I've witnessed it happen to a colleague early on in my career. He posted how trivial it was to cause an IoT device to reset because they had a reset password only protected by hashing an English word that they changed every update. There are multiple security lapses there, and he didn't even mention the really scary ones, this one was almost silly.
Turns out the parent company of the IoT device and his parent company were the same, and calls got made, his post misunderstood by management, and he got told to find a new job somewhere else.
Still makes my blood boil, and I'd name names, but neither company exists anymore. It did teach me to be _very_ careful what I post online, even when I'm anonymous.