Terminated Employee's Unrevoked Access Causes Hundreds of Thousands in Damages
A former employee, whose system access was not revoked post-termination, caused significant financial and operational damage by deleting files and corrupting a database.

A critical failure in offboarding procedures led to a former employee causing hundreds of thousands of dollars in damages after their system access was not immediately revoked upon termination. The incident, recounted by Yad Senapathy, CEO of the Project Management Training Institute, highlights a dangerous gap in responsibility between HR and IT departments.
Senapathy, who worked in IT at a large organization, recalled a situation where a terminated employee remained active on internal systems for several days. This lapse occurred because HR believed IT would handle access revocation automatically, while IT was awaiting a formal request from HR. This communication breakdown allowed the disgruntled former worker to exploit their extensive knowledge of the company's infrastructure.
The former employee utilized shared administrative credentials and access to project tracking systems to wreak havoc. This included deleting crucial files, corrupting a vital database, and locking out other users. The cascading effect of this unauthorized access led to significant operational disruptions and financial losses, estimated to be in the hundreds of thousands of dollars.
Beyond the immediate financial impact, the incident caused weeks of delays on an important project. Compounding the problem, the recovery process was complicated by the fact that the systems were damaged by the very individual who possessed the intimate knowledge required for their repair. This underscores the risk of concentrating system knowledge within a single individual.
Senapathy emphasized that the former employee was not a sophisticated hacker but rather someone who simply retained access after their departure. The organization failed to change credentials or review administrative rights promptly, allowing the situation to escalate. This incident serves as a stark reminder of the importance of robust access management protocols.
To prevent similar occurrences, Senapathy advocates for immediate access revocation on the same day of termination, alongside regular reviews of shared account access. He also stressed the need to avoid situations where a single person holds sole responsibility for critical systems. Implementing clear offboarding checklists that prioritize credential revocation is essential.
The narrative also includes an anecdote from the article's author, who experienced a similar situation where their access to a critical external database remained active months after they had left a previous employer. This personal reflection further emphasizes the pervasive nature of such offboarding failures.
This incident underscores a fundamental cybersecurity principle: timely and complete deprovisioning of user access is as critical as robust security measures for active employees. The financial and operational costs of neglecting this process can be substantial, highlighting the need for clear policies, accountability, and efficient execution of offboarding procedures.