A Raspberry Pi was found in a network closet, and after analysis, it was discovered to be a malicious device with a WiFi and Bluetooth connection. The device was found to be connected to a paid IoT service and had a nodejs app that collected data, but its exact purpose was unclear. The owner of the device was identified through a username and WiFi credentials, and it was found to be an ex-employee who had been given a key to the building. The incident was handled internally, and the ex-employee was told to leave without further action.