Ex-Employee's Lingering Access Leads to System Sabotage and Financial Losses

September 3, 2026
Ex-Employee's Lingering Access Leads to System Sabotage and Financial Losses
  • A former employee retained active credentials and admin rights for days after offboarding, enabling file deletion, account locking, and database corruption due to unclear ownership and delayed offboarding.

  • The interviewee urges same-day removal of access, immediate reviews for shared accounts, and a policy that prevents one person from owning an entire system, accompanied by an updated offboarding checklist once company property is returned.

  • The incident is presented as a cautionary tale showing how weak offboarding can cause substantial financial and operational harm.

  • Remediation was hampered because the former employee damaged systems and exploited intimate knowledge of repair procedures.

  • The access chain stretched through shared admin credentials and project tracking systems, creating a domino effect of unauthorized access across multiple platforms.

  • Gaps in offboarding included no immediate access revocation, no forced re-review of shared accounts, and unclear ownership for terminating system access.

  • A former IT employee at a large company retained access after termination, resulting in extensive system damage and significant financial losses.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories