Ubiquiti dev charged with knocking $4bn off firm's value after insider threat spree
- Reference: 1638479113
- News link: https://www.theregister.co.uk/2021/12/02/nickolas_sharp_ubiquiti_hack_charged/
- Source link:
US federal prosecutors claimed that 36-year-old Nickolas Sharp had used his "access as a trusted insider" to steal data from his employer's AWS and GitHub instances before "posing as an anonymous hacker" to send a ransom demand of 50 Bitcoins.
The DoJ statement does not mention Sharp's employer by name, but a Linkedin account in Sharp's name says he worked for Ubiquiti as a cloud lead between August 2018 and March 2021, having previously worked for Amazon as a software development engineer.
[1]
In an eyebrow-raising indictment
[2]PDF , 19 pages, non-searchable] prosecutors claim Sharp not only pwned his employer's business from the inside but joined internal damage control efforts, and allegedly posed as a concerned whistleblower to make false claims about the company wrongly downplaying the attack's severity, wiping $4bn off its market capitalisation.
[3]
[4]
Criminal charges were filed overnight in an American federal court against Sharp, of Portland, Oregon. The indictment valued the 50 Bitcoins at $1.9m "based on the prevailing exchange rate at the time."
US attorney Damian Williams said in a US Justice Department [5]statement : "As further alleged, after the FBI searched his home in connection with the theft, Sharp, now posing as an anonymous company whistle-blower, planted damaging news stories falsely claiming the theft had been by a hacker enabled by a vulnerability in the company’s computer systems."
[6]
Sharp is alleged to have downloaded an admin key which gave him "access to other credentials within Company-1's infrastructure" from Ubiquiti's AWS servers at 03:16 local time on 10 December 2020, using his home internet connection. Two minutes later, that same key was used to make the AWS API call GetCallerIdentity from an IP address linked to VPN provider Surfshark – to which Sharp was a subscriber, prosecutors claimed.
Later that month, according to the prosecution, he is alleged to have set AWS logs to a one-day retention policy, effectively masking his presence.
[7]Insider threat? Pffft. Hackers on the outside are the ones mostly making off with your private biz data, says Verizon
[8]IT consultant who deleted every account on UK company Jet2's domain cops 5 months in jail
[9]Remember insider threat? Old news now. Focus on malware detection, says EU infosec agency
[10]Google reveals own security regime policy trusts no network, anywhere, ever
Eleven days after the AWS naughtiness, the indictment claims, he used his own connection to log into Ubiquiti's GitHub infrastructure. "Approximately one minute later," alleged the indictment, Sharp used Surfshark to ssh into GitHub and clone around 155 Ubiquiti repos to his home computer.
"In one fleeting instance during the exfiltration of data," said the indictment, "the Sharp IP address was logged making an SSH connection to use GitHub Account-1 to clone a repository."
For the rest of that night, prosecutors said, logs showed Sharp's personal IP alternating with a Surfshark exit node while making clone calls. Although it was not spelled out in the court filing, prosecutors appeared to be suggesting that Surfshark VPN was dropping out and revealing "the attacker's" true IP.
[11]
Ubiquiti discovered what was happening on 28 December. Prosecutors claimed Sharp then joined the company's internal response to the breaches.
In January 2021 Ubiquiti received a ransom note sent from a Surfshark VPN IP address demanding 25 Bitcoins. If it paid an extra 25 Bitcoins on top of that, said the note, its anonymous author would reveal a backdoor in the company's infrastructure. This appears to be what prompted Ubiquiti to [12]write to its customers that month alerting them to a data breach . Ubiquiti did not pay the ransom, said the indictment.
Shortly after Federal Bureau of Investigation workers raided Sharp's home, prosecutors claim he "caused false or misleading news stories to be published about the Incident and Company-1's disclosures and response to the Incident. Sharp identified himself as an anonymous source within Company-1 who had worked on remediating the Incident. In particular, Sharp pretended that Company-1 had been hacked by an unidentified perpetrator who maliciously acquired root administrator access [to] Company-1's AWS accounts."
