Texas Developer Sentenced to 4 Years for “Kill Switch” Cyberattack on Former Employer

A Texas-based software developer has been sentenced to four years in federal prison for deploying a “kill switch” that crippled his former employer’s network. Davis Lu, 55, a former Eaton Corp. software developer, was convicted in March 2025 after prosecutors revealed a calculated campaign of digital sabotage.

The trouble began after a 2018 corporate reorganization reduced Lu’s responsibilities and system access. In retaliation, he planted malicious code across Eaton’s systems, including scripts that crashed servers and deleted coworkers’ profiles. Some programs carried ominous names like “Hakai” (Japanese for destruction) and “HunShui” (Chinese for sleep).

The most damaging move came in the form of a “kill switch” named IsDLEnabledinAD, designed to lock out all users if Lu’s name was removed from the company directory. When he was terminated in September 2019, the kill switch activated, locking thousands of employees out of critical systems worldwide. The attack caused more than $360,000 in losses and took over a year to fully remediate.

Investigators later uncovered Lu’s internet searches on privilege escalation, hiding processes, and rapid file deletion—clear evidence of intent. He was indicted in 2021 and ultimately sentenced in August 2025 by Judge Pamela A. Barker of the U.S. District Court for the Northern District of Ohio to 48 months in prison, followed by three years of supervised release. Restitution will be determined later.


Lessons Learned for Businesses

  • Implement Least Privilege Access: Limit user permissions to only what’s necessary for their role.
  • Continuous Monitoring: Use automated tools to detect unusual activity, privilege escalation, or unauthorized code changes.
  • Separation of Duties: Avoid giving one individual unchecked control over critical systems.
  • Incident Response Plans: Prepare for insider threats with clear protocols for rapid containment and recovery.
  • Employee Offboarding Controls: Immediately revoke access and audit systems when an employee exits.

Published by Shawn E. Tuma

Shawn Tuma is an attorney who is internationally recognized in cybersecurity, computer fraud and data privacy law, areas in which he has practiced for nearly two decades. He is a Partner at Spencer Fane, LLP where he regularly serves as outside cybersecurity and privacy counsel to a wide range of companies from small to midsized businesses to Fortune 100 enterprises. You can reach Shawn by telephone at 972.324.0317 or email him at stuma@spencerfane.com.

Leave a comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Business Cyber Risk

Subscribe now to keep reading and get access to the full archive.

Continue reading