{"id":8652,"date":"2025-11-22T10:03:32","date_gmt":"2025-11-22T10:03:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/22\/fired-techie-admits-hacking-employers-network-in-retaliation-for-termination\/"},"modified":"2025-11-22T10:03:32","modified_gmt":"2025-11-22T10:03:32","slug":"fired-techie-admits-hacking-employers-network-in-retaliation-for-termination","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/22\/fired-techie-admits-hacking-employers-network-in-retaliation-for-termination\/","title":{"rendered":"Fired Techie Admits Hacking\u00a0Employer\u2019s Network in Retaliation for Termination"},"content":{"rendered":"<p>    Fired Techie Admits Hacking\u00a0Employer\u2019s Network in Retaliation for Termination<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A former IT contractor from Ohio has admitted to launching a cyberattack against his employer\u2019s network in retaliation for being terminated, federal prosecutors announced this week.<\/p>\n<p>Maxwell Schultz, 35, of Columbus, Ohio, pleaded guilty to computer fraud charges after leading a technical attack that locked thousands of employees out of their systems nationwide.<\/p>\n<p>On May 14, 2021, Schultz was fired from his contract position in the company\u2019s IT department. Rather than accepting the termination, he chose to strike back digitally.<\/p>\n<p>Shortly after his dismissal, Schultz impersonated another contractor to fraudulently obtain valid <a href=\"https:\/\/cybersecuritynews.com\/hackers-are-weaponizing-invoices-to-deliver-xworm\/\" target=\"_blank\" rel=\"noreferrer noopener\">login credentials<\/a>, gaining unauthorized access to the company\u2019s network.<\/p>\n<p>Once inside the system, Schultz executed a <a href=\"https:\/\/cybersecuritynews.com\/agent-tesla-malware-employs-multi-stage-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell script<\/a> designed to cause maximum disruption.<\/p>\n<p>The malicious code reset approximately 2,500 employee passwords simultaneously, effectively locking thousands of workers and contractors out of their computers across multiple locations.<\/p>\n<p>Schultz didn\u2019t stop at password resets. He actively sought methods to delete digital evidence of his unauthorized access, including PowerShell event logs and <a href=\"https:\/\/cybersecuritynews.com\/new-dire-wolf-ransomware-attack-windows-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">system logs<\/a>.<\/p>\n<p>Despite clearing multiple logs, investigators eventually traced the attack back to him. The company suffered significant financial losses exceeding $862,000.<\/p>\n<p>These damages included widespread employee downtime, disrupted customer service operations, and extensive labor costs required to restore standard network functionality.<\/p>\n<p>The ripple effects impacted both internal operations and customer relationships. As part of his guilty plea, Schultz acknowledged that anger over his termination motivated the attack. He now faces serious federal consequences.<\/p>\n<p>U.S. District Judge Lee Rosenthal will sentence Schultz on January 30, 2026. He faces up to 10 years in federal prison and a maximum fine of $250,000.<\/p>\n<p>The FBI led the <a href=\"https:\/\/www.justice.gov\/usao-sdtx\/pr\/former-contractor-admits-hacking-employer-retaliation-termination\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">investigation<\/a>, with Assistant U.S. Attorneys Rodolfo Ramirez and Michael Chu prosecuting the case.<\/p>\n<p>This case highlights the critical importance of immediately revoking system access for terminated employees, particularly those with administrative privileges.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fired-techie-admits-hacking\/\">Fired Techie Admits Hacking\u00a0Employer\u2019s Network in Retaliation for Termination<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fired-techie-admits-hacking\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fired Techie Admits Hacking\u00a0Employer\u2019s Network in Retaliation for Termination A former IT contractor from Ohio has admitted to launching a cyberattack against his employer\u2019s network in retaliation for being terminated, federal prosecutors announced this week. Maxwell Schultz, 35, of Columbus, Ohio, pleaded guilty to computer fraud charges after leading a technical attack that locked thousands [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1112],"tags":[130],"class_list":["post-8652","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-hacking-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8652"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8652"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8652\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8652"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8652"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8652"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}