Latest
Post an AI Image and Unfriend MeShe Asked How to Publish Her Bedtime Story. They Called Her a Thief.The AI Hype Cycle: Why the Crash Is Coming, and Who’s Causing ItSix Claude Prompts That Get You Unstuck, and Why the Order MattersDogpiled Over AI Art at the Renaissance FaireClaude Opus 5.5: What the New Release Means for WritersTrump’s AI Force Is a Fire Department With No Fire CodeWhat It Costs to Fix an AI-Written ManuscriptWhen Your Memoir Should Be a NovelThe Hugging Face AI Agent Attack: An Operations ReadingWhen Your Own Memoir Sounds Like BraggingWhat Belongs on a Copyright PageWhat an AI Detector Score on Your Manuscript Is WorthThe Clients Who Pay and VanishThe Quotation Marks That Get Authors SuedThe Work You Would Never Have StartedMonthly or Milestone: How Ghostwriting Gets BilledWhen a Client Thinks the Ghostwriter Used AIThe One-Hour Call Before I Quote Your BookBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreBlack Tuesday: The Web Ring War Nobody Outside It NoticedThe Web Got Fenced: What AI Search Costs Small SitesWhat the AI Visibility Industry Sells, and What the Evidence Says
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

The Consultant We Fired for Cracking Our Passwords

This entry is part 47 of 53 in the series Technology
TL;DR: A PCI scan found L0phtCrack, a password-cracking tool, sitting on one of our servers. The trail led not to a hacker but to our own consultant. He needed passwords to do his job, and instead of asking, he cracked them. He succeeded, and he was fired the day we found out, because in security, intent doesn’t excuse the act. Insider threats come in flavors, and the well-meaning one teaches the sharpest lesson.

We found it during a PCI audit sweep. Scanning every system, as the audit required, we turned up a copy of L0phtCrack sitting on one of our servers. If you know the tool, you know the feeling: L0phtCrack is a password cracker, an unambiguous hacker utility, and it was inside our environment, on our hardware.

The first hours were pure panic response. A cracking tool on a server means someone put it there, and until you know who, you assume the worst: an intruder with a foothold, working your credential store while you hunt. We traced it down expecting a breach.

The call is coming from inside the house

The trail ended at one of our own consultants. He’d a job to do, the job required passwords, and we hadn’t given him passwords. Instead of asking for access, he installed a cracker and took it. And here’s the detail that matters: he succeeded. He got passwords. He got in. The tool worked exactly as designed, wielded by someone we’d invited into the building.

He wasn’t malicious. He was trying to do his job and chose the wrong path. It didn’t matter. We called him in, and he was let go immediately. Cracking credentials on a corporate network isn’t a judgment call, whatever the intent behind it. The act is the offense.

That firing taught the organization something no policy memo could: the rules bind everyone, including the people we hired for their expertise, including people whose motives were arguably clean. If intent excused the act, every attacker caught mid-breach would claim good intentions, and some of the most damaging insiders have them.

The other flavor

Insider threats don’t all look like an impatient consultant. At another company I worked with, a colleague in my group uncovered an employee cooking the books, systematic financial fraud from inside the organization. That one ended in prosecution and jail. At a third company, we discovered illegal pornography on an employee’s system; he was fired and the police were called in.

Three insiders, three motives: expedience, greed, and criminality. What they share is the thing perimeter security can’t address. Every one of them was already inside. Firewalls face outward. The consultant had legitimate access to the building, the fraudster had legitimate access to the ledgers, and no amount of perimeter hardening would have touched either.

An engineer cracked our passwords because asking felt slower. In security, good intent doesn’t excuse the act.
Share on X

Why do you never hear insider threat stories?

