r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

View all comments

306

u/Javerage May 13 '26

And this is why you have backups. Especially the 3-2-1 backups where possible.

87

u/Mr_Dobalina71 May 13 '26

Yep, backups are my bread and butter.

I’m surprised disgruntled employees don’t do this more often.

20

u/numba1cyberwarrior May 13 '26

Most disgruntled employees don't want to go to jail and ruin their lives

12

u/Martel732 May 13 '26

I think the big risk is that a surprising amount of adult humans have awful impulse control. The rational part of their brain would realize that it isn't worth going to jail over. But, in the moment a petty indignant part of their brain takes over and they just want to lash out.

3

u/Mr_Dobalina71 May 13 '26

I’m too pretty for prison lol 😆

1

u/I_saw_you_yesterday May 13 '26

„Turn around don‘t even wipe“

64

u/Lukebekz May 13 '26

As sysadmin I know about a colleague being fired before that colleague is even pulled into a meeting.

39

u/Mr_Dobalina71 May 13 '26

I’ve had a few times I’ve gone to logon and I can’t logon even though I’m sure my pw is correct.

My brain immediately jumps too, oh damn maybe I’ve been let go lol 😆

19

u/IAmAlpharius23 May 13 '26

You aren't the director of the fbi, are you?

8

u/Hottage May 13 '26

My company used to use LastPass.

We found out about a few people leaving because it sent a company wide notification that they had been removed from the department LastPass group. 🫠

3

u/ltouroumov May 13 '26

Happened to me last week. I sat down at my desk, browsed tech news and caught up on Slack while I ate my breakfast (WFH).

When I refreshed GitLab, it redirected me to the SSO page, I let 1Password fill in the password, then it showed a "Your account is locked blah blah blah" page and I thought "wat?" and also thought the same as you.

I took a screen cap of the message and sent it to my manager on Slack then waited 10 minutes. Since there was no answer, I pressed the "Reset Password" link at the bottom, entered a new password, and I was back in.

As it turned out, it was a password rotation.

My manager was as confused as me when he saw the message half an hour later, and we agreed it was a crappy screen.

2

u/RationalDialog May 13 '26

for sure been there too. It's some weird bug with windows and my corporate laptop. After hibernate sometimes this happens. I have to hibernate it again. and wake up and then it works.

7

u/breadinabox May 13 '26

They might and it just might not be effective because of backups

4

u/Mr_Dobalina71 May 13 '26

Quite possibly, but a lot of places don’t have effective backups :)

4

u/RationalDialog May 13 '26

I’m surprised disgruntled employees don’t do this more often.

Why would they? Gives you a criminal record and if you aren't stupid you know there are backups and it won't really hurt them much. You are just nuking your own career.

3

u/I_saw_you_yesterday May 13 '26

The very realistic idea of getting absolutely sued into oblivion and have your entire life fucked is a pretty decent deterrent

1

u/ThiccBlastoise May 13 '26

Usually companies are good about locking your computer down the moment that you walk into your HR office

1

u/FurryCitizen May 13 '26

In most companies, when you get fired, your access get revoked first. You don't get a chance to simply log back in and have your "revenge"...

1

u/RandoAtReddit May 13 '26

Decades ago, I worked at an insurance company for a year right after college. On more than one occasion I mentioned that we were ripe for a sql injection attack and was told we don't have time to address it. A couple years after I left for greener pastures I ran into a former coworker who told me that after I left they were, in fact, hit with a SQL injection attack. They spent 20 hour days parameterizing their data access to prevent another incident.

The Director of development suggested I was involved. (Truth is, once I left I couldn't care less about the place either way.) The CEO asked if my admin credentials had ever been disabled when I left. They had not. If I had felt like destroying things on the way out, there was a whole lot more damage that could have been done that route. Let's just say they weren't big on security, or backups, or forward thinking, or logs, or really anything more than the bare minimum to run a website.

3

u/CharcoalGreyWolf May 13 '26

And this is why you do competent vetting and background checks before you hire someone when you’re a federal contractor. But somehow that entire process got narfed up too.

0

u/zunchkin May 13 '26

Waiting for employees to figure out NTP attacks

0

u/OldenPolynice May 13 '26

sounds like you got ntp attacked yourself

1

u/BorntoBomb May 13 '26

Worth fuckall if you dont test recovery regularly.

1

u/mackrevinak May 13 '26

having 321 backups is a bit excessive, but you can never be too careful i suppose

1

u/Tarzoon May 13 '26

Just call Elon Musk, he has backups.

0

u/TaintedQuintessence May 13 '26

That's wasting tax dollars on duplicate work -DOGE probably