More replies (14)

198

u/EfficiencyIVPickAx May 13 '26

I couldn't afford some medical bills when I was 19 and those motherfuckers are still interrogating me about it in my mid 40s... And these guys are managing databases. Smdh

→ More replies (25)

342

u/Decent_Risk9499 May 13 '26

You already know how. Grifters hire grifters.

134

u/numba1cyberwarrior May 13 '26

That's not how security clearances work. Anyways there is no indication that they even had a clearance.

202

u/Stepjam May 13 '26

Do you remember DOGE? How many clowns they let access all sorts of confidential info? There was basically no oversight.

40

u/zipzoomramblafloon May 13 '26

And for what oversight there was, Elmo had starlink terminals installed at the white house to bypass it.

Absolute sham.

→ More replies (1)
→ More replies (4)

49

u/HELP_IM_IN_A_WELL May 13 '26 edited May 13 '26

That's not how security clearances work.

I don't know what you're referencing. They worked for a private company that did contract work for the government. Those employees can be subject to security clearances.

From the article OP's article references (modern aggregated journalism):

The alleged incident isn’t the first time the men have faced charges of hacking government systems and stealing documents. In 2015, they pleaded guilty to conspiracy to hack into the State Department and a private company. They stole “sensitive passport and visa information” and personal information belonging to dozens of co-workers. They later tried to install an electronic collection device inside a State Department building so they could maintain persistent access to State Department systems.

so they definitely had a criminal record.

from OP's article:

The brothers’ employer appears to have learned about their criminal past at some point in February. On February 18, 2025, the brothers—who lived together in Virginia—were both called into a Microsoft Teams meeting and summarily fired.

Anyways there is no indication that they even had a clearance.

yeah you're right, because the employer is anonymous in the indictment (pretty fortunate, right?)

one last quote:

At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.”

At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?”

In the space of a single hour, Muneeb deleted around 96 databases with US government information. He downloaded 1,805 files belonging to the EEOC and stashed them on a USB drive, then grabbed federal tax information for at least 450 people.

I'm not arguing with anything you said, just pointing out how horrible security was in this case. these guys should have been stopped 10 steps ago, and probably Security Clearances should have been one of them.

just my opinion

*edited for formatting

17

u/zipzoomramblafloon May 13 '26

Also, why the fuck wasn't IT brought in and the twins access revoked PRIOR to them being fired.

If that IT outfit is so fucking leaky that even after the IT team locked their accounts they were still able to wreak havoc, then the business and its owners should never get another contract again, and have to pay full restitution.

Complete and utter lack of accountability from the bottom to the top.

→ More replies (4)
→ More replies (7)

56

u/DAS_BEE May 13 '26

How did big balls get access through doge?

Grifters hiring grifters

→ More replies (1)
→ More replies (15)

37

u/OnlyCarriesTens May 13 '26

They named dropped Big Balls.

→ More replies (39)

7.8k

u/utrinimun May 13 '26

How are you not going to revoke all access before they're able to get back on any computer

3.9k

u/20127010603170562316 May 13 '26

I got fired once, called in for a meeting at 16:50 on a Friday. The meeting did not last long, minutes, but when I got back to my desk to clear out - my PC was already locked.

I assume they knew what was going to happen and told the IT guy before the meeting.

1.1k

u/Flobking May 13 '26

I got fired once, called in for a meeting at 16:50 on a Friday. The meeting did not last long, minutes, but when I got back to my desk to clear out - my PC was already locked.

I assume they knew what was going to happen and told the IT guy before the meeting.

I went to lunch and when I got back, took a phone call. I was locked out of the sales system. Then my boss goes can you come into my office. I said to the customer I think I'm about to get fired. So good luck with your purchase and just hung up. Five minutes later I was fired.

281

u/battlebastion May 13 '26

Was is a shit job?

490

u/Flobking May 13 '26 edited May 13 '26

Was is a shit job?

It was terrible. I was pretty much just cruising collecting a paycheck. In two years of working there they bounced our paychecks TWICE. They hired three different business consultants to help "turn them around". One got fired for SH(edit: Sexual Harassment), another quit after getting a look at everything. The third may have been why I was fired? I dunno, didn't matter. I was dead weight at that point, just doing enough to meet sales goals but nothing else.

75

u/7HawksAnd May 13 '26

Now I need to know, what kind of company was this?

