The Containment Era is here. →Explore

Executive Summary

In February 2024, Opexus, a federal IT services provider, suffered a significant internal data breach at the hands of recently terminated employees, Muneeb and Sohaib Akhter. Despite passing standard background checks, the Akhter twins—who had prior convictions for cybercrimes—were able to exploit their insider access minutes after being fired, deleting and exfiltrating sensitive data from U.S. government agencies, including DHS, IRS, and EEOC. Key company missteps included inadequate offboarding controls, missed red flags in hiring, and delayed user account revocation, compounding the impact on critical federal data and operations.

This breach underscores rising risks linked to insider threats, especially among trusted staff with privileged access. Failures in vetting, change management, and technical safeguards contributed to the severity and highlight the urgent need for robust zero trust, continuous monitoring, and improved personnel screening, particularly for organizations entrusted with sensitive public sector data.

Why This Matters Now

High-profile insider breaches are on the rise, exposing gaps in both technical defenses and HR processes—even in regulated, government-facing industries. As more attacks involve disgruntled or overlooked insiders with privileged access, organizations must urgently enhance their background checks, enforce real-time access revocation, and implement stronger zero trust controls to safeguard critical and sensitive data.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident highlighted failures in identity and access management, inadequate background checks, delayed account revocation, and insufficient internal segmentation—all requirements under frameworks like NIST 800-53, ZTMM, PCI DSS, and HIPAA.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, rapid identity revocation, inline policy enforcement, and comprehensive egress visibility would have constrained or prevented insider abuse, contained lateral movement, and detected malicious data actions before major exfiltration or destruction. Controls tailored to segment workloads and strictly enforce access revocation can prevent terminated users from accessing sensitive systems.

Initial Compromise

Control: Zero Trust Segmentation

Mitigation: Terminated users are instantly isolated from sensitive cloud workloads.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Abnormal privilege use and redundant admin access are quickly detected.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral connections between unrelated workloads are blocked by default.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Malicious or unusual command executions are identified and responded to in real time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorised outbound transfers are denied or logged for rapid response.

Impact (Mitigations)

Destructive actions are blocked or pre-approved via distributed enforcement policies.

Impact at a Glance

Affected Business Functions

  • Data Management
  • Compliance Reporting
  • Freedom of Information Act Processing
Operational Disruption

Estimated downtime: 30 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Sensitive investigative files and records related to Freedom of Information Act matters were deleted, affecting multiple federal agencies including the Department of Homeland Security, Internal Revenue Service, and the Equal Employment Opportunity Commission.

Recommended Actions

  • Immediately implement identity-based segmentation and automated access revocation to eliminate lingering credentials after employee termination.
  • Enforce east-west microsegmentation to contain lateral movement between sensitive workloads and agency-specific data environments.
  • Deploy robust egress controls and encrypted traffic monitoring to detect and block unauthorized data exfiltration attempts.
  • Centralize multicloud policy visibility and automate threat detection to rapidly identify anomalous or destructive actions by privileged users.
  • Regularly test incident response procedures and privilege audits to ensure policy alignment with Zero Trust and CNSF best practices.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image