The Containment Era is here. →Explore

Executive Summary

In February 2025, twin brothers Muneeb and Sohaib Akhter, both 34 and former federal contractors, were terminated from their positions after their prior felony convictions for unauthorized access to U.S. State Department systems were discovered. Immediately following their dismissal, they accessed their employer's systems without authorization, deleting approximately 96 government databases containing sensitive information, including investigative documents and Freedom of Information Act records. They also attempted to cover their tracks by seeking guidance from an AI assistant on clearing system logs and wiping company-issued laptops before returning them. This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.

Why This Matters Now

This incident underscores the critical need for stringent access controls and monitoring mechanisms to prevent insider threats, especially from individuals with prior offenses. The case highlights the potential risks associated with rehiring individuals with a history of cyber offenses and the importance of comprehensive background checks and continuous monitoring to safeguard sensitive government data.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed deficiencies in access control and monitoring, allowing individuals with prior convictions to access and delete sensitive government data.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attackers' ability to exploit retained credentials, move laterally, and exfiltrate sensitive data, thereby reducing the overall impact.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Implementing Aviatrix CNSF would likely have constrained the attackers' ability to utilize retained credentials by enforcing strict identity-based access controls.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust Segmentation would likely have restricted the attackers' ability to escalate privileges by enforcing least-privilege access to critical systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security would likely have constrained lateral movement by monitoring and controlling internal traffic between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control would likely have detected and alerted on unauthorized activities, such as consulting external AI assistants for malicious purposes.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement would likely have restricted unauthorized data exfiltration by controlling outbound traffic.

Impact (Mitigations)

Implementing Aviatrix Zero Trust CNSF would likely have reduced the overall impact by limiting unauthorized access and actions within the network.

Impact at a Glance

Affected Business Functions

  • Freedom of Information Act (FOIA) Processing
  • Investigative Operations
  • Data Management
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: N/A

Data Exposure

Sensitive investigative documents and Freedom of Information Act records from multiple federal agencies.

Recommended Actions

  • Implement strict access controls and immediately revoke credentials upon employee termination to prevent unauthorized access.
  • Enforce Zero Trust Segmentation to limit lateral movement within the network and restrict access to critical systems.
  • Deploy Threat Detection & Anomaly Response systems to identify and respond to unauthorized activities promptly.
  • Utilize Multicloud Visibility & Control to monitor and manage access across all cloud environments.
  • Establish comprehensive audit logging and monitoring to detect and investigate suspicious activities effectively.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image