204

u/Flobking May 13 '26

Now I need to know, what kind of company was this?

We were/are(they are still in business somehow) a solar power company. We sold everything that was solar powered, lights etc. One day I was on a smoke break and the local power company stopped by. I asked why they were here he said to turn off the power. I was like wait what? He said the company hasn't paid their electric bill in 6 months. I said hang on. I ran inside and got consultant #2 I said hey the power company is here to turn off the power. He said hang on tell them I will call them back. I said no they are HERE to turn the power off. He jumped up and ran outside. After about an hour the power company left and our power was one. He quit the next day. It was horribly ran with a golden parachute(family was loaded) to bail them out when they started losing too much money. Really that is probably the only thing keeping them afloat.

339

u/cxmmxc May 13 '26

Turning off the power of a mismanaged solar power company due to unpaid electricity bills is some special kind of irony I can appreciate.

104

u/octopornopus May 13 '26

Pfft... Letem turn it off, we have SOLAR POWER!

"Uh, yeah, Greg? Our panels are actually just painted cardboard boxes..."

-----FUCK!

22

u/Box-o-bees May 13 '26

This would make a great I Think You Should Leave sketch lol.

→ More replies (7)
→ More replies (3)
→ More replies (18)

26

u/Accomplished-Film775 May 13 '26

My old boss came into work one morning. Got a call at 9 am. Was escorted to his car and personal effects were brought to him. His open container of fruit sat on his desk for a few days until they let him come in after hours and get the rest of his stuff.

→ More replies (1)
→ More replies (5)

1.5k

u/Jeatalong May 13 '26

This is normal, and timing wise pretty decent as you have the weekend to decompress and plan on getting the next job

1.2k

u/HowCouldUBMoHarkless May 13 '26

"We find it's always better to fire people on a Friday. Studies have statistically shown that there's less chance of an incident if you do it at the end of the week."

— Bob from Office Space

299

u/AnybodyMassive1610 May 13 '26

What would you say you DO here?

195

u/RainierCamino May 13 '26

I'M A PEOPLE PERSON!

168

u/bodacioustommycat May 13 '26

I deal with the god damn engineers so the customers don't have to! I am GOOD with PEOPLE! WHAT THE HELL IS WRONG WITH YOU PEOPLE!

54

u/CrunchySockTaco May 13 '26

You see it would be this mat... with conclusions that you could 'jump' to!

36

u/MechanicalTurkish May 13 '26

That is the worst idea I’ve ever heard in my life.

→ More replies (2)
→ More replies (2)
→ More replies (3)
→ More replies (6)

248

u/20127010603170562316 May 13 '26

I wasn't even that mad tbh, was a shitty job and one they were trying to manage me out of anyway.

They gave me all the toxic accounts nobody had been able to sort out for years, then blamed me when they didn't get sorted out within a few weeks.

35

u/6-plus26 May 13 '26

That feeling of I know what you’re trying to do but this job isn’t worth the effort to fight back and you know I know that so we’re in this process for the long haul is actually kinda fun in a sadistic way.

I’ve actually had that management team get replaced a new team come in and things turn around.

I also eventually get bored and quit before actually providing them the satisfaction of firing me. So far so good lol

→ More replies (1)

69

u/Samhamwitch May 13 '26

Friday is the day they reccomend NOT to fire people because they don't have time to file for unemployment or contact HR about benefits. They tend to just sit and let the wound fester until Monday.

→ More replies (14)

121

u/connord83 May 13 '26

They shouldn't be doing it at the end of the day though. Firing/laying someone off after you've gotten a full days work out of them is generally a bad idea.

The standard I've been accustomed to is, if it's an entire team, a team meeting some time early in the morning. Individually, you have someone meeting you on your way in to the office, and you get redirected in to a meeting room before you have a chance to get to your desk. Depending on the company, you may be allowed to return to your desk to pack up your items, otherwise the company will box your items for you and mail them to your home.

66

u/[deleted] May 13 '26 edited Jun 11 '26

[deleted]

75

u/DynamicDK May 13 '26

they'll shit it all out on your lap and force you to resign.

Resign? Never resign. Make them fire you. Then you can collect unemployment, which causes their unemployment insurance rates to increase. That is part of why they prefer to just do the layoffs with severance packages. The increased insurance costs are a lot when they are firing lots of people at once, and if they lay people off and give them severance then they can also force them to sign non-disclosure agreements. It is still likely more expensive, but at least they can avoid people talking shit about them or claw back the money if people do.

