Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
A former IT worker, Yad Senapathy, has described how a company he once worked for lost hundreds of thousands of dollars after a terminated employee's system access was never revoked. Confusion between HR and IT over who was responsible for cutting off credentials meant the ex-employee could log back in for several days, deleting files, locking out colleagues and corrupting a database in an act of revenge. The case highlights how gaps in offboarding processes, rather than sophisticated hacking, remain a major source of costly security incidents.
The affected company had more than 1,000 employees, and the terminated worker held wide-ranging access, including shared admin credentials, account controls and project tracking systems, which cascaded into further systems. Recovery was made harder because the employee responsible for the damage was also among those best placed to fix it, adding weeks of delay to an important project. Senapathy recommends same-day revocation of access, mandatory reviews of shared account permissions, and avoiding letting a single person hold sole ownership of critical systems.
- Nobody revoked a fired employee's system access for days.
- Ex-worker deleted files, locked accounts, corrupted a database in revenge.
- Damage cost hundreds of thousands of dollars plus project delays.