What If a Former Employee Still Had Access to Your Files?

What If a Former Employee Still Had Access to Your Files?

In 2026, Apple alleged that a former employee who had joined OpenAI was able to access Apple’s internal network storage weeks after leaving the company, according to TechCrunch reports.  

In its complaint, Apple says the former employee, system electrical engineer Chang Liu, allegedly exploited a “rare, previously unknown authentication bug” that allowed him to access the company’s network. The vulnerability was described as a zero-day vulnerability.  

TechCrunch also asked Apple when Liu’s access to the company’s network was decommissioned, given that he had previously been granted network credentials as an employee. Apple did not respond to the publication’s inquiry.  

The case remains a dispute between the parties, so Apple’s allegations should not be treated as established findings. But the security lesson is clear: Leaving a company does not automatically mean every technical path into its systems disappears.  

Even when an employee’s primary account has been disabled, organizations need to think about credentials, applications, devices, tokens, integrations, shared accounts, and vulnerabilities that may preserve another route to company data.  

This isn’t only a problem for large technology companies.  

A former employee doesn’t need to exploit a sophisticated vulnerability to create a security risk. Sometimes, the problem is much simpler: an old Microsoft 365 account, a forgotten VPN login, access to a shared Google Drive folder, or credentials that were never revoked.   

Another big misconception is that a former employee with access must be deliberately trying to cause damage. They don’t have to be. Imagine an employee leaves the company, but their account remains active for several days. They could still receive email and access shared files; they could still have access to a client folder.  

From a security perspective, the company has created an unnecessary access path. The longer unnecessary access remains active, the more opportunities there are for credentials to be misused, devices to be compromised, or sensitive information to be accessed by someone who no longer needs it.  

Offboarding Is a Cybersecurity Process  

Employee offboarding isn’t just an HR task. It is an access-control issue. Depending on their role, your former team members may have access to:  

  • Microsoft 365 or Google Workspace  
  • VPNs and remote-access tools  
  • CRM and accounting systems  
  • Cloud storage  
  • Project management platforms  
  • Client portals  
  • Development environments  
  • Shared mailboxes  
  • Password managers  
  • SaaS applications  
  • Company devices and mobile apps  
  • API keys, service accounts, or other credentials  

NIST’s security guidance specifically recommends disabling system access, revoking authenticators and credentials, and retrieving security-related property when personnel are terminated or transferred.  

6545

What Should Happen When Someone Leaves?  

A practical offboarding process should cover more than the employee’s primary login.  

1. Disable the main account  

Start with the obvious: email, Microsoft 365 or Google Workspace, VPN, remote access, and other core systems.  

2. Find the forgotten access  

Check the applications and services the employee actually used. Don’t assume the central identity system contains everything.  

3. Revoke credentials and active sessions  

Passwords aren’t the only thing that matters. Review active sessions, authentication methods, tokens, API keys, certificates, and other credentials where relevant.  

4. Review shared access  

Check shared drives, folders, mailboxes, project spaces, client portals, and other resources where access may have been granted separately.  

5. Secure company devices  

Retrieve company laptops, phones, security keys, and other equipment. If devices cannot be recovered, make sure the organization can remotely revoke or protect access where possible. Microsoft’s guidance for removing former employees, for example, includes blocking access to Microsoft 365, preserving business data when necessary, and handling company devices separately.  

6. Transfer ownership before deleting anything  

Former employees may own files, calendars, mailboxes, projects, or other business data that the company still needs. Secure and transfer that information before permanently deleting accounts.  

Your Logs May Already Tell You the Story  

There’s another important part of the process: monitoring. If an organization discovers that a former employee accessed company systems after leaving, logs can sometimes show exactly what happened.   

  • Who accessed the system?  
  • When did they access it?  
  • What did they access?  
  • Was that access authorized?  

Without adequate logs, answering those questions becomes much harder.  

Automated Offboarding vs. Manual Offboarding  

There are two very different ways a business can handle employee offboarding. The first is manual.  

HR notifies the manager that someone is leaving. The manager contacts IT. IT disables the main account, then checks a list of systems the employee may have used. Someone else may need to remove access to the CRM. Another person may need to transfer ownership of files. Finance may handle a separate application. It can work. But it depends on people remembering every step, knowing every system the employee had access to, and completing the process in the right order.  

