Dismissed employees often leave active accounts in internal systems, and these become a loophole for attackers. As Ilona Kokova, a leading information security expert at MWS Cloud, told RIA "Novosti", hackers can gain access to corporate infrastructure through such access points.
Using someone else's account, one can download internal correspondence and documents, modify or delete data. Stolen information is published in the public domain, sold, or used for blackmail and extortion. In addition, a former employee's account allows attacking other employees and moving further through the network.
Often, a vulnerability arises when an employee created a shared workspace, invited colleagues, and after dismissal, their account remained active. The team continues to use the service, and the old account becomes an entry point for fraudsters. To reduce risks, the expert advises regularly reviewing access rights, disabling accounts immediately after dismissal, and limiting contractor access to the project's duration.
It is also recommended to apply the principle of least privilege – giving employees only the rights necessary for current tasks. This reduces the likelihood of data leaks and makes it more difficult for attackers to penetrate the company's infrastructure.
Read more on the topic:
- Scammers use AI to fake voices and write "personal" messages
- Hackers are Attacking More and More: Banks Allocate up to 45 Billion Rubles for Cybersecurity
- Fraudulent applications disguised as Ozon Bank appeared on Google Play