Fired Brothers Wipe 96 US Gov Databases in 5-Minute Revenge Attack
Twin brothers Muneeb and Sohaib Akhter, both 34, have been accused of destroying 96 databases holding US government information within minutes of being fired from their Washington, DC employer—a firm that sold software and services to 45 federal clients. According to court documents, the brothers were terminated via Microsoft Teams at 4:50 PM on February 18, 2025. While Sohaib's VPN access and Windows account were promptly deactivated, Muneeb's account was overlooked. By 4:56 PM—just six minutes after the call ended—Muneeb had accessed a US government database maintained by the company, issued commands to block other users, and executed a deletion. He continued wiping databases at 4:58 PM and beyond, allegedly erasing critical federal records and disrupting government operations.
The incident exposes a serious failure in identity lifecycle management and offboarding procedures. The breach wasn't a one-off; investigators allege the brothers had a long history of credential abuse. On February 1, 2025, Muneeb asked Sohaib to extract the plaintext password of an Equal Employment Opportunity Commission (EEOC) complainant from the company's database. The password was then used to access that individual's email account without authorization. Investigators also found that Muneeb had harvested 5,400 username-password pairs from his own company's network and built custom Python scripts—including "marriott_checker.py"—to test those credentials against third-party sites like Marriott, DocuSign, and airline loyalty programs. He reportedly logged in successfully hundreds of times and used stolen airline miles to book personal travel, underscoring how reused passwords and weak credential segregation enable devastating downstream attacks.
The brothers weren't strangers to the justice system. In 2015, they pled guilty in Virginia to wire fraud and computer-related crimes; Muneeb served three years and Sohaib served two. Despite this, both were rehired into the federal-contracting tech sector—Muneeb in 2023, Sohaib a year later—raising broader questions about background-check rigor in companies handling sensitive government workloads. With Muneeb's account remaining active after termination, the employer effectively handed an insider threat the keys to dozens of federal systems. Victims of similar credential-exposure incidents can verify whether their email addresses appear in known leaks and rotate any reused passwords immediately to limit blast radius.