The second approach is automated offboarding. In this model, a change in the employee’s status, such as termination or a role change in the HR system, can trigger a predefined workflow. Depending on the organization’s setup, that workflow can automatically disable the user’s main account, revoke access to connected applications, invalidate credentials or sessions, remove group memberships, and notify the people responsible for systems that cannot be handled automatically.  

NIST describes this kind of approach in its identity and access management guidance, where personnel changes can trigger workflows that remove resource access and invalidate credentials.  

Manual processes can be appropriate for smaller businesses or systems that cannot be integrated. Automated processes can also have gaps if the company’s applications, permissions, or identity systems aren’t configured correctly.  

The real difference is how much the process depends on memory.  

With a manual process, the question is: “Did someone remember to remove access everywhere?”  

With an automated process, the question becomes: “Did the workflow trigger correctly, and are all the relevant systems connected to it?” That’s a much easier process to monitor, test, and improve.  

For businesses with many employees and cloud applications, automation can also make offboarding faster and more consistent. Instead of waiting for several people to complete a checklist, critical access can be removed as soon as the appropriate status change occurs.  

However, automation should not be treated as a substitute for periodic access reviews. Businesses still need to identify applications that aren’t connected to the automated workflow, review unusual permissions, check shared accounts, and make sure former employees haven’t been left with access through another route.  

The strongest approach is usually a combination: automate what can be automated, review what can’t, and make someone responsible for the gaps.  

101636

A Simple Offboarding Checklist  

Before considering an employee fully offboarded, ask:  

  • Is their primary account disabled?  
  • Have active sessions and credentials been revoked?  
  • Have VPN and remote-access permissions been removed?  
  • Have shared folders and cloud resources been checked?  
  • Have SaaS applications been reviewed?  
  • Have company devices and security keys been recovered?  
  • Have ownership of important files and accounts been transferred?  
  • Have unnecessary API keys, tokens, and other credentials been revoked?  
  • Can the business verify the changes through its logs?  
  • Has access been reviewed across systems the central IT team doesn’t administer?  

If several answers are “I’m not sure,” that’s worth investigating.  

Secure Offboarding Is a Technology Problem, Too  

Employee departures are inevitable. Forgotten access doesn’t have to be. Reach out to Klik Solutions, we help businesses review access, strengthen identity and permission controls, secure Microsoft 365 and cloud environments, and build practical processes that reduce the risk of forgotten accounts and unnecessary access.  

You don’t need an enterprise security department to get the basics right. You need to know who has access, what they can access, and what happens to that access when their role changes.  

Want to find the gaps in your current setup? Reach out to Klik Solutions and let’s review your IT environment. For more practical technology and cybersecurity tips for your business, follow Klik Solutions on social media. 

Frequently Asked Questions 

How quickly should a former employee’s access be removed?  

As quickly as possible after the employment or access relationship ends. The exact process depends on the circumstances, but access should not remain active simply because someone has not yet gotten around to removing it.  

Is disabling Microsoft 365 or Google Workspace enough?  

Not necessarily. Businesses often use dozens of applications and services outside their primary productivity platform. VPNs, CRMs, financial systems, cloud platforms, client portals, shared accounts, and other services may need separate review.  

What should a business do if it discovers a former employee still has access?  

First, determine whether the access is still active and what information or systems it can reach. Then revoke the unnecessary access, preserve relevant logs, and investigate whether the account or credentials were used after the employee left. If sensitive information may have been accessed, the business should also consider its legal, contractual, and incident-response obligations.  

How often should employee access be reviewed?  

There isn’t one universal schedule for every organization. Access should be reviewed when employees join, leave, or change roles, and businesses should also conduct periodic reviews appropriate to the sensitivity of their systems and data.  

Register for klik solutions picnic

Error: Contact form not found.

sign up to attend this event

    All fields are required

    support Hope children of ukraine!

    donate now!

      All fields are required

      Thank you for your enquiry.

      thanks-icon

      Please monitor your inbox for all March Madness updates.

      Thank you!

      thanks-icon

      We will contact you soon.