Federal prosecutors in Virginia have filed a superseding indictment accusing brothers Muneeb Akhter and Sohaib Akhter of a new wave of cybercrime after their termination from a government contractor in February 2025. The indictment alleges the pair conspired to access company and customer systems without authorization, delete about 96 databases containing U.S. government information, steal sensitive data tied to agencies including DHS, EEOC, and the IRS, and use anti-forensic techniques to destroy evidence. Prosecutors say Muneeb Akhter copied EEOC files to a USB drive, deleted DHS-hosted data, stole IRS-related records containing federal tax information and FOIA materials, and used AI tools to obtain commands for deleting databases and clearing logs.
The filing further alleges Muneeb Akhter used roughly 5,400 stolen usernames and passwords from the EEOC Public Portal to access victims’ email, airline, hotel, and financial accounts, including through Python scripts and deceptive domains such as wardensys.com and wardensystems.com. Sohaib Akhter is separately charged with password trafficking, firearm possession as a prohibited person, and witness tampering tied to the grand jury investigation. The new case follows the brothers’ earlier federal convictions and 2015 sentencing for wire fraud and cyber intrusions involving a private company and the U.S. Department of State, where prosecutors said they stole payment-card and personal data, abused insider access to sensitive information, and attempted to establish clandestine access inside a State Department facility.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced that two Virginia men were arrested for allegedly conspiring to destroy government databases. The arrests represent a new law-enforcement step in the case tied to the previously described 2025 intrusion and sabotage allegations.
The indictment alleges that Muneeb Akhter later used about 5,400 stolen usernames and passwords from the EEOC Public Portal to access victims’ email, airline, hotel, and financial accounts. Prosecutors say he used Python scripts and deceptive domains including wardensys.com and wardensystems.com in the scheme.
Prosecutors allege Muneeb Akhter used AI tools to obtain commands for deleting databases and clearing logs, and employed anti-forensic measures to destroy evidence. These actions were described in the indictment as part of the 2025 intrusion and sabotage activity.
The superseding indictment alleges that Muneeb Akhter copied EEOC files to a USB drive and stole IRS-related records containing federal tax information and FOIA materials. Prosecutors say the theft was part of a broader effort to exfiltrate sensitive government-linked data from Company-1 systems.
After their termination, prosecutors allege the brothers conspired to access Company-1 systems without authorization and damage the company and its federal agency customers. The indictment says approximately 96 databases containing U.S. government information were deleted, including DHS-hosted data.
According to the superseding indictment, Muneeb Akhter and Sohaib Akhter were terminated from government contractor Company-1 on February 18, 2025. Prosecutors allege the later 2025 offenses were carried out after their dismissal.
On October 2, 2015, the U.S. Department of Justice announced that twin brothers Muneeb and Sohaib Akhter were sentenced for wire fraud and cybercrime conspiracies involving unauthorized access to U.S. Department of State systems and a private company. Muneeb Akhter received 39 months in prison and Sohaib Akhter received 24 months, with both also ordered to serve three years of supervised release.
On 2015-06-29, Muneeb and Sohaib Akhter pleaded guilty in the Eastern District of Virginia to wire fraud and computer intrusion offenses tied to hacks involving a private company and U.S. Department of State systems. The Justice Department said the conduct included theft of customer and government data, and Sohaib admitted attempting to install a covert collection device inside a State Department building.
A superseding indictment in the Eastern District of Virginia charged Muneeb Akhter and Sohaib Akhter with computer crime, fraud, identity theft, firearms, and witness tampering offenses tied to conduct in 2025. The filing also included forfeiture allegations covering multiple laptops, phones, and external drives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcestorage.courtlistener.com
Open sourcestorage.courtlistener.com
Open sourcestorage.courtlistener.com
Open sourcestorage.courtlistener.com
Open sourcestorage.courtlistener.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.