Twin brothers wipe 96 government databases minutes after being fired

(arstechnica.com)

41 points | by jnord 12 hours ago ago

13 comments

  • chatmasta 10 hours ago ago

    > At 4:58 pm, he wiped out a Department of Homeland Security database using the command “DROP DATABASE dhsproddb.”

    This article is hilarious. The two bickering brothers remind me of the guys in the Oceans movies played by Casey Affleck and Scott Caan. It’s amazing they got this close to sensitive data.

    • johnbarron 7 hours ago ago

      I think its them on video: https://youtu.be/Rx19zOzQeis

    • bmitc 9 hours ago ago

      Those two in the movies were always a highlight for me, especially when the one joins the other in the Mexican factory riot.

  • chrisra 11 hours ago ago

    I have no problem with my credentials being revoked everywhere before I know about a layoff. I don't really care how I learn about it, just please don't make me come in to the office.

    • ccimmergreen 8 hours ago ago

      So this was why the FBI Director Kash Patel was in a panic when he couldn't log in one day. Revoking credentials before firing someone makes a lot of sense in security.

      • metalman 2 hours ago ago

        no, becaus the simple and pragmatic solution for ANYONE who is subject to arbitrary termination, is to litter everything they build with caltrops and dead man triggers and then hint that they will go into "consulting" when fired.

        I know of one case where this was totaly unintentional, and a machinest at a local pulp and paper plant had self delegated to write the software that controlled tension on the giant machines in the mill, but as it was his only real forey into sofware, nobody else could operate it, and they fired him after a manegment reshuffle, and then after the next scheduled shut down, nothing worked right, greasy dusty ancient screen with a blinking cursor was what they had, plugged into the important bits of a half sqare mile plant. still funny to think about!

    • xingped 10 hours ago ago

      Oh don't worry, inconvenience and abject humiliation is standard fare for firings in the US. You don't even have to pay extra! Isn't that great?!

  • kaikai 11 hours ago ago

    How on earth did someone previously convicted of what sounds like hacking get job access to so many prod government databases? Wild that it took them so long to get caught.

  • waterTanuki 10 hours ago ago

    > On Feb. 1, 2025, Muneeb Akhter asked Sohaib Akhter for the plaintext password of an individual who submitted a complaint to the Equal Employment Opportunity Commission’s Public Portal, which was maintained by the Akhters’ employer. Sohaib Akhter conducted a database query on the EEOC database and then provided the password to Muneeb Akhter. That password was subsequently used to access that individual’s email account without authorization.

    It should be a federal crime with prison time to make a DB for a federal agency and not hash and salt passwords or other auth credentials.

  • cyanydeez 11 hours ago ago

    so, apparently, the passwords were stored in cleartext.

    • whynotmaybe 9 hours ago ago

      Remind me of a forum a long time ago that sent me my password in clear when I used the "forgot password" link.

      When I advised them that it was a bad idea to store password in clear, they answered that they keep it in clear so that they can send it when someone forget.

      Defeated by such argument, I deleted my account.

      • scorpioxy 6 hours ago ago

        I've got a better one. I once had the same argument mentioned to me by my manager at the time when I pointed out that passwords were being stored in clear text. That it needs to be this way so that it is read/sent when the users forget their passwords(which happened a lot). I tried to explain that typically a "reset password" flow is used for that but that fell on deaf ears. That system contained healthcare data.

        Something bad did end up happening due to that lax security and there were oh so many meetings about it.

  • iJohnDoe 7 hours ago ago

    It’s crazy that people are desperate for jobs and these clowns get hired.