GoFirm
Back to Blog
Case Studies·3 min read

A fired employee's database access should have ended the moment the meeting did. At Opexus, it did not.

By GoFirm

On 18 February 2025, Opexus, the Washington, D.C.-based contractor that sells case management software to more than 45 U.S. federal agencies and hosts government data on servers in Ashburn, Virginia, fired twin brothers Sohaib and Muneeb Akhter during a remote video call. The company had just discovered that Sohaib was a convicted felon, the product of a decade-old case in which both brothers had pleaded guilty to hacking the U.S. State Department. Both still held privileged access to Opexus systems, including the software behind the Equal Employment Opportunity Commission's (EEOC) Public Portal, when the call ended.

The retaliation had, in one sense, already begun before the brothers even knew they were being fired. Seventeen days earlier, on 1 February 2025, Muneeb had asked Sohaib for the plaintext password of a member of the public who had submitted a complaint through the EEOC portal. Sohaib ran a database query, retrieved it, and passed it on. Muneeb used the password to access that person's email account without authorisation, weeks before either brother had been told they would lose their jobs.

Immediately after the termination call on 18 February, the brothers turned their still-live access on their employer and its government customers. Over the following hours they accessed computers without authorisation, write-protected databases to stop them being recovered, deleted the databases outright, and worked to destroy evidence of what they had done. By the time it stopped, approximately 96 databases holding U.S. government information, including the case management and Freedom of Information Act response processing software that federal agencies depended on, had been deleted. FOIA systems at multiple agencies were disrupted as a direct result.

This is not an isolated case. The Identity Theft Resource Center's mid-year report found insider wrongdoing incidents rose to 21 in the first half of 2026, seven times the three recorded in all of 2025, driven partly by tech-sector layoffs. A termination meeting is, on that data, an increasingly common precursor to a deliberate, high-privilege act of sabotage, not a clean end to an employment relationship.

The defences that failed here were not weak by conventional standards. Opexus said the brothers had passed the seven-year background check required at the time of hire; the felony that surfaced predated that window. Its termination process itself was conventional too: a documented meeting, a clear decision, delivered directly to the employees concerned. What was missing was any control over what happened to their system access in the minutes after that meeting ended, while both men could still reach the databases they went on to destroy.

Revoking privileged access is an execution event, and it should happen before an employee is told they are losing their job, not after. Before a termination meeting begins for someone holding standing access to production databases, that access should already be suspended, pending a confirmation from a named security authority to restore it if the meeting goes differently than planned.

A fired employee, however aggrieved, cannot produce a confirmation from an authority who no longer trusts them. Neither can a co-conspirator working from the outside. The execution boundary holds regardless of how much time passes between the moment someone learns they are out and the moment they decide to do something about it.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence
. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References


1. U.S. Department of Labor, Office of Inspector General. 2026. Federal jury convicts Alexandria man on charges relating to the deletion of U.S. Government databases. DOL OIG, 7 May 2026.
2. DiMolfetta, D. 2026. EEOC experienced security incident involving contractor's 'unauthorized' access, email says. Nextgov/FCW, 8 January 2026.
3. Identity Theft Resource Center. 2026. ITRC: Malicious insiders surge as H1 2026 data compromises set pace for record year. ITRC, 22 July 2026.

Share this article