Darknet Diaries - 178: Ubiquiti
Episode Date: August 4, 2026Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he w...as being listened to enough. What do you do when the company you work for isn't securing their software up to your standards? Well, he thought he needed to teach them a lesson, but in the end, he learned an even bigger lesson.SponsorsThis show is brought to you by Drata. Drata is the trust management platform that uses AI-driven automation to modernize governance, risk, and compliance, helping thousands of businesses stay audit-ready and scale securely. Learn more at drata.com/darknetdiaries.This show is sponsored by Material Security. Your cloud office (think Google Workspace or Microsoft 365) is the core of your business, but it’s often protected by scattered tools and manual fixes. Material is a purpose-built detection and response platform that closes the gaps those point solutions leave behind. From email threats to misconfigurations and account takeovers, Material monitors everything and steps in with real-time fixes to keep your data flowing where it should. Learn more at https://material.security.Support for this show comes from ThreatLocker. ThreatLocker is a Zero Trust Platform that gives organizations control over what can run and what users and devices can access. It combines prevention with real time detection and automated response, helping security teams stop unauthorized activity and quickly contain compromised machines. Learn how ThreatLocker can strengthen your defenses at threatlocker.com/Darknet.View all active sponsors.SourcesFull list of sources on the show page: https://darknetdiaries.com/episode/178/
Transcript
Discussion (0)
I'm just going to get right into it.
I don't even want to ask her name because I don't even want to know who's doing this,
but some of the first time you did this.
I started a new job a couple of months back,
and it's entirely remote work from home except for the occasional trip to the office.
There are maybe eight people in the company who work at the main office
that would recognize me at any given point.
So I saw an opportunity and decided to run with it.
I was going to try something I'd never done before and steal food.
This is a famous office thing.
I'm a university student at the same time as being a full-time employee.
So I wanted to, like, everyone talks about this as a thing,
and the office might as well become a member of the professional world.
And so I just took a sandwich.
Where?
Just from the office fridge.
We have three refrigerators.
It's a little two-story office.
So I just went upstairs to a floor where my team would never be on.
and took a sandwich.
Now, so you open the fridge to see what's in there.
You're hungry.
Like, that was the whole goal is to find something to eat out of there.
And do you see, like, an old container and some spoiled milk and sandwich
and decide, okay, the sandwich is the best thing?
Or what goes through your mind on picking it?
It was a couple of different things, but I thought,
what's the most inconspicuous thing?
Because the sandwich wasn't labeled.
You could tell it was fresh, but it wasn't labeled.
so it could easily be a case of mistaken sandwich.
So I'm like, well, this gives me an out.
So I grab it, I take it back to my office or to my floor where I'm working with my team,
and nobody bats an eye.
They've just assumed that I've brought a sandwich.
So I didn't even think that they would question it.
But every time since then, whenever I've gone back, I've slowly stepped it up.
I first started not necessarily looking as carefully for, like,
like plainly wrapped sandwiches,
I'd grab like a container and start looking through.
I'd now go to the fridge that's on just like the first floor of our office space,
where most people are,
just open it up and we'll grab the first sandwich I see.
Trying and like seeing if I can get away with it each time.
And I've also tried a couple of different sandwiches that way.
And I don't think I'd ever had a bistromi on rye until I started and stole a sandwich.
And it just became a little thrill for me, which sounds crazy in some capacity.
But given the people you've interviewed, I don't think it's too far out,
but it's one of those things where I always get a little bit of a rush
because I know nobody will ever figure it out,
and nobody's going to piece it together since I'm there, maybe once a month or so.
I just think it's not evil.
Well, some would call you evil.
I guess some would.
And I think that's really going to open a lot.
separate conversation of where is the line?
These are true stories from the dark side of the internet.
I'm Jack Recyder.
This is Darknet Diaries.
This episode is sponsored by Threat Locker.
The weird part about modern cyber attacks is how normal they look.
The attacker logs in from Chrome, uses PowerShell, runs a remote admin tool your IT team already trusts.
There's no custom malware, no dramatic movie hacker moment, just no
normal tools used in the wrong way.
That's part of why Threat Locker exists.
Threat Locker helps organizations control what software can run, what it can do, and how systems
communicate.
If attackers get credentials or land on a machine, they'll have a much harder time moving
through the environment.
Because security teams are realizing something important.
Problem isn't always unknown software anymore.
Sometimes it's trusted software, being used by the wrong person.
If you want to see how ThreatLocker works, go to ThreatLocker.com.
and book a demo today.