This appears to be referencing an [13]article by infosec blogger Brian Krebs that was published that day, on 30 March 2021. He spoke "on condition of anonymity for fear of retribution by Ubiquiti", and El Reg (among many other outlets) [14]followed up Krebs' reporting in good faith . In that article, the "whistleblower" said he had reported Ubiquiti in to the EU Data Protection Supervisor, the political bloc's [15]in-house data protection body.
We have asked Krebs for comment.
Sharp is innocent unless proven guilty. He is formally charged with breaches of the Computer Fraud and Abuse Act, transmitting interstate threats, wire fraud and making false statements to the FBI. If found guilty on all counts and handed maximum, consecutive sentences on each, he faces 37 years in prison. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YalQHSJP@W@IWuqHsTV8mwAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://regmedia.co.uk/2021/12/02/nickolas_sharp_us_indictment.pdf
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YalQHSJP@W@IWuqHsTV8mwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YalQHSJP@W@IWuqHsTV8mwAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.justice.gov/usao-sdny/pr/former-employee-technology-company-charged-stealing-confidential-data-and-extorting
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YalQHSJP@W@IWuqHsTV8mwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2020/05/19/verizon_data_breach_report/
[8] https://www.theregister.com/2019/12/18/jet2_scott_burns_prison_sentence/
[9] https://www.theregister.com/2020/10/20/enisa_annual_report_cybersecurity/
[10] https://www.theregister.com/2016/04/06/googles_beyondcorp_security_policy/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YalQHSJP@W@IWuqHsTV8mwAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2021/01/12/ubiquiti_data_leak/
[13] https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/
[14] https://www.theregister.com/2021/04/01/ubiquiti_data_breach/
[15] https://edps.europa.eu/data-protection/our-role-advisor_en
[16] https://whitepapers.theregister.com/
Re: Either way, this is an indictment of Ubiquiti
"Even before information technology, there was an adage about putting all of your eggs in one basket."
This. ^^
Re: Either way, this is an indictment of Ubiquiti
Technically, no significant damage was done. Data was exfiltrated . . . to an employee's computer. The real damage done was by the claim to the press that there was a more significant data breach than actually occurred, which shows how vulnerable companies are to the mere appearance of data loss. It sounds like Ubiquiti tried to do the right thing, ethically speaking, and were punished by the market as a result.
Re: Either way, this is an indictment of Ubiquiti
Customers (and Ubiquiti, for that matter) had no way of knowing the difference and had to react accordingly. "No significant damage was done" only if you assume this costs nothing.
We must deal with information that we are given. We then evaluate the credibility vs. the costs / benefits of reacting. In this case, the most reasonable response was to react as if the information was true.
The problem is that Ubiquiti made themselves custodians of data whose security was absolutely vital and wound up in a position (due to decisions they made) where they could not determine the security of that data.
In fairness, this is an extremely difficult problem to tackle well. But if a company is making that commitment on a large scale, then they need to be able to deliver on that commitment. Ubiquiti failed catestrophically.
Either way, this is an indictment of Ubiquiti
Even if all of these allegations are true, I'm not sure if this makes Ubiquiti come out looking better or worse. If one person can cause this much infrastructure-level damage, what does it say about their infrastructure security architecture and overall commitment to security?
One of the reasons I've been sharply critical about the mass-centralization of vital data is that it increases the value of a security breach to obscene levels. Even if an inside threat isn't inherently malicious, what about blackmail, extortion, etc.? There are many parts of the world where grabbing somebody's family and cutting off parts until compliance is reached is not exactly out of the question. I would never blame that person for complying. And if the value of a large-scale breach of, say, Google or Microsoft's cloud-hosted workspaces is in the hundreds of millions or even billions of dollars / Euros / pounds, how do you even defend against some group with the budget and discipline to make a serious, no-holds-barred attempt at that? With the current state of international relations, can we even rule out governments (including the "civilized Western" ones) if they're not in it for profit, just creating mass damage?
Our industry has had many bad experiences caused by the technological equivelants of biological monoculture, and instead of learning from these it seems to be betting harder and harder on this.
Even before information technology, there was an adage about putting all of your eggs in one basket.