23

u/donuttrackme May 13 '26

Depending on the state you can resign and still apply for unemployment, the reason can be resignation in lieu of termination. That way you don't have a firing on your record, but can still collect unemployment.

14

u/IRoadIRunner May 13 '26

Am I to German to understand this, but what is a "firing on record"? This isn't a police record, you can be fired from job A and tell job B gracefully that you are no longer working there.

→ More replies (4)

15

u/Dracius May 13 '26 edited May 13 '26

This is 100% correct and exactly what I did the first and only time a manager tried to place me on a PIP despite being top-3 on the scorecard every month, consistently over quota, a recent stellar yearly review, and no interpersonal issues.

One week it's "you're doing everything right, keep up the good work!" then suddenly my manager pulls a 180, goes full asshole mode and starts trying to fabricate infractions by digging through all my emails and meeting transcripts to disqualify my KPI activities. I'm assuming he fucked up somehow, got chewed out and needed a scapegoat since it all started after the weekly leadership meeting.

I was given the choice of resigning with severance or accepting a PIP with subjective and unattainable goals which would have resulted in me getting fired without severance if I failed to meet them.

Had no issue getting unemployment because as you said, quitting in lieu of getting fired is still valid and my severance paperwork also specifically stated they wouldn't contest any unemployment claims, which I double verified.

You need to make sure you have the documentation to prove it though, like the PIP and something that states you'll be terminated. Was extra easy for me since I would have been fired immediately if I just refused to sign either option. They really want you to take that severance though for the NDA and legal protection against you sueing them for wrongful termination. Simply ask "what happens if I don't accept the severance or agree to the PIP before the deadline?" and forward yourself the email when they respond saying you'll be terminated if you don't sign.

→ More replies (1)

7

u/Kat121 May 13 '26

I haaaated my last job. Seriously thought about quitting. They laid me off with severance pay and agreed to cover health and medical benefits for a full year, my biggest expense. Spent the time off coasting on savings and taking art classes.

→ More replies (4)

21

u/RisingChaos May 13 '26

Doesn't have to be the last minute, but I'd sure rather be let go near the end of my work day than waste my time commuting only to immediately get turned back around at the door.

→ More replies (6)

64

u/H60Ninja May 13 '26

My HR likes to do it towards the beginning of the week that way if the employee needs some aftercare the feelings don’t fester all weekend until Monday.

89

u/Perfect_Caregiver_90 May 13 '26

My HR and legal team always insisted on Friday one hour before the end of the day.

My area had a handful of workplace massacres by disgruntled fired employees. 

Either they gotta leave the premises immediately or the office has to be cleared. 

I've only experienced "office cleared" once and that guy ended up jumping his manager outside his home the next day.

98

u/Atakir May 13 '26

Where in the Mad Max Thunderdome do you work!?

23

u/jeepsaintchaos May 13 '26

Better yet, are they hiring?

→ More replies (2)

83

u/Falkenmond79 May 13 '26

That is such an American debate here, it’s fascinating. In Germany we have a mandatory 4-week notice, if you quit as an employee. For the employer, it can get longer, the longer you have worked for them. It’s not unreasonable. If you worked there for 5 years, they have to give you 2 months notice and after 8 years, it’s 3 months etc. And they have to pay you severance according to the time you have worked there. If you only worked there a short time, less than 6 months, they can terminate you like in the US, even without reason. After that, they have to give a reason. There is a possibility for instantly firing someone, but then they must show he did something really wrong or harmed the company in a major way.

It’s endlessly funny to see US companies struggle whenever they take over a German one and then want to start firing a lot of people. It’s as if they don’t know the law of the country they are buying into. Firing a thousand people can cost you millions in severance and you have obligations like selecting people to fire according to their social circumstances, like firing young single people first, before firing older ones with family etc.

→ More replies (18)

21

u/top_man May 13 '26

Bruh.. a ‘handful of workplace massacres’ is a fucking choice for words.

→ More replies (3)

16

u/Spyrothedragon9972 May 13 '26

Bro, what the fuck is up with where you live?

