Darket Diaries
Darket Diaries

178: Ubiquiti

Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. What do you do when the company you work for isn't securing their soft

Featured Speakers

Jack Rhysider Host

Topics Discussed

Episode Summary

Executive Summary: This episode chronicles how Ubiquiti cloud engineer Nicholas Sharp, frustrated by stalled advancement and perceived underappreciation, used his legitimate access and a VPN to steal internal data, impersonate an outside attacker, extort his employer, and later try to frame Ubiquiti as misleading customers. The investigation, FBI raid, and forensic evidence exposed the scheme, ending with Sharp’s guilty plea and six-year prison sentence.

Main Topics: Nick Sharp’s career and resentment at Ubiquiti (Priority: 5/5): Sharp rose from AWS to lead Ubiquiti’s cloud team, but despite high pay and responsibility he felt overlooked, underpaid, and ignored by leadership, especially around security priorities. Insider misuse of legitimate access (Priority: 5/5): The core crime was not a classic external hack but an insider using normal credentials, shared accounts, and weak access controls to download hundreds of private repositories and sensitive logs. Operational security failures and logging weaknesses (Priority: 5/5): The story repeatedly highlights poor segmentation, overly broad privileges, weak auditing, and insufficient monitoring as conditions that made the theft possible and difficult to detect. Extortion and deception through ransomware-style tactics (Priority: 4/5): Sharp attempted to pressure Ubiquiti with an anonymous ransom note demanding Bitcoin and threatening to publish stolen data, trying to make it look like an outside criminal operation. Forensic investigation and attribution (Priority: 5/5): Despite VPN use and log manipulation, investigators traced activity through IP evidence, router traffic, device fingerprints, and later FBI searches that tied the theft to Sharp’s home network and devices. Public fallout, whistleblower framing, and legal consequences (Priority: 4/5): Sharp later contacted journalist Brian Krebs to amplify claims that Ubiquiti misled customers, causing stock damage and reputational harm, but he was eventually arrested, pleaded guilty, and was sentenced to prison.

Key Arguments: The transcript argues that insider threats can be more dangerous than external attacks because a trusted employee can exploit legitimate access without triggering obvious alarms. It suggests that Ubiquiti’s broad permissions and poor logging created the conditions for a large-scale data theft that should have been easier to detect. It presents Sharp’s motive as a mix of grievance, ego, and financial gain rather than purely ideological protest, despite his later claim that it was a security drill. It argues that security incidents often become worse when organizations under-communicate or frame events ambiguously, which can amplify customer mistrust and market damage. It shows that technical concealment measures like VPNs and log cleanup are often insufficient against layered forensic analysis and endpoint/network evidence. It implies that publicly exposing a company’s security weakness can be weaponized by insiders for revenge or leverage, not just whistleblowing. It underscores that weak internal controls around shared accounts, access rights, and audit retention can turn one employee into a high-impact threat actor.

Data Points: Age: 32 - Nick Sharp was 32 years old when he joined Ubiquiti in 2018. Annual salary: $250,000 - Sharp was paid this amount to manage Ubiquiti cloud solutions. Company headcount: 800 employees - Ubiquiti is described as having about 800 employees at the time. Amount of Ubiquiti theft: Over 100 repositories - Sharp cloned more than 100 private repositories in a single overnight operation. Time of initial test access: 3:16 a.m. - Sharp logged out after testing access to Ubiquiti’s vault, then another login occurred at 3:18 a.m. VPN subscription length: 27 months - Sharp purchased a Surfshark subscription to hide his activity. Ransom demand: 25 Bitcoin - The anonymous ransom note demanded 25 BTC for stolen data and another 25 BTC for the alleged back door. Estimated ransom value: About $2 million - The 25 Bitcoin demand was worth roughly this amount at the time. Market cap loss: $4 billion - Ubiquiti stock fell about 20% in two days, wiping out roughly this amount in market value. CWT ransom: $4.5 million - Carlson Wagon Lit Travel negotiated down from an initial demand of $10 million. CWT initial demand: $10 million - Referenced as the ransom amount demanded in the CWT ransomware case. Garmin disruption: 4 days - Garmin’s systems were reportedly down for four days during its ransomware incident. Sentence: 6 years - Sharp was sentenced to six years in prison after pleading guilty. Potential wire fraud penalty: 20 years - The transcript notes the serious wire fraud charge could have carried this maximum penalty.

Pivotal Quotes: "No BTC. No talk. We're done here." — Nicholas Sharp (as the anonymous extortionist): Message sent after Ubiquiti did not pay the ransom by the deadline. "I’m being framed. Someone must have used my PayPal account." — Nicholas Sharp: His response to FBI agents confronting him about the Surfshark VPN purchase. "I wanted Ubiquiti to finally pay attention to its ongoing security issues." — Nicholas Sharp: His later attempt to reframe the intrusion as an unsanctioned security drill during sentencing.

Implications: The episode shows how insider threats exploit trust, weak access controls, and poor logging. For companies, least privilege, monitoring, and incident response are essential; for listeners, motives matter less than the damage when privileged access is abused.

🔓 Sign Up for Unlimited Episode Search

About Darket Diaries

Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.

View all episodes from Darket Diaries