Noah Reed had been a mid-level IT security analyst at Corvale Financial for two years, mostly handling routine access reviews and phishing training reminders nobody read, which was why the ghost account he found during a routine audit felt, at first, like nothing more than an administrative loose end. The account had system-level access, no assigned employee, and had been active for eleven months without triggering a single alert.

Noah's job was to flag the account and move on to the next line item, but something about its access pattern kept him staring at his screen after his shift ended: it logged in every night between 1 and 3 a.m., always for a duration under twenty minutes, always touching the same set of wire transfer approval systems Noah had no reason to think anyone worked with at that hour.

He ran the pattern against every legitimate maintenance window Corvale scheduled, every automated batch job, every known service account with similar permissions, and came up empty each time. Whatever was logging in at 1 a.m. wasn't doing anything the company's own documentation could explain, which was, in Noah's experience, the single most reliable sign that something was deliberately hiding rather than merely undocumented.

He raised it with his supervisor the next morning, expecting a shrug and a ticket assigned to someone more senior. Instead, his supervisor's reaction was fast enough and careful enough that Noah understood, before anyone told him directly, that this wasn't the first time someone at Corvale had noticed something wrong and hadn't known quite what to do about it.

The forensic review that followed, conducted quietly over two weeks by an outside cybersecurity firm Corvale brought in without informing most of its own staff, traced the ghost account's origin to a piece of malware installed eleven months earlier through a phishing email that had, according to the logs, been opened by someone inside the company's own wire transfer approval team.

Noah worked alongside the outside firm's lead analyst for most of those two weeks, a terse woman named Priyanka who communicated almost entirely in log timestamps and packet captures, and who taught him more about persistent access techniques in fourteen days than he'd learned in two years of routine compliance work. He found himself staying past midnight more nights than he could count, less because anyone required it than because the puzzle had become genuinely difficult to walk away from.

The phishing email itself, once recovered from an archived mail server, was almost embarrassingly simple — a fake internal IT notice about a mandatory password reset, formatted well enough to pass a quick glance but riddled, on closer inspection, with the kind of small formatting inconsistencies that Corvale's own security training materials warned employees to watch for. Someone had clicked it anyway, the way someone always eventually does.

The malware gave its operator persistent access to Corvale's internal systems, but what made it dangerous rather than merely intrusive was the second discovery: someone inside the company had modified the fraud detection thresholds on the wire transfer system just weeks after the malware's installation, raising the dollar amount required to trigger a manual review from fifty thousand to five hundred thousand dollars.

That kind of change required insider knowledge no external attacker could plausibly have obtained alone, which meant Corvale wasn't dealing with a single intrusion but a coordinated effort involving someone on the inside, a possibility that turned what had been a technical investigation into something considerably more uncomfortable for a company built on trust between colleagues.

Noah spent an uneasy few days after that realization looking at his own coworkers differently, cataloguing who had the access and the technical knowledge to make a change like that without leaving obvious fingerprints — a mental exercise that felt disloyal even as he told himself it was simply due diligence, the same due diligence he'd expect anyone to apply to him if the suspicion pointed his way instead.

Noah, given expanded access to help the outside firm trace the threshold change, found the insider's fingerprint in an unlikely place: a system maintenance log showing the threshold modification had been made using the credentials of a compliance officer named Derek Voss, a fifteen-year Corvale employee who happened to be on medical leave the exact week the change was logged.

Derek's credentials being used while he was on leave suggested either that Derek himself had made the change remotely, or that someone else had stolen his access during a period when his absence made detection less likely. The digital chase that followed involved cross-referencing badge swipe records, VPN logs, and a home office IP address that, to Noah's genuine surprise, matched neither Derek's home network nor any known Corvale remote-access point.

The IP address traced to a coworking space three states away, rented under a name that turned out to be an alias for a former Corvale contractor who had been let go eighteen months earlier following a dispute over access permissions he'd felt entitled to keep after his contract ended — a grudge, it turned out, with considerably more follow-through than most.

Noah spent two full days cross-referencing the coworking space's registration records against Corvale's old contractor database before the alias finally cracked, a process that felt, at the time, like assembling a puzzle with half the pieces deliberately hidden. The outside firm's lead investigator told him afterward that most insider-adjacent cases took months to crack this cleanly. Noah didn't feel lucky. He felt exhausted, and mostly relieved it was over.

The former contractor had kept a working copy of Derek's old credentials from his time at the company, installed the malware himself through a phishing email crafted to look like routine IT communication, and had been slowly testing the wire transfer system's limits for months, apparently building toward a single large transfer he planned to execute once he'd confirmed the threshold change would hold up under scrutiny.

Federal investigators, brought in once Corvale's outside firm confirmed the insider angle, froze the shell accounts the contractor had set up to receive the eventual transfer just four days before he'd scheduled it to execute — a timeline reconstructed afterward from his own planning documents, recovered from the same laptop that had been used to install the original malware.

The former contractor was arrested at the same coworking space his IP address had traced back to, still under the alias he'd used to rent it, a detail Noah found almost anticlimactic given how much technical sophistication the rest of the scheme had involved. Sometimes, he learned, the person behind an elaborate intrusion was simply someone with a grudge, a laptop, and more patience than anyone at Corvale had given him credit for.

Derek Voss, whose stolen credentials had made the whole scheme possible, was cleared of any wrongdoing once the investigation confirmed he'd genuinely been on medical leave throughout, though he told Noah afterward that the experience had left him oddly paranoid about his own login history for months, checking his access logs the way some people check that they've locked the front door.

Corvale rebuilt its entire fraud detection threshold system from scratch in the aftermath, with Noah promoted to a role specifically created to prevent exactly the kind of insider-enabled intrusion he'd stumbled onto during a routine access review. He kept a printout of the original ghost account's access log in his desk drawer, a reminder of how close eleven months of nightly logins had come to disappearing millions of dollars without anyone noticing at all.