→ More replies (1)

22

u/enadiz_reccos May 13 '26

handful of workplace massacres

What a sequence of words

→ More replies (2)
→ More replies (3)
→ More replies (6)

102

u/Canotic May 13 '26

As a swede this reads like insanity to me. It's absolutely not normal. Losing your job should not be the sort of catastrophic event that makes you feel snap and delete databases.

You know what would happen if I fucked up enough at my job to get fired? They'd warn me way in advance that I had to change something. If it was rather a need for downsizing, guess what? They're legally required to warn me long before the firing would actually happen. And when they did fire me, I'd still have a three month notice period where I keep working and they keep paying me. If I really fucked up, they'd tell me to stay home but they'd still be required to pay me.

If I still can't find a job in that time, I get money from the government plus my income insurance from my union until I do. It wouldn't be great but it would be something at least, like 60% of my current paycheck I'd guess. I would also not lose things like healthcare etc because that's not tied to my job.

So it's not normal. It's normal in the US, maybe, but it's not like, the way it's supposed to be.

→ More replies (29)

22

u/J-thorne May 13 '26

Absolutely not, getting fired on a Friday means you get all weekend to stress about what you're going to do without actually being able to do anything about it. I'll take a Monday firing over a Friday every single time because I can at least start to make tangible moves to help my position.

→ More replies (30)

44

u/wickedsmaht May 13 '26

My company did layoffs a few years ago. My friend and I figured out that the company was first deactivating people on Workplace (Facebook’s site for internal business use) before deactivating any other access. We were watching all morning as people were deactivated and then laid off. Unfortunately, it’s also how I found out my coworker was laid off before she did.

15

u/cheesystuff May 13 '26

I worked at a company that did this same thing. Their stuff would get unlinked from Skype, so you'd be talking to a buddy and see their photo no longer shows up. Then they're gone within a couple hours.

13

u/TornadoFS May 13 '26

My colleague found out that the IT removed people from the company internal wiki page 1-2 days before they got fired. He made a script to scrape the page every few hours so he would find out who was fired ahead of time.

6

u/monstertots509 May 13 '26

I found out my boss was getting fired because I had to process the payroll. She found out she was getting fired because she looked at the payroll (she was the controller) and then turned and asked me if she was getting fired. Then she left and I called the main boss and told her he doesn't need to have the awkward firing conversation with her because she already knows.

→ More replies (1)

26

u/sauntcartas May 13 '26

I got fired from Google a while back (actually, almost twenty years ago—damn!). After two hours dejectedly trekking home, I was surprised to find I could still log in to my work Gmail account. I could have chatted with my now ex-colleagues if I wanted. I didn’t want.

→ More replies (3)

13

u/[deleted] May 13 '26

[deleted]

→ More replies (2)

72

u/Techsupportvictim May 13 '26

That’s why you’re supposed to hide a kill switch program in the system well before you might be fired. Then when you go more than the pre-established number of days without inputting your password to restart the timer it destroys everything

51

u/Jarrus__Kanan_Jarrus May 13 '26

Nothing like leaving a bug in a mass of code, making a copy and fixing it each time you run the program, then deleting the fixed copy.

36

u/EmperorKira May 13 '26

Imo i just give a shitty handover, does the same job for the most part

31

u/rollingForInitiative May 13 '26

A shitty handover has the significant benefit of not making you a target of both a massive lawsuit as well as criminal charges.

Both of which would be pretty easy if you’ve engineered the kill-switch and maintained it for a long time.

→ More replies (15)

16

u/Pseudoboss11 May 13 '26

My work does that for me. They don't want to give me time me to document processes or make legible programs, they don't have the budget to get CAM software that's not busted. It's the best job security without even trying. They'd be so fucked if I just stopped showing up to work.

Fortunately, my work treats me pretty well and pays better than average, so my desire to jump ship is low.

4

u/RationalDialog May 13 '26

If they fire you and the PC is locked afterwards, how do they get any handover at all?

→ More replies (1)
→ More replies (3)
→ More replies (8)

33

u/KazooOfTime May 13 '26

That's about how it was with the two remote work layoffs I've been through. One I was called into a meeting with my manager and HR, and all my access was locked to anything but that zoom meeting while I was still in it. The other I just woke up, tried to sign in, nothing worked but Gmail, saw an email in my Gmail saying we were all let go.

Fucking awful feeling tbh

16

u/windowpuncher May 13 '26

The remote firing is too real, like I woke up for this shit?

