Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
- ID
- 20948
- Status
- summarized
- Published
- 03 Sep 2026, 3:00 PM
- Fetched
- 03 Sep 2026, 3:09 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/03/terminated-employee-cost-company-hundreds-of-thousands-of-dollars-because-nobody-revoked-access/5292763
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 5.5
- Created
- 03 Sep 2026, 3:09 PM
- Tags
- Audience
- developerssaas_founders
What happened
A terminated employee at a 1,000+ person company retained active credentials for several days because HR and IT each assumed the other would revoke access. The ex-employee deleted files, locked out other accounts, and corrupted a database, causing hundreds of thousands of dollars in damage and weeks of project delay. Recovery was slow because the person who damaged the systems knew them best.
Why it matters
If you run a startup or small team, assign a single named owner for credential revocation on termination day and enforce shared-admin-credential rotation as part of offboarding. The failure here wasn't a hack—it was a gap between HR and IT where nobody was responsible, and shared admin credentials meant one person's departure cascaded across multiple systems.
Discussion angle
What does your offboarding checklist actually look like right now—who is the named owner for cutting access, and do you have shared admin credentials that survive a departure?