
A software developer has been sentenced to four years in federal prison for orchestrating a sophisticated cyber sabotage attack against his former employer’s computer systems.
## The Case
Davis Lu, a 55-year-old Chinese national and legal U.S. resident from Houston, worked for an Ohio-based company (reportedly Eaton Corporation) from 2007 until his termination in 2019. Following a corporate restructuring that resulted in his demotion in 2018, Lu began planning his revenge.
## The Attack
Lu embedded malicious code throughout the company’s Windows production environment, creating two primary weapons:
**Malicious Code**: An infinite Java thread loop designed to overwhelm servers and crash production systems, causing widespread operational disruption.
**Kill Switch**: A particularly vindictive piece of code named “IsDLEnabledinAD” (Is Davis Lu enabled in Active Directory) that would automatically lock all users out of their accounts if his own account was disabled.
## The Consequences
When Lu’s employment was terminated on September 9, 2019, and his Active Directory account was disabled, the kill switch activated immediately. The result was catastrophic: thousands of employees were locked out of their systems, causing hundreds of thousands of dollars in damages and operational chaos.
## Cover-Up Attempts
When instructed to return his company laptop, Lu deleted encrypted data from the device. Digital forensics investigators later discovered his search history included queries about elevating system privileges, hiding processes, and quickly deleting files—clear evidence of premeditation.
## Legal Outcome
“The defendant breached his employer’s trust by using his access and technical knowledge to sabotage company networks, wreaking havoc and causing hundreds of thousands of dollars in losses for a U.S. company,” stated Acting Assistant Attorney General Matthew R. Galeotti.
Lu was convicted of intentionally causing damage to protected computers and will serve four years in prison followed by three years of supervised release.
## Key Takeaway
This case highlights the critical importance of robust insider threat programs and proper access management protocols, especially during employee transitions and terminations.
