96 Databases Deleted: A Recent Insider Threat Case Every Business Should Learn From

Insider threats can sometimes sound like an abstract cybersecurity problem—until a real-world incident demonstrates how quickly trusted access can become a serious vulnerability.

In May 2026, a federal jury convicted a former employee of a technology company that provided software products and services to more than 45 U.S. government agencies. The case provides businesses with a timely reminder that cybersecurity is not only about keeping unauthorized outsiders out. Organizations must also manage what trusted individuals can do once they are inside.

What Happened?

According to the U.S. Department of Justice, Sohaib Akhter and his twin brother worked for a Washington, D.C.-area technology company that hosted data for federal government customers.

Before their termination, prosecutors presented evidence that Sohaib Akhter accessed an Equal Employment Opportunity Commission database and provided another individual’s password to his brother. That password was later used to access the individual’s email account without authorization.

The situation escalated dramatically after the company terminated both employees during a remote meeting in February 2025.

According to the Justice Department, immediately following their termination, the brothers attempted to harm their former employer and its government customers. Their activities included accessing computers without authorization, write-protecting databases, deleting databases, and attempting to destroy evidence.

Over several hours, approximately 96 databases containing U.S. government information were deleted.

In May 2026, a federal jury convicted Sohaib Akhter of conspiracy to commit computer fraud, password trafficking, and an unrelated firearms offense.

The Insider Threat Lesson

This case illustrates something every organization should consider:

What could someone do with their access if their relationship with your company changed tomorrow?

Businesses naturally give employees access to the systems and information necessary to perform their jobs. IT administrators, developers, managers, contractors, and other employees may have particularly significant privileges.

The risk is not necessarily that these individuals are currently untrustworthy.

The risk is what happens when legitimate access is excessive, poorly monitored, shared, forgotten, or not removed quickly enough.

An employee may need access today but not tomorrow. A contractor may complete a project but retain credentials. An administrator may have permissions far beyond what is necessary for a particular task.

These situations create opportunities for insider threats.

Insider Threats Are Not Always Malicious

It is also important for organizations to understand that insider threat mitigation is not simply about catching employees intentionally trying to cause harm.

Insider incidents can result from negligence, mistakes, compromised credentials, excessive privileges, poor security practices, or intentional misconduct.

An employee might accidentally send sensitive information to the wrong person. Someone may fall victim to a phishing attack and unknowingly provide credentials to an outside attacker. A former employee’s account may remain active after departure.

Different circumstances, but the underlying problem is similar: trusted access creates risk when it is not appropriately managed.

Would Your Organization Catch the Warning Signs?

The 2026 case raises questions that businesses of every size should be asking:

Who currently has privileged access to critical systems?

Are employees able to access information unrelated to their responsibilities?

Are administrative actions logged and reviewed?

Are accounts immediately disabled when an employee leaves?

Does the organization have procedures for high-risk or involuntary terminations?

Are credentials shared between employees?

Are third-party and contractor accounts reviewed regularly?

Would the company recognize unusual downloading, database activity, or access attempts before significant damage occurred?

If an organization cannot confidently answer these questions, its insider threat program may have gaps.

Insider Threat Mitigation Is More Than Monitoring Employees

An effective insider threat program combines people, processes, and technology.

Organizations should establish access controls based on job responsibilities, regularly review permissions, monitor privileged activity, create clear onboarding and offboarding procedures, educate employees about security responsibilities, and establish processes for reporting concerning activity.

Just as importantly, departments cannot operate independently.

Human Resources may know an employee is leaving before IT does. IT may identify unusual account activity without understanding the employee circumstances surrounding it. Management may recognize concerning behavior without realizing it could have cybersecurity implications.

Connecting those pieces can help an organization recognize risk earlier.

How TMPC Can Help

Small and mid-sized businesses may recognize insider threats as a concern but struggle with determining where to begin.

TMPC can help organizations develop an insider threat program appropriate for their size, operations, workforce, and risk environment.

That begins with understanding what the organization is protecting and who has access to it.

TMPC can assist organizations in identifying critical assets, evaluating existing access and security practices, identifying potential vulnerabilities, developing insider threat policies and procedures, strengthening employee onboarding and offboarding processes, assessing third-party risk, and establishing practical mitigation strategies.

The objective is not to treat every employee as a potential threat.

It is to create an environment where access is appropriate, unusual activity can be identified, responsibilities are clearly defined, and the organization has a plan when something goes wrong.

The Question Isn’t Whether You Trust Your Employees

Trust is necessary for any organization to operate.

But trust should not replace security controls.

The recent federal case demonstrates how quickly legitimate access can become a serious organizational vulnerability when circumstances change. Approximately 96 databases were allegedly deleted within hours following the employees’ termination.

For a small business, an incident does not need to reach that scale to be devastating.

The better question is not simply, “Do we trust the people who have access?”

It is:

“If that access were misused tomorrow, would we be prepared?”

TMPC can help businesses answer that question before an incident provides the answer for them.