
A 55-year-old Chinese national from Houston, Texas, has been sentenced to four years in prison followed by three years of supervised release for orchestrating an elaborate cyber sabotage scheme against his former employer.
## The Case Against Davis Lu
Davis Lu, a software developer, was convicted in March 2025 of intentionally damaging protected computer systems. His arrest in April 2021 followed a sophisticated attack on his employer’s network infrastructure that caused hundreds of thousands of dollars in damages.
“The defendant breached his employer’s trust by using his access and technical knowledge to sabotage company networks, wreaking havoc and causing hundreds of thousands of dollars in losses for a U.S. company,” stated Acting Assistant Attorney General Matthew R. Galeotti.
## A Decade-Long Employment Turns Malicious
Lu worked as a software developer for an unnamed Ohio-based company from November 2007 to October 2019. However, following a corporate restructuring in 2018 that reduced his responsibilities and system access, Lu began planning his revenge.
Starting in August 2019, Lu systematically introduced malicious code into the company’s systems, designed to:
– Create infinite loops that crashed servers by generating endless Java threads
– Delete coworker profile files
– Install a “kill switch” to lock out all users
## The Kill Switch: A Personal Signature
Perhaps most telling was Lu’s creation of a kill switch he named “IsDLEnabledinAD” – short for “Is Davis Lu enabled in Active Directory.” This code automatically activated when his account was disabled, immediately locking out thousands of company users worldwide.
Lu’s malicious intent was further revealed through his code naming conventions. He labeled other destructive programs “Hakai” (Japanese for “destruction”) and “HunShui” (Chinese for “sleep” or “lethargy”).
## The Final Act of Sabotage
When Lu was placed on leave and ordered to surrender his laptop on September 9, 2019, he attempted to cover his tracks by:
– Deleting encrypted data volumes
– Erasing Linux directories
– Destroying additional company projects
– Researching methods to hide processes and escalate system privileges
## Lessons for Corporate Security
This case highlights the critical importance of monitoring insider threats, according to FBI Cyber Division Assistant Director Brett Leatherman. Companies must implement robust access controls and monitoring systems to detect malicious activity from trusted employees before significant damage occurs.
The sentencing serves as a stark reminder that technical expertise cannot shield cybercriminals from legal consequences, regardless of their position within an organization.
