Yep. Bad opsec at the org level. Either the eng was doing work stuff on a personal laptop or personal stuff on a work laptop. This is easily preventable and should be table stakes when handling money, phi, etc
What does _phi_ stand for?
pii = personally identifiable information