Why you never hear insider threat storiesThe silence around insider incidents is structural. Companies disclose external attacks because attackers are a shared enemy and victimhood is forgivable. Insider incidents implicate the company itself: its hiring, its oversight, its controls. A fraud case that ends in prosecution becomes public record, but most insider incidents end the way the consultant case and the pornography case ended, in quiet terminations that never touch a press release. Multiply that silence across every company and the picture the industry holds of its own threat landscape is systematically distorted toward the outside. The distortion has a budget consequence, because security spending follows the visible threat and therefore flows overwhelmingly toward the perimeter.Why insider stories never surfaceExternal attacks have a shared enemy. Insider incidents have a mirror.1External breachAttackers are a shared enemyVictimhood is forgivable, so it is disclosed2Insider incidentImplicates the hiring, the oversight,the controls. The company itself.3So it ends quietlyA termination that never touchesa press release4The picture distortsMultiplied across every company,the whole industry mis-sees its own riskSecurity spending follows the visible threat, which is why it flows overwhelmingly to theperimeter.
Why you never hear insider threat storiesThe silence around insider incidents is structural. Companies disclose external attacks because attackers are a shared enemy and victimhood is forgivable. Insider incidents implicate the company itself: its hiring, its oversight, its controls. A fraud case that ends in prosecution becomes public record, but most insider incidents end the way the consultant case and the pornography case ended, in quiet terminations that never touch a press release. Multiply that silence across every company and the picture the industry holds of its own threat landscape is systematically distorted toward the outside. The distortion has a budget consequence, because security spending follows the visible threat and therefore flows overwhelmingly toward the perimeter.Why insider stories neversurfaceExternal attacks have a shared enemy. Insiderincidents have a mirror.1External breachAttackers are a shared enemyVictimhood is forgivable, so it is disclosed2Insider incidentImplicates the hiring, the oversight,the controls. The company itself.3So it ends quietlyA termination that never touchesa press release4The picture distortsMultiplied across every company,the whole industry mis-sees its own riskSecurity spending follows the visible threat, whichis why it flows overwhelmingly to the perimeter.

Notice that you’ve read plenty about external breaches and almost nothing about incidents like these, and the silence is structural. Companies disclose external attacks because attackers are a shared enemy and victimhood is forgivable. Insider incidents implicate the company itself: its hiring, its oversight, its controls. The fraud case ended in prosecution, which is public record, but the consultant and the pornography case ended the way most insider incidents end, in quiet terminations that never touch a press release.

Multiply that silence across every company, and the industry’s picture of its own threat landscape is systematically distorted toward the outside.

The distortion has a budget consequence. Security spending follows the visible threat, so it flows overwhelmingly toward the perimeter, while the controls that actually caught our three insiders, comprehensive scanning, financial oversight, verification applied uniformly, get funded as compliance afterthoughts. I’m not arguing the perimeter is overfunded. I’m observing that the threat you never read about isn’t the threat you don’t have.

What catches insider threats?

Notice what found each one. The consultant was caught by a comprehensive scan, an audit control that inventoried every system without exceptions for systems presumed clean. The fraud was caught by financial oversight, the segregation-of-duties territory I cover in a companion article on documenting roles, not just rules. None were caught by trust, and none would have been caught by tools pointed at the internet.

The uncomfortable summary: insider defense is mostly verification applied to people you’ve already decided to trust. It feels rude. It works anyway. And for executives who publish on security, the insider chapter is the one your readers won’t get anywhere else, because companies bury these stories, and that’s why a candid, anonymized telling carries so much authority.

For more from this series, see The Cybersecurity Hub: breaches, audits, and hard-won security lessons from four decades in the trenches.

Frequently Asked Questions

What is an insider threat in cybersecurity?
A security risk originating from someone with legitimate access: employees, consultants, or partners. Motives range from expedience to fraud to criminal activity, and perimeter defenses don’t address any of them because the actor is already inside.
Should someone be fired for security violations even with good intentions?
Yes. In our case a consultant cracked passwords because he needed access to do his job. He was let go immediately. If intent excused the act, every insider incident would come with a sympathetic explanation attached.
How are insider threats usually discovered?
By verification controls instead of trust: comprehensive system scans, audits, and financial oversight such as segregation of duties. Each insider case I witnessed was surfaced by a control that checked everyone, not by suspicion of anyone.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.