Other
Opexus Federal Contractor Insider Breach
Primary Source βIncident Details
Opexus, a Thoma Bravo-owned software company providing records management services to nearly every US federal agency, was compromised by twin brothers Muneeb and Suhaib Akhter who had prior criminal convictions (2015) for hacking the State Department and a cosmetics company. On February 18, 2025, during their termination meeting, the brothers retained access and deleted 96 government databases (including IRS and GSA data), and exfiltrated ~1,800 EEOC files to a USB drive. FOIA requests at numerous agencies were lost; some agencies suffered outages over a month. The breach went undisclosed for months; Senator Cassidy opened an investigation. Background check failures allowed convicted hackers to hold sensitive positions. Class action lawsuit filed against Opexus. Notable government contractor supply-chain insider threat case.
Technical Details
- Initial Attack Vector
- Insider threat: two employees (twin brothers) with prior hacking convictions retained privileged access; exfiltrated files via USB drive and deleted government databases during and after termination meeting
Timeline
- 2025-02-18 Breach occurred
- 2025-05-21 Publicly disclosed