Summary
Opexus, a software services provider that handles sensitive data for nearly every U.S. federal agency, has disclosed a devastating insider attack. Two employees — identified as twin brothers Muneeb and Suhaib Akhter — allegedly improperly accessed sensitive documents, destroyed more than 30 databases, and removed over 1,800 files tied to government projects. The compromised systems included data from the Internal Revenue Service (IRS) and the General Services Administration (GSA).
The incident caused outages in key government software systems and, in some cases, resulted in permanent data loss. The FBI and other federal law enforcement agencies are actively investigating. Opexus provides records processing software used across the federal government, making the scope of potential impact extremely broad.
This represents one of the most significant insider threat incidents targeting U.S. federal infrastructure in recent memory, highlighting the unique dangers posed by trusted insiders with privileged access to critical government systems.
Source
Commentary
The Opexus incident is a nightmare scenario for government cybersecurity: trusted insiders with legitimate access deliberately destroying critical infrastructure. No amount of perimeter security or external threat detection helps when the attacker already has the keys. The fact that twin brothers coordinated this attack suggests premeditation rather than a momentary lapse in judgment.
The permanent data loss is particularly alarming. Federal agencies processing tax records and government services can’t simply “restore from backup” if the backups themselves were targeted. This incident should force a serious rethinking of how government contractors manage privileged access — including mandatory separation of duties, real-time behavioral monitoring, and the assumption that any insider could become a threat. The concentration of sensitive federal data in a single vendor’s hands also deserves scrutiny.
