How a former employee read his old firm's files for 2 years
An engineer who left a Tennessee engineering firm to co-own a competitor kept reading his old employer's files for nearly 2 years, using a colleague's email and the firm's own document system.[1][2] This case file covers what he took, how prosecutors valued it, what he was sentenced to, and the one offboarding step that would have shut the door on day one.
What happened
Jason Needham worked at the Tennessee engineering firm Allen & Hoshall before leaving to become a co-owner of a rival, HNA Engineering.[1]
After he left, he kept going back in. Over a period of nearly 2 years, he accessed a colleague's email account at his old firm on hundreds of occasions, and used what he found there to get into the firm's internal document-sharing system.[1][2]
What he found was exactly what a competitor would want. He downloaded engineering schematics and more than 100 PDF files containing project proposals and budget information, along with marketing plans and the firm's fee structures.[1][2] In a business that wins work through bids, knowing a rival's pricing and proposals is close to reading their hand of cards.
How he got in
There was no sophisticated hacking here. According to the Justice Department, the access came through 2 doors the firm had left open.[1][2]
The first was email. He was able to keep signing in to a colleague's mailbox long after he had left. The releases do not say how he knew the login, but nothing in the way stopped a former employee from using it hundreds of times.[2] Email is often the master key of a small business, because password resets, shared links and login details for other systems all pass through it.
The second was the document-sharing system. Its credentials did rotate, which sounds like good practice. But the new credentials were circulated through email, so reading the mailbox gave him each fresh set as it was issued.[2] Rotating a shared password only helps if the new one does not land somewhere the old insider can still see.
Nothing about this required breaking a lock. It required knowing where the keys were kept, which is exactly what a former employee knows.
How it was caught
The Justice Department releases do not say how Allen & Hoshall discovered the access. The FBI investigated the case, and it was prosecuted by the US Attorney's Office for the Western District of Tennessee along with the Justice Department's computer crime section.[1][2]
On April 14, 2017, Needham pleaded guilty to intentionally accessing a protected computer without authorization. At that time, prosecutors valued the information he obtained at about $425,000.[2]
What it cost
On August 4, 2017, a federal judge sentenced Needham, then 45, to 18 months in prison, followed by 2 years of supervised release, and ordered him to pay $172,393.71 in restitution to his former employer.[1] By sentencing, the value of the proprietary information he took was put at more than $500,000.[1] A spokesperson for the firm said it took computer crimes seriously and pursued the case to protect private information.[1]
The unmeasured cost is harder to count: nearly 2 years in which a direct competitor could see the firm's bids, budgets and plans while it competed for the same work.
The missing control
The missing control: rotating shared credentials at offboarding. When someone leaves, every password they knew, including shared logins and any account they could reach, gets changed, and the new ones are not sent through a channel they can still read.
This case had 2 gaps that one checklist would have closed. A proper offboarding step would have reset or locked any account the departing engineer knew the password to, including colleagues' accounts where passwords had been shared, and would have added a second factor to email. With the mailbox closed to him, the rotating document system credentials would have stopped reaching him too. Instead, a gap left open when he walked out stayed open for nearly 2 years.
What to do in your business
- Write a one-page leaver checklist. Disable their accounts the same day, and list every shared login they knew: Wi-Fi, file shares, vendor portals, social accounts, alarm codes.
- Change shared passwords when anyone leaves. Do it the same day, even if they left on good terms, and send new passwords through a password manager, not email.
- Stop sharing personal logins. Colleagues should not know each other's email passwords. If someone needs access to a mailbox, grant it properly through your email admin settings.
- Turn on MFA for email. A known password alone should not open a mailbox. Use an authenticator app or security key for every account.
- Check sign-in logs after departures. For 30 days after someone leaves, look for logins from unfamiliar places or devices on the accounts they used or knew.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.