Chapter 12 - THE INVESTIGATION

The company hired an external forensic firm.
Findings:
Claire intentionally emailed ATLAS_FINAL_PACKAGE.zip to Vertex.
Vertex did not solicit the package.
The package contained company source code and customer-derived data.
The sensitive staging file entered the package because Ethan’s temporary local test folder was included by the packaging script.
Security controls failed at several points:
poor local-data handling,
no automated content scan before package creation,
founder policy exception without documentation,
lack of data-loss prevention on personal outbound devices,
and spouse access to an unlocked home-office machine.
Claire did not hack Morgan Systems.
She used Ethan’s accessible laptop and her own email.
That distinction mattered legally.
The report did not call it:
cyberattack.
It called it:
intentional unauthorized transmission by a household-access actor combined with internal data-handling control failure.
Ugly.
Precise.
Hard to argue with.
The forensic firm also found Claire had not searched for client data.
Her activity showed:
desktop folder access,
file copy,
email attachment,
send.
No browsing of staging subfolders.
No opening of customer files.
No search for borrower names.
That mattered to intent.
Claire meant to harm Ethan’s project.
She did not intend to expose borrower information.
Rachel told her:
“Intent matters for some consequences. Foreseeability matters for others.”
Claire asked:
“What does that mean?”
“It means you can be less culpable for one harm without being blameless for the act that created it.”
May you like
Claire wrote that sentence down.
It was the most accurate description of the entire case.