Terminated employee cost company hundreds of thousands of dollars because nobody revoked access

A former employee caused significant financial damage to their previous company by exploiting unrevoked system access. The incident highlights the critical need for robust offboarding procedures in IT security.
Why it matters
It underscores the high cost of poor identity and access management (IAM) practices in corporate environments.
They had more access than the average Joe, and IT didn't track what needed to be cut off
PWNED Welcome back to PWNED, where we talk about organizations that are independently self-owned. This week’s tale of toxic tech involves a disgruntled ex-employee who had the means and opportunity to wreak havoc.
Our story comes courtesy of Yad Senapathy, who serves as CEO of the Project Management Training Institute in Dallas, Texas. He recalls a time many years ago when he used to work in IT at a company with more than 1,000 employees.
While Senapathy was working there, the company terminated an employee, but nobody cut off his access to internal systems. The angry worker logged back in, then deleted files, locked out other people's accounts, and even corrupted a database.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in