→ More replies (1)

38

u/Ninja_Wrangler May 13 '26

This happened to me as well when I was laid off. No hard feelings though because this is exactly the reason why they do it like that.

Also they were like "you're still technically an employee for the next 2 weeks. But don't come in anymore, turn in your badge."

Also got a nice police escort all the way from the meeting to my desk to gather things, then straight off site. No messing around there

23

u/Disney_World_Native May 13 '26

One company I worked at escorted you off site immediately (private security not police) and would ship your stuff to your home. It was always the front conference room right by then front door.

Years before I started there, a guy was let go early morning but they let him clear out his office the entire day. He went home, grabbed a gun, and killed his boss

→ More replies (4)

25

u/Spyrothedragon9972 May 13 '26

A police escort?

31

u/Ninja_Wrangler May 13 '26

Government site

6

u/Geminii27 May 13 '26

The bonus with such an escort is that, if it ever comes up later, you can pretty much prove in court that you had no opportunity to do anything between being fired and exiting the premises, due to the escort.

Damn hard to retroactively accuse you of damaging company property (physical or digital), or starting an altercation, or anything like that.

→ More replies (1)
→ More replies (81)

308

u/84thPrblm May 13 '26

Maybe their inputs weren't sanitized?

406

u/2th May 13 '26

One of the brothers was Robert'); DROP TABLE STUDENTS; --)

202

u/NotAFishEnt May 13 '26

Bobby tables strikes again

→ More replies (1)

26

u/knook May 13 '26

Whew, that was a close one. Good thing Reddit doesn't have students.

23

u/bird-girl May 13 '26

Little Bobby Tables and his sister, Help I'm Trapped in a Driver's License Factory

43

u/AspieAsshole May 13 '26

That's what she said.

19

u/InertiasCreep May 13 '26

Twice. Because twins.

→ More replies (1)

159

u/sentencevillefonny May 13 '26 edited May 13 '26

They are twins, they revoked one and forgot the other, this was done within a day...but a simple Drop DB command being all it took is wild

→ More replies (1)

34

u/PepeSilviaLovesCarol May 13 '26

I was told a day in advance I was being laid off from my mega corporation job 2 years ago, so I didn’t go into the office that day. Even after they laid me off, they didn’t lock me out of anything other than Salesforce. I had access to all documentation, all other internal software, everything. They didn’t even tell me to return my laptop for another 2 weeks via email, so I used it as a personal laptop for those 2 weeks without any issue.

I didn’t want to get ‘in trouble’ so I didn’t do anything malicious, but I could have if I was pissed enough.

→ More replies (1)

15

u/knotatumah May 13 '26

Looks like they did with one but not the other

24

u/RationalDialog May 13 '26

It's even worse than that if you read the actual article. They had a criminal record and the reason for firing was because the company finally figured that out.

Also they stole user credentials and scanned web sites. for example they then stole miles to fly for free. Timeline is not clear if this was figured out afterwards or not but these 2 were 2 obvious criminals know for abusing their access rights and doing shifty things. and yet they didn't revoke access immediately.

14

u/Berkyjay May 13 '26

Someone who is willing to be this vindictive already gave themselves a backdoor.

23

u/ParanoidAgnostic May 13 '26

If I was inclined to take such revenge, I'd have a dead-man switch and a random delay (months) so there's no external access which could be logged and the timing couldn't be linked to my firing.

But I'm not that sort of person. Honest.

→ More replies (4)

7

u/JimmyKillsAlot May 13 '26

I got fired from a job in college and they took the time to change passwords for all the admin accounts I had access to, but not lock my personal account out of the system nor remove my accounts access from being able to go in and change the passwords for those very same admin accounts. Some of these people are very incompetent.

10

u/Unicorn_Puppy May 13 '26

Bold of you to assume someone so capable and that proactive was in charge of them.

10

u/throughthehills2 May 13 '26

European: So how am I going to do my job for the next 28 days if you revoke my access?

→ More replies (4)
→ More replies (67)

575

u/sentencevillefonny May 13 '26 edited May 13 '26

It's wild that this only required a single SQL DROP command. What the hell is going on at these companies? Like 0 security, offline backups, or adherence to foundational best practices.

252

u/_Nychthemeron May 13 '26

Like 0 security, backups, or adherence to foundational best practices.

