A March 2026 class action says Opexus gave privileged access to twin brothers with public records of attacking government systems, and that the fallout reached people who filed complaints with the EEOC.
OpexusCasepointData BreachInsider ThreatEEOCTL;DR
- Opexus sells case-management and Freedom of Information Act (FOIA) software to federal agencies. The complaint says it is used by 80% of them.
- In February 2025, twin brothers working as Opexus engineers allegedly deleted dozens of government databases and copied files. Both were federally charged over the incident.
- The complaint alleges the brothers had 2015 federal convictions for hacking and wire fraud, and that Opexus either missed the record or failed to cut off their access quickly once it surfaced.
- The EEOC emailed affected people on January 9, 2026, saying it learned of the compromised data around December 18, 2025. Roughly ten months separate the incident from that notice.
- Bobby Dees, an Alabama resident, sued on behalf of a proposed nationwide class. Nothing here has been tested by a court, and Opexus’s response isn’t in the complaint.
The central question is simple: who checked the people holding the keys, and how long did anyone tell the people whose records were inside?
Transparency notice. This article relies on a single document: the class action complaint filed March 16, 2026. A complaint is one side’s account. Its statements are allegations, not court findings, and much of its factual material comes from news reports and web pages it cites rather than from evidence tested in court. No judge has ruled on any claim, and the complaint doesn’t include a response from Opexus.
The Facts
Opexus, formerly AINS, LLC, builds software that agencies use to run FOIA requests, audits, investigations, and case files. Those systems hold records that people submitted to the government. The complaint says the company has described its platforms as trusted by 80% of federal agencies, and that it has held tens of millions of dollars in government contracts. It is owned by a private equity firm.
The complaint says that in February 2025 two of its engineers, twin brothers Muneeb and Sohaib Akhter, used their authorized access to delete, corrupt, and copy data from systems that stored government agency records. It describes dozens of deleted databases, including FOIA and audit records, and disruption to the FOIAXpress case-management software that agencies rely on.
What Opexus Is Accused of Doing
The lawsuit doesn’t accuse Opexus of the deletions themselves. It accuses the company of setting the conditions for them. The complaint says the brothers were prosecuted and sentenced in 2015 for a coordinated cyberattack on government systems, including those of the State Department, plus wire fraud, and that those records were public before Opexus hired them. It argues that any contractor exercising ordinary care would have found the history and would not have handed them privileged access to audit, investigative, or FOIA systems.
The complaint’s account of how the history came to light is secondhand. Citing news reporting, it says the brothers’ criminal past surfaced when one of them was offered a job with the Federal Deposit Insurance Corporation’s Office of Inspector General, which required a background check. FDIC officials then allegedly flagged the brothers as insider threats, which prompted Opexus to act. Dees says that even after Opexus was told, it failed to promptly revoke or restrict their access.
The complaint also lists security controls it says were missing or weak: limits on how much access any one person holds (“least privilege”), monitoring of privileged users, alerts for bulk copying or deletion, and rapid removal of access when someone is being let go. These are drawn from federal guidance such as NIST Special Publication 800-53 and Federal Trade Commission (FTC) advice. The complaint infers the absence of these controls from the fact that the deletions and copying happened. It doesn’t cite internal Opexus documents showing what controls were in place.
Who Was Affected
Dees says he submitted personal information to the Equal Employment Opportunity Commission (EEOC), the federal agency that handles workplace discrimination charges, in connection with an employment matter. The EEOC uses outside contractors to store and manage case files. On January 9, 2026, the EEOC emailed him a “Notice of Data Security Incident.” The complaint reproduces it.
“handle data in an unauthorized (UA) and prohibited manner in early 2025”EEOC notice, January 9, 2026, describing staff of a third-party vendor
The notice adds that personally identifiable information “may have been exposed,” possibly including name and other identifying or contact information, and that the review was ongoing with law enforcement involved. It doesn’t name Opexus.
That is narrower than the picture the complaint paints elsewhere. The complaint says Opexus generally stores names, Social Security numbers, financial account numbers, and similar details across its government work. The EEOC notice, however, mentions only name and other identifying or contact information for this portal. The complaint says the class includes thousands, “if not tens of thousands,” of people, and says the exact number is in Opexus’s records. It offers no confirmed count of people whose data was actually taken.
