● Data Breaches

KPMG Senior Partner Expelled Over Unauthorized Access to Confidential Documents

July 24, 2026 · snewle
KPMG Senior Partner Expelled Over Unauthorized Access to Confidential Documents

A major accounting firm has expelled a senior partner following confirmation of a serious insider threat incident involving unauthorized access to confidential client documents. KPMG’s former chief operating officer, Eileen Hoggett, was immediately removed from the firm after a whistleblower claim revealed that senior partners had illicitly accessed sensitive Lendlease board documents and stored them in a work locker.

What Led to the Immediate Expulsion?

The incident represents one of the most serious allegations to emerge from a wider KPMG scandal. According to Colin Kruger, who reported on the matter, the whistleblower claim alleged that senior partners within the firm had gained unauthorized access to highly sensitive documents belonging to Lendlease’s board. These confidential materials were subsequently kept in a physical work locker, raising significant concerns about document security and insider access controls.

How Did KPMG Respond to the Breach?

The firm’s leadership took swift action once the whistleblower allegations were confirmed. Hoggett, who held the position of chief operating officer, was immediately expelled from the partnership. The confirmation of the unauthorized access and improper storage of client documents prompted the rapid response, demonstrating the severity with which KPMG treated the security breach.

Why Does This Insider Threat Matter?

This incident serves as a stark reminder of the persistent risks posed by insider threats within professional services organizations. When senior executives and partners—individuals with elevated access privileges and deep organizational trust—mishandle confidential client information, the potential for damage extends beyond immediate data exposure. The case highlights vulnerabilities in physical document security protocols, even within organizations that handle sensitive business information as part of their core operations.

The involvement of a chief operating officer in such an incident is particularly concerning, as individuals in leadership positions typically have broader access to confidential materials and are expected to model proper security practices. The storage of illicitly accessed documents in a work locker suggests a deliberate effort to retain unauthorized materials rather than an inadvertent security lapse.

The whistleblower mechanism proved crucial in bringing this breach to light, underscoring the importance of internal reporting channels for identifying insider threats that might otherwise remain undetected. Organizations across all sectors can learn from this incident about the ongoing need for robust access controls, monitoring of document handling practices, and clear consequences for security violations, regardless of an employee’s seniority level.

Source: DataBreaches.net