Executive Summary
In February 2024, Opexus, a federal IT services provider, suffered a significant internal data breach at the hands of recently terminated employees, Muneeb and Sohaib Akhter. Despite passing standard background checks, the Akhter twins—who had prior convictions for cybercrimes—were able to exploit their insider access minutes after being fired, deleting and exfiltrating sensitive data from U.S. government agencies, including DHS, IRS, and EEOC. Key company missteps included inadequate offboarding controls, missed red flags in hiring, and delayed user account revocation, compounding the impact on critical federal data and operations.
This breach underscores rising risks linked to insider threats, especially among trusted staff with privileged access. Failures in vetting, change management, and technical safeguards contributed to the severity and highlight the urgent need for robust zero trust, continuous monitoring, and improved personnel screening, particularly for organizations entrusted with sensitive public sector data.
Why This Matters Now
High-profile insider breaches are on the rise, exposing gaps in both technical defenses and HR processes—even in regulated, government-facing industries. As more attacks involve disgruntled or overlooked insiders with privileged access, organizations must urgently enhance their background checks, enforce real-time access revocation, and implement stronger zero trust controls to safeguard critical and sensitive data.
Attack Path Analysis
The attack began with the insiders using valid credentials after employment termination to re-access company systems (Initial Compromise). Leveraging their privileged access, they maintained or elevated permissions necessary to reach sensitive production data (Privilege Escalation). They then pivoted laterally across Opexus's infrastructure to access databases and data for multiple federal agencies (Lateral Movement). Upon maintaining access and evading detection, they issued commands to copy, delete, and possibly transfer sensitive files (Command & Control). Sensitive government data was exfiltrated, including personally identifiable information and investigative files (Exfiltration). Finally, the attackers deleted large volumes of data, disrupting business operations and causing lasting organizational impact (Impact).
Kill Chain Progression
Initial Compromise
Description
Muneeb Akhter accessed Opexus’s computer network using valid credentials minutes after employment termination, exploiting a gap in access revocation procedures.
Related CVEs
CVE-2026-22233
CVSS 5.5OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the 'Estimated Staff Hours' field, leading to stored cross-site scripting (XSS).
Affected Products:
OPEXUS eCASE Audit – All versions prior to 2026-01-08
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Data Destruction
Transfer Data to Cloud Account
Data Manipulation
Indicator Removal
Account Discovery
Account Manipulation
Disabling Security Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Identification and Authentication
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA (EU Digital Operational Resilience Act) – ICT Security and Resilience Mechanisms
Control ID: Art 9(2)
CISA ZTMM 2.0 – User De-provisioning Effectiveness
Control ID: Identity Pillar – Termination and De-provisioning
NIS2 Directive – Access Control and Data Protection
Control ID: Art 21(2) – Technical and Organisational Measures
ISO/IEC 27001:2022 – Removal or Adjustment of Access Rights
Control ID: A.9.2.6
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal contractor insider threats expose critical vulnerabilities in background screening processes, compromising sensitive data across multiple agencies including DHS and IRS.
Information Technology/IT
Government IT contractors face elevated insider threat risks requiring enhanced zero trust segmentation, threat detection capabilities, and comprehensive access control frameworks.
Computer Software/Engineering
Software engineering firms managing government data need robust egress security, anomaly detection systems, and immediate access revocation protocols to prevent insider attacks.
Financial Services
IRS data breach demonstrates critical need for encrypted traffic protection, threat detection systems, and enhanced background verification for personnel accessing financial records.
Sources
- Opexus claims background checks missed red flags on twins accused of insider breachhttps://cyberscoop.com/opexus-background-checks-insider-attack-muneeb-sohaib-akhter/Verified
- Twin Brothers Sentenced for Wire Fraud, Conspiring to Hack into U.S. Department of State and Private Companyhttps://www.justice.gov/usao-edva/pr/twin-brothers-sentenced-wire-fraud-conspiring-hack-us-department-state-and-privateVerified
- Government Data Wiped by Insider Hackers in OPEXUS Security Breachhttps://www.adminbyrequest.com/en/blogs/government-data-wiped-by-insider-hackers-in-opexus-security-breachVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, rapid identity revocation, inline policy enforcement, and comprehensive egress visibility would have constrained or prevented insider abuse, contained lateral movement, and detected malicious data actions before major exfiltration or destruction. Controls tailored to segment workloads and strictly enforce access revocation can prevent terminated users from accessing sensitive systems.
Control: Zero Trust Segmentation
Mitigation: Terminated users are instantly isolated from sensitive cloud workloads.
Control: Multicloud Visibility & Control
Mitigation: Abnormal privilege use and redundant admin access are quickly detected.
Control: East-West Traffic Security
Mitigation: Lateral connections between unrelated workloads are blocked by default.
Control: Threat Detection & Anomaly Response
Mitigation: Malicious or unusual command executions are identified and responded to in real time.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorised outbound transfers are denied or logged for rapid response.
Destructive actions are blocked or pre-approved via distributed enforcement policies.
Impact at a Glance
Affected Business Functions
- Data Management
- Compliance Reporting
- Freedom of Information Act Processing
Estimated downtime: 30 days
Estimated loss: $5,000,000
Sensitive investigative files and records related to Freedom of Information Act matters were deleted, affecting multiple federal agencies including the Department of Homeland Security, Internal Revenue Service, and the Equal Employment Opportunity Commission.
Recommended Actions
Key Takeaways & Next Steps
- • Immediately implement identity-based segmentation and automated access revocation to eliminate lingering credentials after employee termination.
- • Enforce east-west microsegmentation to contain lateral movement between sensitive workloads and agency-specific data environments.
- • Deploy robust egress controls and encrypted traffic monitoring to detect and block unauthorized data exfiltration attempts.
- • Centralize multicloud policy visibility and automate threat detection to rapidly identify anomalous or destructive actions by privileged users.
- • Regularly test incident response procedures and privilege audits to ensure policy alignment with Zero Trust and CNSF best practices.



