This sort of thing is somewhere in the "a vulnerability is not an exploit" and "security through obscurity" space. There may not be any reason to get scared over this *particular* incident, but it does serve as a good wake up call for considering what other things *could* be done in the "Click Here to Kill Everybody" future. I think the biggest problem was the shared password, leaving no accountability, which means the management must be blamed. cdf8d4db9473e52eea6cd18ec83a996aff5e8dfda931b14706bb99070f8cd160