Executive Summary
In February 2024, twin brothers Muneeb and Sohaib Akhter exploited their privileged positions as contractors at Opexus, a government IT provider, to compromise, steal, and destroy sensitive data belonging to more than 45 federal agencies, including the Department of Homeland Security, IRS, and EEOC. The attack occurred minutes after the brothers were terminated, leveraging insider access to delete 96 critical databases, extract personally identifiable information, and disrupt ongoing investigations. Their methods reportedly included using AI to cover their tracks by clearing system and audit logs. The incident triggered a major federal investigation and prompted urgent responses from affected agencies, highlighting the impact of trusted insider abuse on national operations.
This breach exemplifies a growing trend of insider threats exploiting technical know-how and elevated access during termination events, intensified by the use of generative AI tools to evade detection. The case underscores the critical need for organizations handling sensitive federal data to implement rigorous access controls, continuous monitoring, and rapid offboarding processes to mitigate potential insider-driven damage.
Why This Matters Now
With organizations heavily relying on contractors and third-party vendors, insider breaches now present an acute risk, as technically skilled insiders can cause outsized harm before detection. The integration of AI tools into attack workflows escalates the urgency for continuous monitoring, zero trust enforcement, and automation in offboarding processes.
Attack Path Analysis
Insider actors with valid credentials abused their privileged access granted as government contractors to target critical federal databases. They may have elevated access rights or exploited weak internal controls to reach sensitive data sets and systems beyond their original roles. The actors traversed internal services and potentially leveraged database and application access for broader impact. They maintained local control of systems and employed covert guidance from AI tools for operational security, including log evasion. Sensitive government files were copied and exfiltrated, including IRS and EEOC data. In addition to data theft, the actors deleted or wiped key databases and production systems, causing significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
As trusted insiders, the attackers used existing valid credentials and direct system access from their employment as contractors to enter enterprise systems and database servers.
MITRE ATT&CK® Techniques
Valid Accounts
Impair Defenses: Disable or Modify Tools
Indicator Removal on Host: Clear Windows Event Logs
Windows Management Instrumentation
Transfer Data to Cloud Account
Data Destruction
Account Discovery
Valid Accounts: Domain Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 Rev. 5 – Least Privilege
Control ID: AC-6
PCI DSS 4.0 – User Identification and Authentication for All Users
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Security Policies and Procedures
Control ID: Art. 9(2)
CISA Zero Trust Maturity Model 2.0 – Identity Governance and Access Control
Control ID: Identity Pillar, Maturity Stage: Initial
NIS2 Directive – Access Control and Asset Management
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct victim of insider threat targeting DHS, IRS, and EEOC databases with privileged access exploitation requiring enhanced zero trust segmentation and anomaly detection.
Information Technology/IT
Government contractors face elevated insider threat risks from privileged users with database access, necessitating enhanced egress security and threat detection capabilities.
Computer/Network Security
Cybersecurity firms must strengthen multicloud visibility and encrypted traffic monitoring to detect insider threats leveraging AI tools for log manipulation.
Legal Services
Law firms handling FOIA requests and government matters face data theft risks requiring robust east-west traffic security and identity-based policy enforcement.
Sources
- Twins with hacking history charged in insider data breach affecting multiple federal agencieshttps://cyberscoop.com/muneeb-sohaib-akhter-government-contractors-insider-attack/Verified
- Two Virginia Men Arrested for Conspiring to Destroy Government Databaseshttps://www.justice.gov/opa/pr/two-virginia-men-arrested-conspiring-destroy-government-databasesVerified
- Defining Insider Threatshttps://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threatsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
This incident highlights the need for Zero Trust segmentation, rigorous east-west traffic controls, policy-driven egress security, and anomaly detection to curtail insider abuse. CNSF capabilities such as least privilege enforcement, high-fidelity traffic visibility, and distributed policy enforcement would have constrained data access, detected policy violations, and prevented exfiltration or destruction at several points in the kill chain.
Control: Zero Trust Segmentation
Mitigation: Limits initial access to only resources explicitly required by role.
Control: Multicloud Visibility & Control
Mitigation: Detects and alerts on privilege escalations or unusual permission assignments across multi-cloud and hybrid infrastructure.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized east-west connections between workloads containing critical data.
Control: Threat Detection & Anomaly Response
Mitigation: Monitors and flags anomalous processes, tool usage, or suspicious outbound queries indicative of covert control.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or alerts on unauthorized outbound data transfers, application-to-internet connections, or policy-violating egress.
Provides auditable, distributed policy enforcement with rapid detection of destructive actions.
Impact at a Glance
Affected Business Functions
- Data Management
- Information Security
- Government Operations
Estimated downtime: 7 days
Estimated loss: $500,000
Sensitive investigative files and records related to Freedom of Information Act matters were deleted, and personally identifiable information of at least 450 individuals was stolen.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and ensure least-privilege access across all cloud resources, including databases and sensitive internal applications.
- • Deploy continuous east-west traffic visibility and microsegmentation to prevent unauthorized lateral movement between workloads and sensitive data stores.
- • Implement centralized, policy-driven egress filtering to detect and block data exfiltration to unsanctioned external destinations, even by insiders.
- • Integrate advanced threat and anomaly detection to rapidly identify privilege misuse, log evasion attempts, and anomalous tool usage.
- • Establish distributed, auditable policy controls with real-time enforcement to detect and contain destructive insider actions before operational disruption occurs.