Data deletion and data copying are different harms. The complaint alleges both, and says copied files may now sit “in unauthorized hands.” It doesn’t claim any of Dees’s data has been used for fraud. His alleged injuries are loss of privacy, higher risk of identity theft, time and money spent on protection, and emotional distress.
The Timeline
The brothers are prosecuted and sentenced for a federal hacking and wire fraud conspiracy, according to the complaint.
The alleged deletions and file copying take place on Opexus systems.
The EEOC says it was made aware of the compromised data.
The complaint cites a Bloomberg report of an indictment tied to the breach.
The EEOC emails Dees the incident notice.
Dees files the class action in federal court in Washington, D.C.
What Opexus Knew, and When
On knowledge, the complaint uses two theories at once. One is that Opexus “knew or should have known” of the convictions through ordinary pre-employment screening. The other, stated more concretely, is that the history was flagged to Opexus after the FDIC check and that access wasn’t promptly cut. It doesn’t say when that notice arrived or how long access continued. Those dates are the gap in the story.
The same gap applies to disclosure. The complaint says, on information and belief, that Opexus or affected agencies learned of the incident near the time it happened, given the operational disruption and law enforcement response. The EEOC’s own notice says it learned of the compromised data around December 18, 2025. The complaint doesn’t reconcile these accounts, and neither can this article. It also cites an FTC privacy assessment stating that Opexus’s FTC contract requires it to notify the agency immediately of breaches that may affect FTC data. That quote concerns the FTC contract, not the EEOC’s.
“This was not a close call or a nuanced judgment error.”
The complaint’s characterization of the hiring decision (an allegation)
The Legal Fight
Dees brings five counts. Four are on behalf of a proposed nationwide class of anyone whose personal information was accessed, copied, destroyed, or placed at material risk by the February 2025 incident: negligence (including negligence per se, meaning breach of a safety rule can itself count as carelessness), negligent and wanton hiring, retention, and supervision, invasion of privacy, and breach of fiduciary duty. The fifth, under the Alabama Deceptive Trade Practices Act, is on behalf of an Alabama subclass. It alleges Opexus implied that its data security was reasonable when it wasn’t.
He seeks compensatory and punitive damages, statutory or enhanced damages where allowed, court orders requiring stronger security such as least-privilege access and regular audits, and a jury trial. The complaint doesn’t state a dollar figure, though it invokes the federal Class Action Fairness Act on the basis of more than $5 million at stake and more than 100 class members.
What Has Been Decided, and What Hasn’t
Nothing on the merits. The case was filed on March 16, 2026, and the complaint says Opexus was to be served by certified mail. No court has certified a class, ruled on any claim, or made any finding about Opexus’s hiring or security. The brothers’ criminal case is separate: the complaint says they were arrested and charged, and cites a Justice Department announcement, but this document doesn’t report a verdict, and the charges against them are allegations until resolved.
One more caution. The complaint says Opexus merged with Casepoint in January 2025 in one paragraph and in 2021 in another. Which is right isn’t established here.
What Remains Unresolved
| Question | What the complaint says | Status |
|---|---|---|
| Did Opexus run background checks? | Alleges checks were inadequate or missed the convictions | Allegation; no Opexus account |
| How long did access continue after the flag? | Says it wasn’t promptly revoked; gives no dates | Unresolved |
| What data was copied? | Says files were exfiltrated and may contain PII | EEOC says PII “may have been” exposed |
| Has any data been misused? | Alleges increased risk only | No misuse alleged for Dees |
| How many people are affected? | “Thousands, if not tens of thousands” | Unconfirmed estimate |
What to Watch
- Whether Opexus responds in court, and whether it disputes the brothers’ hiring history or its access controls.
- Whether the court lets the case proceed as a class action covering everyone whose data was in the affected systems.
- Further updates from the EEOC, which told recipients its review was ongoing and that updates would follow.
- The outcome of the criminal case against the two former engineers.
The core dispute is a timing question that the complaint can’t answer alone: what Opexus knew about these two employees, on what date it knew it, and how much data left its systems before access was closed.
The source document for this investigation is attached below.



