This happened on my watch in Prod Support for a certain oil company.

The dev/prod Oracle databases had the same internal password. Luckless dev connected to what they believed was their dev instance in Toad and then dropped the schema.

They then called us to advise what had happened once they realised their mistake. We restored from backup (not before they bitched about how long it took to recover) but they never should have been able to do so in the first place.

Rule Number 1: Restrict access properly to your prod environment. That means no recording random username/password combos in docs, scripts etc.

Rule Number 2: Don't share credentials across environments.

Anon for obvious reasons.

