"Several days passed where the person was no longer on payroll, but their credentials were still active," Senapathy said.
That sentence, from Yad Senapathy — now CEO of the Project Management Training Institute in Dallas, Texas, recalling an earlier role in IT at a company with more than 1,000 employees — is the hinge of a costly administrative failure. An employee was terminated, nobody promptly revoked access, and the result was deletion of files, locked accounts, a corrupted database and recovery costs that Senapathy says ran into "hundreds of thousands of dollars." The incident also added weeks of delay to a high-priority project and created an awkward recovery problem: the person who broke the systems knew them best.
Shared admin credentials and project-tracking systems were compromised
According to Senapathy's account to The Register, the terminated worker retained active credentials long enough after leaving payroll to log back into internal systems. Those credentials were not limited to a single service; the employee had access to shared admin credentials, account controls, and project tracking systems. Each of those systems in turn granted permission to other systems, creating a domino effect of inappropriate access that the former worker exploited to "wreak revenge on the whole organization."
Senapathy emphasized that the problem was not an exotic technical hack. "The employee wasn't some genius hacker. They just still had access after they left and nobody changed the credentials or reviewed admin rights," he told The Register. In short: excessive centralized knowledge and unrevoked access, not novel malware, produced the damage.
Hundreds of thousands of dollars and weeks of delay
Senapathy estimated the financial hit at "hundreds of thousands of dollars," and he said the operational impact stretched project timelines by weeks. Recovery was made more difficult because the same individual who caused much of the damage "best knew how to repair them," prolonging downtime and complicating restoration efforts.
The combination of monetary loss and delayed deliverables illustrates how administrative lapses translate into measurable business outcomes when account controls are not promptly enforced after termination.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhy nobody cut off access: HR, IT and the missing handoff
The incident reflected a failure of responsibility rather than a single mistaken click. Senapathy described a breakdown in the handoff between human resources and IT: HR expected IT to handle access closure once termination paperwork was processed; IT expected a formal request from HR. "I've learned that when nobody is clearly responsible and there is no set deadline, these things can easily get missed until there is already a problem," he said.
That ambiguity meant there was no single, time-bound owner for the crucial task of disabling accounts and changing shared credentials. Because one person "collect[ed] so much system knowledge," shutting the door behind them "took longer than it should have," Senapathy said.
Yad Senapathy's prevention checklist
- Place offboarding checklists and access reviews alongside hardware returns ("right next to 'return the laptop'"), Senapathy recommends.
- Same-day deletion of access: Senapathy said the issue "could've been prevented by same-day deletion of access."
- Forced re-review of shared-account access and "zero tolerance for one person owning a whole system alone," he added.
Those recommendations frame the failure as a process and governance problem rather than a purely technical one: identify accountable parties, set deadlines, and remove excessive single-person control.
What this means for HR, IT, and project managers
- HR: Expect to be the trigger for access revocation, and that trigger must include a formal, time-bound request to IT; otherwise HR and IT assumptions can cancel each other out.
- IT: Beware of hidden single points of control. Shared admin credentials and individual "system owners" require periodic review and immediate revocation when an employee departs.
- Project managers: Understand that a single individual's access can affect timelines across connected systems — weeks of delay and large recovery bills followed here.
The Register's PWNED column also included a secondary anecdote from its writer: after quitting a job they lost email, chat and shared drive access, but months later their former boss asked if they could still log into an externally hosted important database — and they had no problem getting in. That aside, the core of Senapathy's lesson is blunt: when nobody is clearly responsible for offboarding and shared credentials remain unchanged, the organization leaves an open door.
Ultimately, this is a case where organizational clarity — who flips the switch, when — would have mattered more than technical wizardry. The bill was large, the delays real, and the bitter irony was that the person who best understood how to fix the systems had already used that knowledge to break them.




