HomeSecurityProgrammer deployed kill switch code on employer's network

Developer deployed kill switch code on employer's network

A Chinese national has been sentenced to four years in prison (and three years of supervised release) for destroying his former employer's network with malware and deploying a kill switch code that locked out employees when his account was deactivated.

kill switch code employer

Davis Lu, 55, of Houston, Texas, was convicted of intentionally damaging protected computers in March 2025. He was arrested and charged in April 2021 with abusing his position as a software developer and executing malicious code on his employer's computer servers.

“The defendant violated his employer’s trust by using his access and technical knowledge to networks company’s,” said Deputy Assistant Attorney General Matthew R. Galeotti of the Department of Justice’s Criminal Division. “However, the defendant’s technical brilliance and hypocrisy did not save him from the consequences of his actions.”

See also: Scattered Spider: Key member sentenced to 10 years in prison

Court documents show that Lu worked as a software developer for the anonymous, Ohio-based company from November 2007 to October 2019. After his responsibilities and system access were reduced due to a corporate restructuring (in 2018), Lu implemented a scheme to intentionally introduce malicious code into systems, resulting in systems crashing and preventing user logins.

Kill switch deployment

To achieve this, Lu allegedly created infinite loops in the source code. This way, he was able to cause server crashes by repeatedly creating new Java threads without properly terminating them. He also deleted co-worker profile files and implemented a kill switch that would lock out all users if their credentials in the company's Active Directory were deactivated.

Developer deployed kill switch code on employer's network

“The kill switch code — which Lu named ‘IsDLEnabledinAD,’ short for ‘Is Davis Lu enabled in Active Directory’ — was automatically activated when he was put on leave and asked to hand over laptop on September 9, 2019. It affected thousands of the company’s users worldwide,” the Justice Department said.

“Lu named another code 'Hakai,' a Japanese word meaning 'destruction,' and 'HunShui,' a Chinese word meaning 'sleep' or 'dormancy.'‘”.

See also: US: Woman jailed for helping North Koreans break into companies

Additionally, on the day he was asked to return the company-issued laptop, he deleted encrypted volumes and attempted to delete Linux directories and two additional projects. His web search history revealed methods he researched for privilege escalation, process hiding, and file deletion, suggesting an attempt to thwart the company's efforts to resolve the issues.

It is estimated that Lu's illegal actions cost the company hundreds of thousands of dollars. This case also highlights the importance of early identification of insider threats, added Assistant Director Brett Leatherman of the Federal Bureau of Investigation's (FBI) Cyber ​​Directorate.

Insider threat: Employee jailed for developing kill switch

Davis Lu’s conviction is not just an isolated incident of cybercrime; it is a prime example of how dangerous an insider threat. Unlike traditional attacks, which come from an outside source and can be detected by firewalls or intrusion detection systems, “insiders” already have valid access and knowledge of the infrastructure, which gives them a huge advantage over defense mechanisms.

The incident highlights the need for Zero Trust architectures, where access is never taken for granted, even for long-serving employees. The victim company paid a high price for trust without adequate controls, with Lu exploiting his expertise to install malicious code with the aim of causing long-term damage.

See also: Jetflicks: The administrator of the pirate streaming service is imprisoned

Developer deployed kill switch code on employer's network

The case also reminds organizations that they need to invest more in behavioral monitoring, which is a system that detects anomalies in user and application behavior. Such tools could have detected the introduction of unusual loops in code or suspicious file deletions long before the company reached the point of collapse.

From a legal perspective, Lu’s conviction is a clear signal that American courts now treat such acts not as “internal mistakes” but as serious criminal offenses with real prison sentences. This may act as a deterrent, but it will hardly eliminate the problem: bitterness, resentment, or conflicts within a company can be catalysts for attacks by people once considered valuable executives.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS