KPMG secretly and repeatedly accessed a whistleblower's work computer, extracted documents laying out their data misuse allegations, and delivered the files to senior partners and the firm's former chief executive.
The accounting giant accessed the employee's work laptop multiple times without their knowledge. The files contained the whistleblower's own account of alleged data misuse inside the firm. KPMG's defense is that it had the legal right to access any employee's work device — technically accurate, but beside the point. What makes the case notable is the gap between what was permitted and what was done with it.
The episode exposes a structural blind spot in most whistleblower frameworks: formal protections typically attach after a complaint is filed, not during the window when an employee is still building a case on a work device. Routine IT access rights can, in practice, function as a corporate early-warning system against internal dissent — without triggering a single law. By the time a whistleblower assumes their complaint is private, it may already be on the CEO's desk.
Big Four firms have faced intensifying scrutiny over internal governance in recent years, and KPMG has navigated auditing controversies across multiple jurisdictions. An employee who believed their allegations were confidential was, apparently, wrong about that.