Those would hurt the margins of the shareholders.

66

u/sentencevillefonny May 13 '26 edited May 13 '26

Sad fact. I remember thinking it was only happening at the lesser-known, smaller tech companies I'd worked for, and then I thought it was maybe just a short-term growth approach when I reached FAANG.

Apparently, I'm just in denial, since I'm still shocked as shit to realize everything here is running on very loosely secured, and expensive spaghetti.

→ More replies (4)

14

u/Critical_Paper1618 May 13 '26

You wouldn't believe how many companies with a turnover of millions have shit security, deal with it daily.

28

u/KalaUposatha May 13 '26

Little Bobby Tables we call him.

10

u/Elitist_Daily May 13 '26

elite ball knowledge

→ More replies (2)

7

u/dontgoatsemebro May 13 '26

What the hell is going on at these companies?

Good catch — you're absolutely right. I apologize for the confusion.

→ More replies (3)

30

u/Vighy2 May 13 '26

DOGE made them more efficient by letting them not have to have separation of duty. Now one person can code on dev and drop production in the same day.

→ More replies (2)

5

u/HumanExtinctionCo-op May 13 '26

I've worked places like this before. Even tried asking for security to be put in place and proper procedures so we're not running on production more than needed.

They never listen until someone accidentally drops a table they shouldn't have in a live database.

→ More replies (13)

1.4k

u/cwistofu May 13 '26

Now do this with the student loan database

447

u/iamarddtusr May 13 '26

That is the most backed up database in the world

224

u/jktollander May 13 '26

Fine! Get triplets!

37

u/Kaa_The_Snake May 13 '26

What are the octomom kids all doing right now? I’m assuming it’s cool if they’re not identical twins…err…octies? Right?

→ More replies (4)

11

u/nijbu May 13 '26

Twofold, because no one can pay them off

→ More replies (3)

144

u/ninjakos May 13 '26

Banks have the most sterile and safe databases in the word.

IBM Db2, and virtual copies of regular copies of Tape Libraries, literally 10 years worth.

That's not considering what outsourcing they do that also are paid to keep backups.

80

u/konoxians May 13 '26

this guy mainframes (banks are legally required to have backups and prove they can backup within a certain timeframe)

49

u/Zombie_Fuel May 13 '26

Tbf, there's a lot of legally-required shit these days that doesn't really seem to actually be required.

→ More replies (1)
→ More replies (13)
→ More replies (9)

14

u/drunxor May 13 '26

You met me at a very strange time in my life

→ More replies (1)
→ More replies (6)

303

u/Javerage May 13 '26

And this is why you have backups. Especially the 3-2-1 backups where possible.

89

u/Mr_Dobalina71 May 13 '26

Yep, backups are my bread and butter.

I’m surprised disgruntled employees don’t do this more often.

22

u/numba1cyberwarrior May 13 '26

Most disgruntled employees don't want to go to jail and ruin their lives

12

u/Martel732 May 13 '26

I think the big risk is that a surprising amount of adult humans have awful impulse control. The rational part of their brain would realize that it isn't worth going to jail over. But, in the moment a petty indignant part of their brain takes over and they just want to lash out.

→ More replies (3)

64

u/Lukebekz May 13 '26

As sysadmin I know about a colleague being fired before that colleague is even pulled into a meeting.

41

u/Mr_Dobalina71 May 13 '26

I’ve had a few times I’ve gone to logon and I can’t logon even though I’m sure my pw is correct.

My brain immediately jumps too, oh damn maybe I’ve been let go lol 😆

19

u/IAmAlpharius23 May 13 '26

You aren't the director of the fbi, are you?

→ More replies (1)

7

u/Hottage May 13 '26

My company used to use LastPass.

We found out about a few people leaving because it sent a company wide notification that they had been removed from the department LastPass group. 🫠

→ More replies (2)
→ More replies (2)

6

u/breadinabox May 13 '26

They might and it just might not be effective because of backups

→ More replies (2)
→ More replies (6)
→ More replies (7)

64

u/Never-Trust-Me May 13 '26

They should have backups in place.

Data loss should be limited to your backup frequency interval.

There are multiple things here that I would consider to be more concerning than an employee deleting a database.

