Cybercrime

Developer Who Hacked Former Employer’s Systems Sentenced to Prison

Davis Lu was sentenced to four years in prison for installing malicious code on employer’s systems and for deleting encrypted data.

Davis Lu was sentenced to four years in prison for installing malicious code on employer’s systems and for deleting encrypted data.

A Chinese national was sentenced to four years in prison for sabotaging his former employer’s systems through malicious code.

The man, Davis Lu, 55, a legal resident of Houston, Texas, was a software engineer at the victim company, headquartered in Beachwood, Ohio, from November 2007 to October 2019.

According to court documents, Lu began sabotaging the employer’s network after his responsibilities and system access were restricted in 2018, following a corporate realignment.

By August 2019, documents presented in court show, he installed malicious code that exhausted system resources, causing crashes and preventing user logins.

The code was designed to repeatedly create Java threads without proper termination, creating infinite loops leading to server hangs or crashes.

Additionally, Lu deleted coworker profile files, and implemented a kill switch that logged all users out of their accounts as soon as his credentials were disabled in Active Directory, court documents show.

Advertisement. Scroll to continue reading.

The kill switch, named ‘IsDLEnabledinAD’ (an abbreviation for ‘Is Davis Lu enabled in Active Directory’) was activated when Lu was placed on leave and asked to turn in his laptop. He also deleted encrypted data on the day he was directed to surrender his laptop.

According to documents presented in court, Lu searched the internet for methods to escalate privileges, delete files, and hide processes, which indicate he was researching means to prevent system restoration attempts.

His actions impacted thousands of users worldwide and caused hundreds of thousands of dollars in losses to his employer.

Lu was convicted in March. In addition to the four-year prison sentence, he received three years of supervised release.

Related: Scattered Spider Hacker Sentenced to Prison

Related: Hacktivist Sentenced to 20 Months of Prison in UK

Related: UK Student Sentenced to Prison for Selling Phishing Kits

Related: In Other News: Hacker Helps Kill Informants, Crylock Developer Sentenced, Ransomware Negotiator Probed

Related Content

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Cybercrime

Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).

Cybercrime

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.

Cybercrime

Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. 

Cybercrime

Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network.

Cybercrime

Deniss Zolotarjovs was directly involved in extortion strategies and in negotiations with victim companies.

Cybercrime

Ryan Goldberg of Georgia and Kevin Martin of Texas were each sentenced to four years in prison. 

Cybercrime

Kamerin Stokes sold stolen credentials through an online marketplace even after pleading guilty to his role in the DraftKings attack. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version