ZeroHour
The Register · Securitypublished ()ingested Avram Piltch

Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

infoIndustryimportance 18
AI summary · glm-5.3-flash

A terminated employee's unrevoked access let him delete files and corrupt a database, costing the company hundreds of thousands of dollars and weeks of delays.

The Register's PWNED column recounts an anecdote from Yad Senapathy, CEO of the Project Management Training Institute, about a company with 1,000+ employees where a terminated employee's credentials were never revoked. The former worker retained shared admin credentials and used them to delete files, lock accounts, and corrupt a database, causing hundreds of thousands of dollars in damage and weeks of project delays. The takeaway is that unclear offboarding responsibility and unreviewed admin access enabled the sabotage.

  • HR and IT each assumed the other would revoke the terminated employee's access
  • Ex-employee abused shared admin credentials to delete files and corrupt a database
  • Author recommends same-day revocation, offboarding checklists, and no single-owner systems
Full article514 words · extracted from theregister.com · click to collapse

SECURITY

They had more access than the average Joe, and IT didn't track what needed to be cut off

PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled ex-employee who had the means and opportunity to wreak havoc.

Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees.

While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database. 

REG AD

"Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said. "Nobody had been clearly assigned to shut them off. HR thought IT would handle it once the termination was processed. IT was waiting for HR to send a formal request. I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem."

REG AD

This lapse in responsibility meant the terminated employee had access to shared admin credentials, account controls, and project tracking systems. Each of these, in turn, granted permission to other systems, leading to a domino effect of inappropriate access, which the former worker used to wreak revenge on the whole organization. 

According to Senapathy, the damage amounted to hundreds of thousands of dollars. Just as bad were the weeks of delay added to an important project.

As an added irony, recovery was particularly difficult because the systems were damaged by the very person who best knew how to repair them.

“The employee wasn't some genius hacker. They just still had access after they left and nobody changed the credentials or reviewed admin rights,” Senapathy told The Register. “We'd let one person collect so much system knowledge that shutting the door behind them took longer than it should have.”

Senapathy recommends that offboarding checklists and access reviews should be right next to “return the laptop” on that list. The problem in this case is that the terminated employee had more access than most people, and so IT didn't know what they needed to cut off.

“Sadly, it could've been prevented by same-day deletion of access, forced re-review of shared account access and zero tolerance for one person owning a whole system alone,” he said.

This writer can identify with this situation. At a previous job, after I quit, I lost email, chat, and shared drive access, but months later my former boss asked if I could still log into an important database that was hosted externally and show him how to use it. I had no problems getting in.

Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request.®

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/03/terminated-employee-cost-company-hundreds-of-thousands-of-dollars-because-nobody-revoked-access/5292763