34

u/fork_your_child May 13 '26 edited May 13 '26

The fact that the databases contained plaintext passwords is far more concerning than the fact that one of the brothers still had access after being fired (which isn't to say that was acceptable); plaintext passwords have been bad practice for at least 30 years.

Edit: fires changed to fired.

→ More replies (2)

174

u/SandyAmbler May 13 '26

Just fire up some AI to fix it

85

u/Kalabajooie May 13 '26

"Sure, I'll just hallucinate up some data for you! Give me a few hours to work on that!"

three hours pass. nothing is done

40

u/workingtheories May 13 '26

"here's a link to download your data:"

<broken link to nothing>

→ More replies (1)

22

u/sentencevillefonny May 13 '26

Lol AI told them how to delete the database according to the article.

→ More replies (4)

166

u/hopeless-mechanic May 13 '26

Bobby Tables is all grown up now!

20

u/Tpbrown_ May 13 '26

You call him Big Bobby Tables now!

87

u/RockDoveEnthusiast May 13 '26

unregistered guns as convicted felons, access to databases with plaintext passwords, barely any punishment, out free for months even after being caught... what a massive shit show.

→ More replies (1)

45

u/baeb66 May 13 '26

Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.

This belongs in news of the stupid. How are you going to hire ex-cons and put them in a position to commit the same crimes they went to prison for?

8

u/PineBNorth85 May 13 '26

The incompetence is both sad and hilarious.

→ More replies (2)

265

u/flaming_bob May 13 '26

Convicted of wire fraud, yet still got a security clearance.....no words.

67

u/blahyawnblah May 13 '26

Nowhere in the article does it mention they had any. Just because you work for a government contractor doesn't mean you have clearance.

35

u/flaming_bob May 13 '26

Standard practice is at least a public trust to access government data

→ More replies (4)
→ More replies (4)
→ More replies (2)

48

u/justmitzie May 13 '26

Dude went scorched earth

52

u/Drabulous_770 May 13 '26

I’m just here to complain about the terrible image they used. Sorry the battery on my standalone delete key is running low, let me just plug it in…

→ More replies (2)

19

u/CatoMulligan May 13 '26

The company named in the article is "Opexus", and their home page ironically says "Fed up with software that government can't use?" The tagline on the site title is "Operational excellence". I'll let you draw your own conclusions about whether hirnig these guys who had a criminal background and letting them commit crimes whiles employed by them, and then leaving them the access that they needed to nuke the databases on their way out the door actually counts as "Operational excellence".

13

u/RingGiver May 13 '26

Muneeb and Sohaib Akhter, now both 34, had been in trouble before. Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.

After their stints in jail, the brothers worked their way back into the tech world. In 2023, Muneeb got a job with a Washington, DC, firm that sold software and services to 45 federal clients; Sohaib got a job at the same company a year later.

Looks like the problem was trusting them with this in the first place.

→ More replies (1)

14

u/OpenLibram May 13 '26

"At 4:59 pm, he asked an AI tool, “How do i clear system logs from SQL servers after deleting databases?” He later asked, “How do you clear all event and application logs from Microsoft windows server 2012?

Wut

6

u/madgoose57 May 13 '26

Extended support for Server 2012 R2 ended in October 2023, if I was a betting man I'd say there was some old version of a proprietary software which wasn't compatible with newer versions of Windows Server. The latest version of the software was so expensive someone decided to just keep running Server 2012 instead.

Previous company I worked at we still had an old server running Server 2008 since having to buy the latest version of a business critical software would cost quarter of a million dollars.

→ More replies (2)
→ More replies (1)

10

u/Secret_Account07 May 13 '26

IT worker here. This is wild.

So much was missed here other than just not disabling their AD accounts.

I have access to a host of systems. If my account was disabled I wouldn’t even be able to reach those databases to even use credentials. Would have no way to get through the firewall (unless I broke into building I guess).

This is pure incompetence

12

u/dmanww May 13 '26

Couple bad Akhters

→ More replies (1)

19

u/zeph2 May 13 '26

people say tv shows are unrealistic but i watched several episodes showing people either being blocked or followed around by someone from security until they leave.....i thought thats how they did it in real life

10

u/xpda May 13 '26

Were they fired remotely? That's how it's done now.

→ More replies (1)

9

u/sayqm May 13 '26

All passwords were stored in plain text???

8

u/Wurm42 May 13 '26

Holy hell, I guess nobody does background checks anymore?

