Case file · UBIQUITI 2020

The Ubiquiti hack was an inside job: how a senior developer extorted his employer

Published 2026-09-29 · 4 min read · Missing control: Monitor privileged insider access

The hacker who tried to squeeze Ubiquiti for 50 bitcoin was a senior developer on its own cloud team, and after the break-in he joined the group investigating it.[1][4] This case file covers how he used access he already had, how a brief VPN failure pointed straight back to his home, and the one control that would have caught him sooner.

What happened

Nickolas Sharp joined Ubiquiti, the maker of Wi-Fi and networking gear, in August 2018 and worked in its cloud division, where he held administrator credentials for the company's Amazon Web Services accounts and its GitHub code repositories.[2][5] In December 2020, prosecutors said, he used those credentials to copy gigabytes of confidential data, including about 155 code repositories, while routing his traffic through a commercial VPN to hide where he was.[2][4] He also changed log retention settings so the records of what he did would disappear quickly.[2][3]

Ubiquiti spotted the intrusion in late December, and Sharp joined the internal response.[2][4] On January 11, 2021, the company told customers it had been breached.[5] Around the same time, an anonymous note demanded 50 bitcoin, about $1.9 million at the time, to stay quiet and to reveal a supposed backdoor into the network. Ubiquiti refused and went to law enforcement. The note's author then posted some of the stolen files online.[2][3][4]

On March 24, 2021, the FBI searched Sharp's home.[5] Days later, posing as an anonymous insider, he told a well-known security journalist that an outside attacker had gained full administrative control of the company's cloud and that Ubiquiti was playing it down. The story ran on March 30, and Ubiquiti's shares fell about 20%, wiping out more than $4 billion in market value.[1][3][5] He left the company around the end of March.[1][5]

How he got in

He did not have to break in at all. His job gave him administrator keys to the systems that held the company's code and cloud data, and nothing stopped a trusted cloud lead from using those keys in the middle of the night to pull down large amounts of data.[2]

The disguise was thin. To make the activity look like it came from an outsider, he connected through a paid VPN service. He then tried to cover the trail by shortening how long the cloud logs were kept.[2][3] Because he was also on the response team, he was in a position to see what investigators were looking at, which is exactly the problem with letting a person with broad, unwatched access investigate an incident involving that access.[4]

How it was caught

A household internet hiccup did most of the work. During the data theft, his home connection briefly dropped, the VPN stopped masking him, and his real home IP address showed up in the company's logs alongside the VPN address.[2][4] Investigators also tied the VPN account to a payment account in his name.[5] When agents confronted him and searched his home in March 2021, what he told them turned into a separate charge of lying to the FBI.[3]

Sharp was arrested and charged in December 2021 with computer fraud, sending threats across state lines, wire fraud and lying to the FBI.[2][5] Ubiquiti said at the time that the evidence pointed to someone with detailed knowledge of its cloud setup.[5]

What it cost

In February 2023 Sharp pleaded guilty to a computer intrusion charge, wire fraud and making false statements to the FBI.[3] In May 2023 he was sentenced to 6 years in prison and 3 years of supervised release, and ordered to pay $1,590,487 in restitution and forfeit equipment used in the crime.[1]

The ransom was never paid, but the damage did not depend on it. The false news story did more harm than the theft itself, knocking billions off the company's market value for a breach that was, in fact, one employee misusing his own access.[1][3]

The missing control

The missing control: monitoring what privileged insiders do with their access. Sharp's keys were legitimate, so the question was never whether he could get in. It was whether anyone would notice an administrator copying large amounts of code at odd hours and then turning down the logging.

An alert on bulk downloads, a rule that changes to log retention need a second approval, and logs copied somewhere the admin cannot edit would each have flagged the theft within days instead of leaving it to be discovered through a ransom note. Keeping people with suspicious access patterns off the investigation is part of the same control: whoever watches the watchers should not be the one being watched.

What to do in your business

Watch the case
The Ubiquiti Hacker Was Its Own DeveloperDrops 2026-10-14
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More insider risk cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. The Hacker News: Former Ubiquiti employee gets 6 years in prison for $2 million crypto extortion case
  2. The Register: Ex-Ubiquiti engineer charged with stealing data and extorting company
  3. SecurityWeek: Former Ubiquiti employee who posed as hacker pleads guilty
  4. Bitdefender: Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack
  5. The Record: Former Ubiquiti employee charged with hacking and extorting company