Fired on Wednesday, deleting files on Friday: the credit union access that never got cut
Someone at a New York credit union asked for a fired employee's remote access to be shut off. It was not, and 2 days later she logged back in and spent about 40 minutes deleting more than 20,000 files.[1][2] This case file covers what happened, how an unfinished offboarding task turned into a federal case, and the one control that would have made it a non-event.
What happened
In May 2021 Juliana Barile, then 35, was a part-time employee of a credit union in New York, working remotely from Brooklyn during the pandemic.[1][2] On May 19, 2021, a Wednesday, the credit union fired her.[1]
A credit union employee asked the outside firm that handled its IT support to disable her remote access. According to the court filing, that access was not disabled, and her username and password still worked.[2][3]
On Friday, May 21, she connected to the credit union's file server and stayed on for about 40 minutes. In that time she opened various documents, including board minutes, and deleted about 20,433 files and 3,478 folders, roughly 21.3 gigabytes of data, from its shared network drive.[2][3] The deleted material included mortgage loan application files and a folder holding the credit union's anti-ransomware software, which had been labeled with a warning not to delete it.[2][4]
On May 26 she texted a friend, saying in short that the credit union had not revoked her access and that she had deleted its shared network documents.[1][2]
How it worked
There was no hacking in the usual sense. Nothing was broken into, no password was guessed and no one was tricked. A former employee used the same remote login she had used the week before, and the server treated her as a trusted member of staff because, as far as its settings knew, she still was one.[2][5]
The weak point sat in the handoff between people. The request to cut her off went from the credit union to its IT provider, and then nothing confirmed that it had actually been done.[3][5] Small organizations that outsource IT often depend on exactly this kind of email or phone request, with no ticket number, deadline or check that the account is really dead.
Her account also appears to have had broad rights over the shared drive. A part-time employee could delete thousands of folders, including one that protected the organization against ransomware, in a single short session.[2][4]
What it cost
Some of the data had backups, which limited the damage, but the credit union still spent more than $10,000 on remediation.[1][4] The trade press later identified the credit union, but it was the victim here and is not named on this page.
Barile was charged in federal court in Brooklyn with one count of computer intrusion and pleaded guilty in late August 2021. The charge carried up to 10 years in prison.[1][4] She was later sentenced to probation, according to a January 2023 trade press report.[6] The texts to her friend, which were cited in the charging papers, left little room for any other explanation.[3]
The missing control
The missing control: disabling access at the moment of termination, and confirming it was done. The request existed. What was missing was a process that made cutting off access happen at the same time as the firing, with someone checking the result.
If the remote login had been switched off on May 19, or even the next morning, the Friday session could not have happened. A simple follow-up the same day, trying the account or asking the IT firm for written confirmation, would have caught the miss with 2 days to spare. Tighter file permissions, so a part-time role could not wipe shared folders, would have shrunk what 40 minutes could do.[2][3]
What to do in your business
- Cut access before or during the termination meeting. Disable email, remote access, shared drives and any cloud apps while the conversation is happening, not afterward.
- Keep a one-page offboarding checklist. List every system each role can reach, and tick each one off with a name and time when access is removed.
- Get written confirmation from your IT provider. If someone outside does the work, ask for a reply that says the account is disabled, then test it yourself by trying to sign in.
- Limit who can delete in shared folders. Most staff need to read and add files, not erase whole directories. Save delete rights for the few who need them.
- Test a restore. Pick a folder, restore it from backup, and time it. Know that you can get data back before the day you need to.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Attorney's Office, Eastern District of New York: Brooklyn woman pleads guilty to unauthorized intrusion into credit union's computer system
- The Register: Fired credit union employee deletes 21GB of data
- U.S. Department of Justice: Information, United States v. Juliana Barile (E.D.N.Y.)
- The Record: Fired credit union worker pleads guilty after accessing and deleting thousands of files
- BleepingComputer: Fired NY credit union employee nukes 21GB of data in revenge
- CU Times: Former CU employee sentenced in IT revenge case