AboutServicesMediaInsightsInvestigation FAQContact📞 24H Hotline
0800-090-007
PRIVILEGED ACCESS · BILLING FRAUD · INSIDER RISK

The Account Was Not HackedA privileged user allegedly made the bill disappear

DATE 2026.9.1
Relieved Group Insider Risk and Digital Investigation Team

Security programmes are comfortable looking outward: suspicious logins, malware, and password attacks. Risk that survives for years may use a normal account, a legitimate feature, and ordinary working hours. It does not break the door. It needs one exception that no independent team revisits.

Taiwan media reported on 28 August 2026 that prosecutors had indicted a former senior Chunghwa Telecom engineer. The indictment reportedly alleges that a work account was used to mark cloud services rented by a business he operated as non-billable, causing at least NT$33 million in foregone revenue; reports also describe an alleged forged notice. The matter has not reached a final judgment, and the accused is entitled to the presumption of innocence.

The control lesson is broader: access management cannot stop at who logged in. Ask who changed the exception, who benefited, how long it escaped review, and why resource consumption did not reconcile with revenue.

Key Points

For privileged accounts and billing exceptions, establish six controls:

  • Separate operations, testing, and billing-exemption authority so one user cannot set and approve the exception.
  • Every non-billable, free, discounted, or manual adjustment needs a reason, owner, expiry, and review.
  • Regularly reconcile resource consumption, contracts, invoices, cash, and customer master data.
  • Require conflict disclosure for employee interests in companies, relatives, customers, or suppliers.
  • Privileged logs should be monitored and retained independently of the operating team.
  • Preserve logs and data snapshots before asking the subject to explain or correct the anomaly.

1. News watch: the system can work while the control fails

The reported allegations point to a classic control problem: the feature had a legitimate purpose and the privileged user had a job-related reason to access it, but an exception allegedly benefited an entity connected to that user and was not caught by resource-to-revenue reconciliation for years.

This is neither only a cybersecurity event nor a problem solved by stronger passwords. It sits across identity, access, conflicts, billing, finance, and management oversight. When every department sees only its own metric, the anomaly hides between functions.

2. Why is a normal privileged action harder to detect than an external attack?

External attacks often bring unfamiliar devices, failed logins, or large behavioural anomalies. An insider can use a corporate device, known location, ordinary schedule, and an authorised feature, so a conventional technical alert may remain silent.

Detection needs business logic: high consumption without invoices, a free status that never expires, an account linked to an employee interest, or one person able both to create customers and adjust billing. Login data alone cannot answer those questions.

3. Four layers of a privileged-access and billing investigation

01
Access and actions
Preserve accounts, roles, entitlement history, logins, changes, bulk actions, APIs, and privileged logs.
02
Customers and revenue
Reconcile master data, contracts, usage, rates, discounts, invoices, cash, and receivables.
03
People and interests
Verify employees, related businesses, relatives, external customers, suppliers, and possible benefit.
04
Oversight and exceptions
Identify approvers, expiry, reviews, prior audit visibility, and why the anomaly was not escalated.

4. What should a company do when privileged misuse is suspected?

Do not begin with a public accusation. Legal, security, HR, audit, and investigation teams should lawfully preserve entitlements, logs, database snapshots, email, tickets, contracts, and billing records, and prevent overwriting. Access restriction and employment measures must follow policy and local labour law.

Build the smallest necessary timeline: what account changed, when, by whom, who benefited, what resources were used, what revenue was missing, and what control did not respond. Do not presume every anomaly is malicious, and do not let the subject decide which records matter.

5. How Relieved Group can assist

6. Final reminder: the most dangerous access is not always the highest access

The critical permission may be the ability to change one field that no one reconciles across departments. A non-billable switch looks like a technical setting. Over time it can become revenue, customer, and legal exposure.

A company does not need to treat every employee as an adversary. It needs bounded trust, expiring exceptions, traceable actions, and disclosed interests. Controls exist so one person is not simultaneously the door, key, and camera.

FAQ | Privileged accounts, billing fraud, and insider investigations
Are complete login records enough to control privileged accounts?
+
No. Login records identify who used an account and when. The company also needs action details, before-and-after values, affected customers, tickets, approvals, and business impact. Privileged logs should be retained and reviewed independently so the same user cannot both act and remove the record.
Are free, test, and non-billable accounts always improper?
+
No. Testing, compensation, promotion, and internal use may be legitimate. Risk arises when there is no reason, approver, expiry, usage limit, or periodic review, or when the exception benefits an employee interest. Mature control makes exceptions explainable, time-limited, and reconciled rather than prohibiting every exception.
How can a company detect long-term revenue leakage?
+
Reconcile technical consumption with commercial data: usage without invoices, contracts without cash, long-lived free status, discounts concentrated in a few accounts, or repeated changes by one privileged user. One discrepancy may be an error. A sustained pattern warrants a controlled, evidence-preserving investigation.
Can the company inspect an employee's private phone?
+
Not automatically. Access must comply with labour, privacy, device policy, authorisation, and necessity. Start with company-controlled logs, email, tickets, contracts, and financial data. If private-device material is genuinely necessary, counsel should assess consent or lawful process under the relevant jurisdiction.
Should access be disabled before evidence is preserved?
+
Both steps must be coordinated according to immediate risk. Continued access may require restriction, but identity, roles, sessions, tokens, logs, and snapshots should be preserved around the change. Legal, security, HR, and management should decide the measure lawfully to avoid losing evidence or creating unnecessary employment disputes.
Can Relieved Group determine that an employee committed a crime?
+
No. Criminal responsibility is determined by competent authorities and courts. We can organise access, actions, interests, usage, billing, and event timelines, distinguish system error, control failure, conflicts, and unresolved concerns, and prepare a factual record for boards, auditors, HR, counsel, or authorities.

Reference Sources

CONFIDENTIAL ASSESSMENT

Do system use, billing exceptions, and actual revenue no longer reconcile? Preserve access and action evidence first

Relieved Group can organise privileged accounts, exceptions, conflicts, usage, billing, and logs into a factual basis for boards, audit, HR, and legal teams.

📞LINE contact iconWhatsApp contact icon