Unlike some people have commented, there is no account takeover. Employee is simply removed from the organization and all access to organization private repositories and forks is removed. Organization owners can delete forks of private repositories even on personal accounts, if they have allowed them to be created. The forks of private repositories are always private and share permissions with the upstream.