Why were they storing passwords in plaintext in the databases?!
post
Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.
I'm not gonna say there were signs that these two weren't the most law abiding of citizens to begin with, buuuuut...
I briefly worked with a government client that would bring in prison laborers to collect trash. From the IT building of the tax agency.
But don't worry, they were just white collar criminals. You know, people who only went to jail for stealing... financial data... The very thing that was accessible in that building.
Genius.
Oh I'm sure the government loved taking them, since >Half of all Politicians are corrupt fraudsters.
Company only paid for a 7 year background check, so you mis them getting out of prison 8 years ago.
And why couldn’t they have done that to the student loans system?
Like JFC, they could have instantly made themselves immune from trial-by-jury anywhere in America by doing that one tiny thing.
Probably not one of the 96(+) databases they had :(
DROP TABLE students
Student loans are loans from third party lenders which are cosigned by the federal government for collateral.
Even if every government record of it were destroyed, the loan servicers would have perfect multiple ledger copies of it all.
Peter Thiel probably has a backup copy now from doge unfortunately.
Wasn't that a premise in Mr Robot?
Muneeb Akhter asked Sohaib Akhter for the plaintext password
The more scary part in this story is that the government stores your passwords in plain text!
So basically ANYONE with access to the database can steal your credentials, including employees, the government and any authorities.
Never re-use passwords.
Every place I have worked, most of HR and like half of finance/accounting has access to your social security number, full address and phone number. Sometimes even the password and security questions you used for whatever BS portal they made you setup an account in.
Never heard of hashing and salting apparently
To be fair, what else could they do with that keyboard.

Only a living wage can prevent data dumps.
Upper management can't even see it...yet.
In a row?!
Try not to delete any databases on your way to the parking lot!
But I explicitly stated in the CLAUDE.md employee guidelines to not delete production databases!
"I can't go out for a pack of smokes without running into 9 databases that you dropped!"
“Eh, they can recover from yesterday,” he said, referring to daily database backups.
But did they recover from backups? Don't leave the most juicy intrigue out of the story.
Its always interesting when people are both very smart and also very stupid at the same time.
Knowledgeable and smart are not the same thing. These two are very knowledgeable about the systems they worked on and database manipulation, believe it or not these are not hard skills to learn. But they were incredibly dumb regardless given every single action they took at every point in their lives.
Fun fact. In psychology assessment this are being called hard skills: very technical abilities for doing specialized tasks; and soft skills: social and emotional abilities to navigate social contexts, manage conflict and self regulate emotions.
Hard skills are easier to teach, while soft skills are very hard.
Muneeb and Sohaib Akhter, now both 34, had been in trouble before. Back in 2015, the brothers pled guilty in Virginia to a scheme involving wire fraud and computers. Muneeb was sentenced to three years in prison, while Sohaib got two.
They had a track record and found employment in government IT
HR should've been fired for that fuckup.
A case study in why credentials are revoked before firings.
No. A case study against employing known criminals.
top 50 comments