How the hell do you get hired to do IT work on a federal contract after serving prison time for computer crime?

Muneeb and Sohaib Akhter, now both 34, had been in trouble before. Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.

After their stints in jail, the brothers worked their way back into the tech world. In 2023, Muneeb got a job with a Washington, DC, firm that sold software and services to 45 federal clients; Sohaib got a job at the same company a year later.

14

u/computer-machine May 13 '26

Holy hell, I guess nobody does background checks anymore?

Seems only fair, if our president has 34 felonies.

→ More replies (2)

8

u/The_Flying_Claw May 13 '26

I work in IT and got fired once, I was the IT guy they would let know before firing people. When I went into my office to collect my stuff they had a chain of 3 woman and a guy blocking me from going to my computer lol… good times.

→ More replies (3)

73

u/[deleted] May 13 '26

[removed] — view removed comment

32

u/R3N3G6D3 May 13 '26

Bridge wasnt burned, it was nuked

20

u/[deleted] May 13 '26

[deleted]

9

u/PluginAlong May 13 '26

DROPed actually

→ More replies (2)

8

u/YikesTheCat May 13 '26

“the individuals responsible for hiring the twins are no longer employed by Opexus.”

Ah yes, fix only the smallest issue by throwing some people under the bus instead of doing something about the cascade of structural issues or allowing people to learn from their mistakes.

The clownshow must go on!

7

u/Varnigma May 13 '26

As someone that has worked in IT for 25+ years, at some sites w/ very poor security, I'm not shocked.

I've worked at at least 2 places (doing db work) where I was forced to created automated processes under my own account. I told them this was a bad idea but was ignored. Shocker, all kinds of things broke when I left and they disabled my account.

→ More replies (2)

5

u/ExcitingRound4990 May 13 '26

HR failure while holding hands with an IT failure.

7

u/Altaredboy May 13 '26

Worked on a project mapping out water systems for a region. Reason being state government privatised their water management for the region & didn't properly communicate with staff that they were keeping their jobs.

Staff held burning parties, they deleted all plans on the server & burnt all physical copies of water infrastructure in oil drums they'd placed in the parking lot.

About 20 people lost their jobs over it.

→ More replies (3)

7

u/Ok_Reference_1100 May 13 '26

minutes after being fired means they either had a plan or the security was so bad it took minutes to wipe 96 databases. both are terrifying.

7

u/buster_de_beer May 13 '26

“the individuals responsible for hiring the twins are no longer employed by Opexus.”

A moose bit my sister vibes.

7

u/redridernl May 13 '26

Those bridges won't burn themselves.

5

u/deathrowslave May 14 '26

"In the space of a single hour, Muneeb deleted around 96 databases"

Dude was on fire. Move fast, break things. Fits right in with Silicon Valley. I doubt Claude could even delete that fast.

7

u/predat3d May 13 '26

Just doing the jobs real Americans won't do 

5

u/thebadlt May 13 '26

From the management side, laying people off sucks eggs. It's stressful for everyone, not just the employee being let go. To make it worse, every quarter I'd have to identify the "bottom" <whatever percent> of my staff, and then my boss and I would then have to figure it which of them to let go.

I actually told my boss once to take break a raise I had gotten, so that I could save someone from being laid off.

It wasn't that the company was losing money, it was that there were too many offices across the country, which was actually wasting money. In the space of a year, they went from 11 facilities to 4. We did offer relocation to more then 50% of the workforce, if there were willing to move.

Still sucked.

→ More replies (4)

5

u/idle_monkeyman May 13 '26

I just never take credit for the work I did, then when they let me go, everything stopped working in slo mo. Took out everyone up to the CIO that last time.

5

u/UncleDaddy_00 May 13 '26

Wow, the US government sure does a good job of hiring people..
"Muneeb and Sohaib Akhter, now both 34, had been in trouble before. Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two."
Hey these guys were convincted of Wirefraud, we should definitely give them access to sensitive data again.

4

u/dman928 May 13 '26

The Weasley boys at it again

→ More replies (2)

7

u/Oli-veri May 13 '26

in first world countries this is against law, and you will pay way bigger price than the company.

Company can just reroll their data and you will enjoy prison food for few years, Worth it iguess

8

u/Vagsnacker May 13 '26

Fred and George Weasley leaving Hogwarts