Ex-employee exploited lingering access, costing firm hundreds of thousands
A terminated worker retained login rights and sabotaged internal systems, inflicting financial loss and project delays.
In a large firm of over a thousand staff, a recently terminated employee continued to have active credentials because responsibility for disabling accounts was unclear between HR and IT. Exploiting shared admin rights, the disgruntled former worker deleted files, locked out colleagues and damaged a database, causing extensive operational disruption. The incident resulted in financial losses estimated at hundreds of thousands of dollars and added weeks of delay to an important project.
Because the sabotage was carried out by someone who knew the systems intimately, restoring functionality proved especially difficult. The case highlights the need for immediate revocation of access, regular reviews of shared accounts, and clear off-boarding procedures. The speaker, Yad Senapathy, recommends placing access termination alongside hardware return on checklists and avoiding single-person control of critical systems.
Why it matters
It shows how weak off-boarding can let former staff cause costly damage to a company.
In this story
