First saw something like this 30+ years ago - someone grabbed a list of publicly available userIDs from the company's email system and apparently either manually or using a keyboard macro simply tried multiple times to logon with an incorrect password to lock out the entire company's thousands of user and team IDs. The company used mainframe systems/databases with centralized passwords, so didn't take long at all (not even 30 minutes, IIRC) to get everyone back in business. One imagines that such a simple 'attack' - essentially the same as what the guy did some 30 years later in 2021 - would wreak a lot more havoc in today's world with its overwhelmingly-complicated intertwined security layers, which are further compounded by the need to get consensus from a number of parties - e.g., security, risk, compliance, governance, operations, legal - that it's safe to reopen things for business even after a fix is identified. It seems part of this guy's hefty sentence is likely attributable to businesses relying on systems and infrastructure and bureaucracy that are vulnerable to and unable to recover quickly from even trivial 'attacks' like this that leave systems and data untouched, no?