this post was submitted on 29 Jan 2026
9 points (90.9% liked)
Cybersecurity
9277 readers
58 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Some operational security questions: What's this trainee doing? Why was it a trainee noticing things being put in backpacks? Why was the trainee the one notifying security?
Are there protocols in place for media being brought in or out of the facility and its workstations? Why or why not? Was the trainee the only one who reviewed them recently enough to notice a breach and alert?
But most importantly and at any rate you don't do the grand heist on the last day. Rookie move.
def a rookie move! ^^ thx for the reply, appreciate it! yeah this case raises so many questions & i'm just guessing here. clearly a ton of security issues.
"Why was it a trainee... notifying security?" totally agree. besides the CDs, my main trigger was the trainee reporting it directly to security, skipping any manager or coworker. why? and why did no one else notice anything? makes me wonder if it’s really a single-man job... accomplices in the team maybe?
"Are there protocols in place...?" i d assume protocols exist but were bypassed. plugging in an external burner would def raise eyebrows or trigger dlp/edr. so i bet the workstations had built-in drives. in my dpo class, everyone just laughed bc it’s "old tech" nobody uses anymore... maybe the cybersec team thought the same? blocked usbs & set protocols for ports but underestimated optical? i have gen z students in my opsec classes who don't even know what a tower's cd-player is if i show them a photo. or they know it’s a player but don't realize it's a burner too.
what's ur take?