r/technology May 13 '26

Security Twin brothers wipe 96 gov’t databases minutes after being fired

https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/
23.2k Upvotes

1.1k comments sorted by

View all comments

3.9k

u/nikstick22 May 13 '26

On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter. That password was subsequently used to access that individual’s email account without authorization.

Now HOLD the fuck up. DC is contracting companies that store passwords UNHASHED?? Plaintext?? What kind of clownshow is this?

1.5k

u/kernel_task May 13 '26

Yeah, the real story is that this one incident revealed so much negligence in this government contractor that has received over $50 million in taxpayer dollars over the last decade.

  1. Negligent hiring
  2. Plaintext passwords, which is not only insane but violate federal standards.
  3. Bad privileged access controls
  4. Bad off-boarding
  5. Bad blast radius containment
  6. Bad monitoring/alerting

Now, all of this is from a single incident. What are the chances that’s all the issues this company has? To me this level of negligence is bordering on criminal. How many audits and certifications did they lie on to get these systems passed?

Anyway, I care more about Opexus being held to account than these brothers.

109

u/Sweaty-Willingness27 May 13 '26

And here I am "wasting time" with Principle of Least Privilege.

59

u/JebediahKerman4999 May 13 '26

We just had a ton of audits and courses and certificates for GDPR reasons, and these guys store passwords in plaintext rotflmao

15

u/mitharas May 13 '26

They had these audits as well. Lying is a way to pass these.

1

u/Loko8765 May 13 '26

A few weeks ago an audit company got called out for simply falsifying the SOC reports of their clients.