A federal jury convicted Virginia resident Sohaib Akhter for his role in a retaliatory intrusion that wiped 96 government databases after he and his twin brother were fired from a Washington, D.C.-area software contractor supporting more than 45 U.S. federal agencies. Prosecutors said the brothers accessed systems without authorization, write-protected and deleted databases, stole credentials, and tried to destroy evidence; the case also involved trafficking a password tied to an individual who had filed a discrimination complaint with the Equal Employment Opportunity Commission. Akhter was convicted of conspiracy to commit computer fraud, password trafficking, and firearm possession by a prohibited person.
Court filings and reporting say the brothers also wiped company laptops, discussed preparing for a law-enforcement search, and sought ways to clear system logs after deleting a Department of Homeland Security database. The case drew added scrutiny because both men had previously been convicted in an earlier federal computer intrusion case involving State Department systems and personal data, yet were later rehired as government contractors. Sohaib Akhter faces sentencing on September 9, 2026, with a maximum penalty of 21 years in prison, while his brother Muneeb Akhter separately faces multiple computer fraud, identity theft, and government records theft charges carrying up to 45 years.

See the reporting duties and controls this puts on the clock.
12 events from the most recent confirmed update back to the earliest known activity.
Sohaib Akhter is scheduled to be sentenced on September 9, 2026, and faces a maximum sentence of 21 years in prison. Separate charges against his twin brother remain pending, with higher potential exposure reported.
After entering a plea agreement in the government database sabotage case, Muneeb Akhter later tried to withdraw his guilty plea through handwritten letters to the judge. The filing marked a new procedural development in the federal prosecution separate from his April 15 plea deal and Sohaib Akhter's later conviction.
By May 8, 2026, a federal jury had convicted Sohaib Akhter of conspiracy to commit computer fraud, password trafficking, and firearm possession by a prohibited person. The conviction was tied to unauthorized access, deletion of government databases, and related retaliatory conduct after his dismissal.
After extradition, Sandu appeared in federal court in North Carolina and was placed in federal custody pending trial. Prosecutors said he faces up to 30 years in prison if convicted.
On April 30, 2026, Gavril Sandu was transferred to U.S. custody and extradited from Romania to face federal bank fraud charges in North Carolina. The extradition followed coordination between U.S. and Romanian authorities.
On April 15, 2026, Muneeb Akhter entered a plea agreement in the federal case over the retaliatory deletion of 96 government databases and related unauthorized access after he and his brother were fired. The plea marked a separate procedural development from Sohaib Akhter's later jury conviction.
Romanian authorities arrested Gavril Sandu on January 9, 2026, pursuant to the U.S. case against him. The arrest advanced the long-pending prosecution over the 2009-2010 vishing and bank fraud scheme.
After their firing, the brothers allegedly accessed computers without authorization, write-protected databases, deleted 96 government databases, stole credentials, and attempted to destroy evidence. The activity affected systems tied to numerous federal agencies, including a Department of Homeland Security database.
In February 2025, Sohaib Akhter and his twin brother were fired from a Washington, D.C.-based software services company that supported more than 45 U.S. federal agencies. Prosecutors said the brothers then retaliated against government-related systems.
A federal grand jury in Charlotte indicted Gavril Sandu in 2017 on bank fraud charges stemming from the earlier vishing scheme. The indictment alleged his role in obtaining stolen card data, creating counterfeit cards, and withdrawing funds as a money mule.
In 2015, Sohaib Akhter pleaded guilty in a separate federal case involving wire fraud and conspiracies to gain unauthorized access to protected and government computers. Related reporting also notes the Akhter brothers had prior convictions tied to unauthorized access to U.S. State Department systems.
Between May 2009 and October 2010, Gavril Sandu and co-conspirators allegedly hacked small businesses' VoIP systems to place spoofed bank calls, tricking victims into revealing debit card numbers and PINs. The stolen data was used to create magnetic-stripe cards and withdraw cash from victim accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourcecsoonline.com
Open sourcearstechnica.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcejustice.gov
Open sourcesecurityaffairs.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.