10 years ago, I nearly lost my career over a pentest.
I found a way to compromise salary data during an authorized engagement. I reported it asap, but made 2 mistakes:
1️⃣ I broke the Rules of Engagement (ROE). It said to stop when sensitive data was accessed. I wanted to show impact, so I fetched 1,000 records.
2️⃣ I got cocky. I joked to a coworker, “If this pentest taught me anything, it’s that I’m the lowest-paid security engineer here.”
That afternoon, my manager called me in. I thought it was to celebrate the find, but someone overheard my joke. Instead, he said: “Farzan, I hear you’ve been looking at people’s salaries. What’s going on?”
My intent was ethical, but it dawned on me that the optics weren’t. It went to a legal and ethics review, and for a moment, I thought my career was over. The case was eventually dropped, but I lost my promo that year.
It taught me that judgment matters more than technical skill.
My advice to pentesters and red teamers:
👉 Just because you can, doesn’t mean you should. And if you have to think about it, you probably shouldn’t.