I was at a large web dev company where an employee put in his two week notice, then was able to access several of the companies servers and exfiltrate nearly every app or web site they had built in the last two years.
Rumor had it he was using the code to start a dev company on his own and this was the "seed" code that would help him get up and running much faster. AFAIK nothing ever happened to him legally.
Dumbass didn't realize that all SSL traffic was being MITM'd. I never sent any sensitive over personal email from work, being well aware of the practices (also helps to have friends in compliance).
The trick is to use a piece of software that doesn't use your system's certs but has it's own built in, like run Linux in a VM and use that browser. That way, you'll see the MitM attack.