Londonchiropracter.com

This domain is available to be leased

Menu
Menu

The curious case of the Ubiquiti employee-whistleblower-hacker

Posted on December 2, 2021 by admin

I wish I was a crime podcast host right now — it’d be my favorite way to tell this tantalizing story about a tech worker hacking his own company, demanding a ransom, and later turning into a ‘whistleblower’ to cover his tracks.

According to a document published by a New York district court, Nikolas Sharp, a former employee of network device maker Ubiquiti, hacked the company’s system and demanded a $2 million ransom. This is just the tip of the iceberg of the story, so let’s unpack what happened.

Who is Nikolas Sharp?

Sharp was a cloud lead at Ubiquiti Networks from August 2018 to March 2021, according to his LinkedIn profile. Prior to this, he worked at companies like Amazon and Nike.

What was the big Ubiquiti security incident?

In January, the company, sent an email to its customers saying that a hacker had gained access to its systems hosted on third-party services —such as AWS — and some customer data including names, email IDs, addresses, and phone numbers may have been exposed. The company, which makes Wi-Fi mesh gears access points primarily for enterprise customers, said it wasn’t aware of any malicious activity on any user’s account.

You can read the full email in the tweet below:

Ubiquiti was breached. Notification emails went out to customers just now. Change your password on your Ubiquiti account pic.twitter.com/pm1ebVbPfS

— Milton Security (@MiltonSecurity) January 11, 2021

At the time of this disclosure, the company wasn’t aware of the hacker’s identity. The fun bit was that Sharp was a part of the team that was investigating the scope of the incident.

What did Sharp actually do?

As a cloud lead, Sharp had access to certain keys to get into the company’s AWS and GitHub repositories. On December 10 last year, he anonymously logged into the company’s AWS account, and a few days later, he accessed the company’s GitHub account. into the GitHub account.

Ubiquiti's Dream Machine access point
Ubiquiti’s Dream Machine access point

When he gained access to these accounts, he copied some of the company’s sensitive data to his own computer, including more than 155 repositories from GitHub.

On January 7, 2021, the company received an anonymous ransom email stating that if it paid 25 Bitcoins, the hacker would return the stolen data without publishing or using it. The sender also offered to inform the firm about an unprotected backdoor that could have further security implications for another 25 Bitcoins. The total value of 50 Bitcoins at that time was nearly $2 million, but the company didn’t pay that up.

On January 29, Sharp wiped the laptop he used to hack the company’s servers.

How did he get caught?

To mask his identity, Sharp had purchased a license for SurfShark VPN. Court documents suggested that he used this service on multiple devices.

When he was cloning repositories from the company’s GitHub repositories, the power went out at his house, and when he got reconnected, his IP was logged without any protection from the VPN.

That IP address was spotted later during the investigation. In March, The FBI issued a search warrant against Sharp and seized electronics from his house.

The whistleblowing

While the FBI investigation was going on, Sharp allegedly reached out to news organizations as a whistleblower. He told them that Ubiquiti had downplayed the scope and impact of the breach. He also claimed that the company failed to keep records of what accounts were accessing the sensitive data. You can read about Shap’s claims here.

To cover his tracks, Shap had also set auto-deleting commands on logs for AWS, so there would be no trace of activity on the account for more than a day.

So what next?

Sharp has four charges against him including hacking, wire fraud, and extortion, and he could face up to 37 years of prison if all charges are proven. So who’s making a podcast or a limited series on this story?

Source

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • SpaceX draws $89 billion in demand for its debut bond sale, one of the largest US offerings this year
  • The American dream is ‘very dead’ for young Americans, says Mrs. Dow Jones
  • Nearly 60% of TikTok videos shown to new users are AI slop, study finds
  • Apple’s design studio has lost nearly every Jony Ive-era designer. Incoming CEO John Ternus says he’ll fix it.
  • A 201-year-old mutual bank just launched an AI Center of Excellence with a startup partner

Recent Comments

    Archives

    • June 2026
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020

    Categories

    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    ©2026 Londonchiropracter.com | Design: Newspaperly WordPress Theme