TWIN BROTHERS DESTROY 96 GOV'T DATABASES AFTER FIRING
INDUSTRY DESK■ 2 MIN READ
TUE, MAY 12, 2026■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE
Two brothers with system access deleted 96 government databases within minutes of being terminated from their IT positions. The incident highlights a critical security gap in credential management protocols.
The twins, employed as IT administrators, gained access to and systematically wiped multiple government databases immediately following their termination. Security officials confirmed the deletion of 96 separate databases across various systems before access could be revoked.
Investigations revealed the brothers retained active login credentials and administrative privileges even after receiving termination notices. The rapid succession of deletions—accomplished in minutes—suggests premeditation and intimate knowledge of the targeted systems.
This incident underscores a fundamental security vulnerability in many organizations: the failure to disable employee credentials before or during the termination process rather than after. Standard IT security protocol mandates revoking access before informing employees of their termination status.
Government agencies typically follow a sequence that includes:
- Disabling network access
- Revoking credentials
- Recovering equipment
- Documenting access revocation
- Only then conducting the termination meeting
In this case, credentials remained active, allowing the employees to execute destructive commands on critical systems. Recovery efforts are ongoing, with agencies assessing whether backup systems contain recoverable data.
The incident prompted immediate reviews of credential management practices across multiple government departments. Officials are examining other cases where terminated employees retained system access and identifying staff whose credentials have not been properly deactivated.
No statement has been released regarding potential charges against the brothers or recovery timelines for affected systems. The case has become a reference point in security training for proper termination procedures and access control management.
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
YESTERDAY— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
YESTERDAY— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
YESTERDAY— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
YESTERDAY— Security Desk