Glossary

Logic Bomb

A logic bomb is like a time bomb in software. It sits quietly in a program doing nothing until something triggers it - maybe a certain date, or an employee getting fired. Then it activates and can delete files, crash systems, or cause other damage.

What is Logic Bomb?

Malicious code inserted into a program that remains dormant until triggered by a specific event, such as a date, user action, or system condition.

Why Should You Care?

Logic bombs pose an exceptional insider threat because they are embedded by trusted employees or contractors with legitimate system access and remain dormant and undetectable until detonation. A single triggered logic bomb can destroy critical data, crash essential systems, and halt business operations for days—costing organizations heavily in recovery and lost revenue while potentially triggering regulatory penalties under data protection laws. Unlike external attacks that can be detected at the perimeter, logic bombs bypass most security controls because they originate from within trusted systems.

Is your business exposed?

Real-World Example

In 2008, Fannie Mae contractor Rajendrasinh Makwana planted a logic bomb after being terminated, scheduling malicious code to execute months later and destroy data across thousands of the company's servers. Another engineer discovered the hidden code before it could detonate, averting what could have caused major damage and extended downtime. Makwana was convicted and sentenced to prison, making this one of the most documented insider logic bomb cases in corporate security history.

How to Protect Against Logic Bomb

  1. 1.

    Review code changes from departing employees

  2. 2.

    Implement code review processes

  3. 3.

    Monitor for unusual scheduled tasks

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required