Fired Hacker Twins Forget to End Teams Recording, Capture Own Crimes
Security breach incident becomes self-documented criminal case when terminated employees leave Microsoft Teams session active.

Two terminated cybersecurity employees have inadvertently created perhaps the most documented cybercrime case in recent memory after forgetting to end a Microsoft Teams recording while committing computer crimes against their former employer. The twin brothers, who had been fired from their positions at a technology company, apparently left their video conferencing software running while executing what investigators describe as a sophisticated revenge hack against company systems.
The incident began when the siblings accessed company networks using credentials and knowledge gained during their previous employment, seeking to damage systems and steal sensitive information in retaliation for their termination. However, their criminal activity was captured in real-time by Microsoft Teams recording functionality that remained active from what appears to have been a previous legitimate meeting. The continuous recording documented their conversations, screen activities, and detailed discussions of their hacking methodology.
Law enforcement officials describe the case as unprecedented in terms of the quality and completeness of evidence typically difficult to obtain in cybercrime investigations. The recording captured not only the technical aspects of the security breach but also the perpetrators' motivations, methods, and future plans. Investigators noted that the twins discussed their illegal activities openly, apparently unaware that their conversation and computer activities were being documented.
The self-incriminating evidence includes detailed footage of the brothers accessing restricted systems, copying confidential data, and attempting to install malicious software designed to disrupt company operations. The recording also captured their discussions about covering their tracks and plans for additional attacks, providing prosecutors with what legal experts describe as an exceptionally strong case for conviction on multiple federal computer crime charges.
Cybersecurity experts are highlighting the incident as both a cautionary tale about insider threats and an example of how modern technology can inadvertently assist law enforcement. The case demonstrates the importance of immediately revoking access credentials for terminated employees, while also illustrating how remote work technologies can create unexpected documentation of criminal activity when users fail to properly manage their digital tools.




