The Ubiquiti hack was an inside job: how a senior developer extorted his employer
The hacker who tried to squeeze Ubiquiti for 50 bitcoin was a senior developer on its own cloud team, and after the break-in he joined the group investigating it.[1][4] This case file covers how he used access he already had, how a brief VPN failure pointed straight back to his home, and the one control that would have caught him sooner.
What happened
Nickolas Sharp joined Ubiquiti, the maker of Wi-Fi and networking gear, in August 2018 and worked in its cloud division, where he held administrator credentials for the company's Amazon Web Services accounts and its GitHub code repositories.[2][5] In December 2020, prosecutors said, he used those credentials to copy gigabytes of confidential data, including about 155 code repositories, while routing his traffic through a commercial VPN to hide where he was.[2][4] He also changed log retention settings so the records of what he did would disappear quickly.[2][3]
Ubiquiti spotted the intrusion in late December, and Sharp joined the internal response.[2][4] On January 11, 2021, the company told customers it had been breached.[5] Around the same time, an anonymous note demanded 50 bitcoin, about $1.9 million at the time, to stay quiet and to reveal a supposed backdoor into the network. Ubiquiti refused and went to law enforcement. The note's author then posted some of the stolen files online.[2][3][4]
On March 24, 2021, the FBI searched Sharp's home.[5] Days later, posing as an anonymous insider, he told a well-known security journalist that an outside attacker had gained full administrative control of the company's cloud and that Ubiquiti was playing it down. The story ran on March 30, and Ubiquiti's shares fell about 20%, wiping out more than $4 billion in market value.[1][3][5] He left the company around the end of March.[1][5]
How he got in
He did not have to break in at all. His job gave him administrator keys to the systems that held the company's code and cloud data, and nothing stopped a trusted cloud lead from using those keys in the middle of the night to pull down large amounts of data.[2]
The disguise was thin. To make the activity look like it came from an outsider, he connected through a paid VPN service. He then tried to cover the trail by shortening how long the cloud logs were kept.[2][3] Because he was also on the response team, he was in a position to see what investigators were looking at, which is exactly the problem with letting a person with broad, unwatched access investigate an incident involving that access.[4]
How it was caught
A household internet hiccup did most of the work. During the data theft, his home connection briefly dropped, the VPN stopped masking him, and his real home IP address showed up in the company's logs alongside the VPN address.[2][4] Investigators also tied the VPN account to a payment account in his name.[5] When agents confronted him and searched his home in March 2021, what he told them turned into a separate charge of lying to the FBI.[3]
Sharp was arrested and charged in December 2021 with computer fraud, sending threats across state lines, wire fraud and lying to the FBI.[2][5] Ubiquiti said at the time that the evidence pointed to someone with detailed knowledge of its cloud setup.[5]
What it cost
In February 2023 Sharp pleaded guilty to a computer intrusion charge, wire fraud and making false statements to the FBI.[3] In May 2023 he was sentenced to 6 years in prison and 3 years of supervised release, and ordered to pay $1,590,487 in restitution and forfeit equipment used in the crime.[1]
The ransom was never paid, but the damage did not depend on it. The false news story did more harm than the theft itself, knocking billions off the company's market value for a breach that was, in fact, one employee misusing his own access.[1][3]
The missing control
The missing control: monitoring what privileged insiders do with their access. Sharp's keys were legitimate, so the question was never whether he could get in. It was whether anyone would notice an administrator copying large amounts of code at odd hours and then turning down the logging.
An alert on bulk downloads, a rule that changes to log retention need a second approval, and logs copied somewhere the admin cannot edit would each have flagged the theft within days instead of leaving it to be discovered through a ransom note. Keeping people with suspicious access patterns off the investigation is part of the same control: whoever watches the watchers should not be the one being watched.
What to do in your business
- Know who holds the master keys. List every person and contractor with administrator access to your cloud, email, website and accounting systems, and remove any access that is not needed for their current job.
- Turn on download and admin alerts. Most cloud and file-sharing services can email you when someone downloads unusually large amounts of data or changes security settings. Switch those alerts on and send them to someone other than the admin.
- Protect the logs. Keep activity logs for at least 90 days and store a copy where your IT person cannot shorten or delete them.
- Require two people for security changes. Changes to logging, backups or admin accounts should need sign-off from a second person, even if that person is the owner.
- Bring in an outside view during an incident. If you suspect a breach, have an independent IT firm or advisor lead the review rather than relying only on the staff whose access is involved.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- How a security training company hired a North Korean fake IT worker
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- The Hacker News: Former Ubiquiti employee gets 6 years in prison for $2 million crypto extortion case
- The Register: Ex-Ubiquiti engineer charged with stealing data and extorting company
- SecurityWeek: Former Ubiquiti employee who posed as hacker pleads guilty
- Bitdefender: Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack
- The Record: Former Ubiquiti employee charged with hacking and extorting company