Executive Summary
In February 2025, twin brothers Muneeb and Sohaib Akhter, both 34 and former federal contractors, were terminated from their positions after their prior felony convictions for unauthorized access to U.S. State Department systems were discovered. Immediately following their dismissal, they accessed their employer's systems without authorization, deleting approximately 96 government databases containing sensitive information, including investigative documents and Freedom of Information Act records. They also attempted to cover their tracks by seeking guidance from an AI assistant on clearing system logs and wiping company-issued laptops before returning them. This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.
Why This Matters Now
This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.
Attack Path Analysis
After being terminated, the Akhter brothers exploited their existing access to the contractor's systems to delete approximately 96 government databases, including sensitive investigative documents and Freedom of Information Act records. They issued commands to prevent others from modifying the databases before deletion and destroyed evidence of their activities. Additionally, they sought to cover their tracks by consulting an AI assistant on clearing system logs and wiped company laptops before returning them.
Kill Chain Progression
Initial Compromise
Description
The Akhter brothers, as former employees, retained access to the contractor's systems post-termination, allowing them to exploit their existing credentials.
MITRE ATT&CK® Techniques
Valid Accounts
Account Manipulation
Data Destruction
Indicator Removal on Host: Clear Windows Event Logs
Data Manipulation: Stored Data Manipulation
Indicator Removal on Host: File Deletion
Indicator Removal on Host: Clear Linux or Mac System Logs
Indicator Removal on Host: Clear Command History
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Account Management
Control ID: AC-2
PCI DSS 4.0 – Limit Access to System Components and Cardholder Data
Control ID: 7.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA Zero Trust Maturity Model 2.0 – Identity Governance
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct target of insider threat database destruction affecting 96 federal databases, requiring enhanced zero trust segmentation and egress security controls.
Information Technology/IT
IT contractors face heightened insider threat risks from privileged access abuse, necessitating multicloud visibility and anomaly detection capabilities.
Computer/Network Security
Security providers must strengthen threat detection systems against insider attacks targeting database integrity and evidence destruction through encrypted traffic monitoring.
Legal Services
Law enforcement databases containing sensitive investigative documents were compromised, requiring enhanced data protection and egress policy enforcement mechanisms.
Sources
- Former govt contractor convicted for wiping dozens of federal databaseshttps://www.bleepingcomputer.com/news/security/former-govt-contractor-convicted-for-wiping-dozens-of-federal-databases/Verified
- Two Virginia Men Arrested for Conspiring to Destroy Government Databaseshttps://www.justice.gov/opa/pr/two-virginia-men-arrested-conspiring-destroy-government-databasesVerified
- In comedy of errors, men accused of wiping gov databases turned to an AI toolhttps://arstechnica.com/information-technology/2025/12/previously-convicted-contractors-wiped-gov-databases-after-being-fired-feds-say/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attackers' ability to exploit retained credentials, move laterally, and exfiltrate sensitive data, thereby reducing the overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix CNSF would likely have constrained the attackers' ability to utilize retained credentials by enforcing strict identity-based access controls.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely have restricted the attackers' ability to escalate privileges by enforcing least-privilege access to critical systems.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely have constrained lateral movement by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely have detected and alerted on unauthorized activities, such as consulting external AI assistants for malicious purposes.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely have restricted unauthorized data exfiltration by controlling outbound traffic.
Implementing Aviatrix Zero Trust CNSF would likely have reduced the overall impact by limiting unauthorized access and actions within the network.
Impact at a Glance
Affected Business Functions
- Freedom of Information Act (FOIA) Processing
- Investigative Operations
- Data Management
Estimated downtime: 14 days
Estimated loss: N/A
Sensitive investigative documents and Freedom of Information Act records from multiple federal agencies.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strict access controls and immediately revoke credentials upon employee termination to prevent unauthorized access.
- • Enforce Zero Trust Segmentation to limit lateral movement within the network and restrict access to critical systems.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to unauthorized activities promptly.
- • Utilize Multicloud Visibility & Control to monitor and manage access across all cloud environments.
- • Establish comprehensive audit logging and monitoring to detect and investigate suspicious activities effectively.



