IT department put sticky notes on the laptops to help employees log in

← Back to the feed

IT department put sticky notes on the laptops to help employees log in

The Register · 1 hour ago

An IT department left temporary login credentials exposed on sticky notes attached to laptops during an office move, allowing an unauthorised contractor to photograph them and later access sensitive company data remotely. Marketing executive Marc Bishop, who shared the story with The Register's weekly "PWNED" column, said the company otherwise had a strong password policy and staff security training, but this basic error undermined its defences. The case highlights how poor handling of routine IT processes, rather than sophisticated attacks, often causes serious breaches.

The laptops, being prepared for reassignment to new starters, were stored in a conference room while facilities staff finished readying the new office. During that window, a contractor with access to the room took photos of the sticky notes bearing employee names and initial passwords, then used them to log in remotely and access proprietary planning documents on shared drives. The Register notes that even IT staff should not have visibility of user passwords, and recommends sending new credentials only via encrypted channels accessible solely to the intended recipient.

  • IT staff left login credentials on sticky notes on laptops
  • A contractor photographed the notes and later logged in remotely
  • Attacker accessed proprietary planning documents on shared drives

Art Culture Gadgets Technology

Read the full article at the source →