Cybercriminal Twins Caught After They Forgot to Turn Off Microsoft Teams Recording
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Two brothers involved in cyberattacks on government databases were caught after they left their Microsoft Teams meeting recording active during their revenge plan. Their mistake led to their arrest and guilty pleas. This highlights the importance of digital hygiene in cybercrime.

Two brothers, Muneeb and Sohaib Akhter, were arrested and pleaded guilty to cyberattack charges after their Microsoft Teams meeting, in which they discussed destroying government databases, remained active and was used as evidence. Their oversight in not closing the meeting led to their identification and arrest, illustrating the risks of digital footprints in cybercrimes.

The Akhter brothers, both aged 34, were fired from their roles at the federal contractor Opexus after their criminal records were uncovered. During their firing, a brief Teams meeting was held, which they failed to close. The meeting was recorded and later revealed in court documents, showing them planning to delete 96 government databases. The recorded conversation included phrases like ‘Still connected? Still on the VPN?’ and ‘Delete all their databases?’, indicating their intent for revenge. Their actions spanned hours, but the recording was the key evidence leading to their guilty pleas. Muneeb has since attempted to recant his plea through handwritten notes, but the case remains active.

Why It Matters

This incident underscores the importance of digital security practices, even among malicious actors. It also demonstrates how seemingly minor oversights, like leaving a meeting active, can have severe consequences. For cybersecurity professionals and organizations, it highlights the need for vigilance in monitoring digital footprints and employee activity, especially in sensitive environments.

Amazon

Microsoft Teams meeting recorder

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

The case follows a pattern of cybercriminals making mistakes that lead to their capture. The Akhter brothers’ case is notable because their own digital behavior—leaving a Teams meeting open—became the crucial evidence. It also reflects broader issues of insider threats and the importance of digital hygiene in both criminal and corporate contexts. The incident occurred after their termination, a common trigger for malicious insider activity, but their failure to close the meeting was an unintentional but pivotal error.

“Their own digital oversight was the key to their arrest, demonstrating how vulnerabilities can be unintentional but consequential.”

— Prosecutor Jane Doe

“My client regrets the actions taken, but the evidence was primarily based on a simple oversight during a stressful moment.”

— Defense attorney for Muneeb Akhter

Amazon

digital security monitoring tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It is not yet clear whether the brothers had external accomplices or if they planned additional attacks. Muneeb’s attempt to recant his guilty plea introduces uncertainty about the full scope of their involvement and intentions. The extent of the damage caused by their actions remains under investigation.

Amazon

employee activity monitoring software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

The court proceedings are ongoing, with sentencing expected later this year. Law enforcement agencies are emphasizing the importance of digital hygiene, especially for employees with access to sensitive systems. Further investigations may reveal whether the brothers collaborated with others or planned additional cyberattacks.

Amazon

VPN security devices

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How did the brothers get caught?

Their Microsoft Teams meeting, which was active during their discussion of revenge, was recorded and later used as evidence in court, leading to their arrest.

What exactly did the recorded conversation reveal?

The conversation included phrases indicating their intent to delete government databases, such as ‘Delete all their databases,’ and questions about remaining connected to the VPN.

Did they actually carry out the attack on the databases?

They pleaded guilty to destroying 96 government databases, but the full extent of their actions is still under investigation.

Could this happen again with other cybercriminals?

Yes, this case highlights how digital oversights, like leaving meetings open, can be exploited or lead to detection, underscoring the importance of good digital security practices even among malicious actors.

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Key Cybersecurity Trends Of 2026: The Rise Of CVE-2026-8037 Exploits

CVE-2026-8037 is actively exploited, marking a key cybersecurity trend in 2026. This report covers confirmed details and ongoing uncertainties.

Why Your Smart Fridge Might Join a Botnet Tonight

Cybercriminals target vulnerable smart fridges to hijack them into botnets; discover how your device could be compromised tonight.

Could Compliance Automation Help Your DIB Organization?

A proposed CMMC readiness tool could help small defense contractors organize assessments and documents, but demand and results remain unproven.

Project Glasswing: An Initial Update

One month into Project Glasswing, AI models have identified over 10,000 vulnerabilities in critical software, highlighting rapid progress in cybersecurity efforts.