Live data from Hacker News

Former Ubiquiti employee charged with stealing data and extorting company

justice.gov

1–10 of 244 posts

Re: Former Ubiquiti employee charged with stealing data and extorting company

#2
Wow, quite brazen. What an interesting read.

Couple things that stood out to me was that the incident occurs in December and the raid ensues March 24th, so roughly 3 months. Building the case I presume.

Then after the raid, the accused doubles down and seeds fake news stories.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#5

Wow, quite brazen. What an interesting read. Couple things that stood out to me was that the incident occurs in December and the raid ensues March 24th, so roughly 3 months. Building the case I presume. Then after the raid, the accused doubles down and seeds fake news stories.

It sounds like he got caught because his VPN dropped during some sort of outage. It's funny because I feel like "don't do crime from your home network" should be an incredibly obvious concept.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#6
Damn. I remember reading about the original "hack" here and getting very concerned about the level of access ascertained by the attacker. I'm almost relieved it was a foolishly clumsy inside job and some of the initial hypotheses about rogue nation state root access to UI devices did not materialize. Brazen, indeed, for him to also have been on the team tasked with cleaning it up.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#8
> At one point during the exfiltration of Company-1 data, SHARP’s home IP address became unmasked following a temporary internet outage at SHARP’s home.

This seems to explain how this comes down after less than a year since the incident. Surfshark now supports an outage related kill switch, not sure if that's a new feature.

Re: Former Ubiquiti employee charged with stealing data and extorting company

#10

Wow, quite brazen. What an interesting read. Couple things that stood out to me was that the incident occurs in December and the raid ensues March 24th, so roughly 3 months. Building the case I presume. Then after the raid, the accused doubles down and seeds fake news stories.

It sounds like he got caught because his VPN dropped during some sort of outage. It's funny because I feel like "don't do crime from your home network" should be an incredibly obvious concept.

He also used keys as the "attacker" that were known to be his as a regular employee. That seems like a n00b move.
Post reply on HN