That's Threatlocker.com slash darknet to book a demo.
This episode is sponsored by Drada.
Let's face it, if you're leading GRC at your organization,
chances are you're drowning in a sea of spreadsheets every day.
Balancing security, risk, and compliance
in an ever-changing landscape of threats and regulatory frameworks
can feel like running a never-ending marathon.
Enter Drata's agentic trust management platform designed for leaders like you.
Drada automates the tedious tasks, security questionnaires, responses, continuous evidence collection, and much more, saving you hundreds of hours each year.
With Drada, you can spend less time chasing documents and more time solving real security problems.
With Drada, you also get access to a powerful trust center, a live customizable product that supports you in expediting your never-ending security review requests in the deal process.
It's perfect for sharing your security posture with stakeholders or potential customers cutting down on the back-and-forth questions.
and building trust at every interaction.
Ready to modernize your GRC program and take back your time.
Visit drada.com slash darknet diaries to learn more.
That's drada, spelled DRATA, drata.com slash darknet diaries.
So this story is about a guy named Nicholas Sharp.
We'll call him Nick.
And no, it's not that sandwich thief you just heard.
That's a different person, entirely unrelated.
I just wanted to hear why someone would steal something from an office fridge, Nick.
The main character in this story is a guy who's big into cloud infrastructure,
which is taking care of the computers that run online services.
Nick lived in Oregon.
And one of the biggest companies in Oregon is Nike Shoes.
So he got a job there doing cloud engineering.
By 2018, he was working for Amazon Web Services out of Portland, Oregon.
The office there handles video and media solutions,
such as the encoding and live streaming of video that's handled by AWS.
About a mile away from AWS is Ubiquity.
They make routers, switches, and IP cameras,
and they wanted Nick to join their growing team of 800 employees.
Since the skills Nick picked up at AWS,
were perfectly aligned with what Ubiquity needed at the time.
So in August 2018, he quit his job at AWS
and took the job at ubiquity, moving up in his career.
Nick was 32 years old by then, and he was ambitious.
Right from the get-go, he wanted to make a job.
ubiquity more secure and more efficient and he had a lot of ideas and he wanted people to listen to him
there's some rumors about nick on some online forums some people say they worked with him at ubiquity
so take this with a grain of salts because you can't believe everything you read online but these
forum posts say nick wasn't the easiest guy to work with he had a big ego and what he would
sometimes do is find a problem and he would make a big deal about it this is a huge problem we need
to fix this right away we got to prioritize this and then he'd step in and so
solve the problem and try to act like he's taking big credit and saving the company.
Well, this tactic seemed to work.
Nick was actually crushing it at ubiquity.
Over a few years, he rose up the ranks and ended up leading the whole cloud team.
And as he gained more responsibility, he gained more access to sensitive parts of ubiquity.
He seemed to like getting access to more systems and parts of the network.
I don't think for any malicious reasons, some people just like feeling important and they want access to important things.
What we do know is that Nick was pulling in $250,000 a year to look after Ubiquities Cloud Solutions.
Even I'm impressed with that kind of pay, dang.
But after a few years, his pay rates stopped growing.
Nick stopped getting raises and promotions and started to feel underappreciated.
He thought he was hot stuff.
He felt like his skills were rare, and he wasn't feeling respected or praised or compensated enough.
Nick felt overworked, overlooked, and definitely underrated.
underpaid. Meanwhile, ubiquity sales were going crazy. They were making hundreds of millions of
dollars in profits a year. And when the pandemic hit, their stock price doubled in 2020. I guess a lot of
people were working from home and they needed internet and networking gear. And ubiquity was
ready to provide it to everyone. Nick was also working from home like most tech workers at the
time. It was a new routine to get familiar with. Still, Nick was given it as all, clocking in,
flagging security flaws, keeping systems safe for millions of customers who didn't even know his name.
Even after work hours, he was glued to the news, keeping his fingers on the pulse.
He doomed-scrolled the cybersecurity headlines.
Data breaches, unauthorized access, ransomware attacks.
They were hitting companies, left, right, and center.
And it drove Nick crazy.
All these companies!
They were thinking they're invincible, untouchable.
Well, at least the C-suite executives did.
And then, boom, they're hacked.
The security team, and guys like him have to pick up the pieces.
And the C-suite has a huge wake-up call when they realized they've been hacked
and they're not invulnerable.
Ubuquity paid Nick a six-figure salary to deliver secure products and keep things safe.
But he wondered if that was enough or if they should pay them more to keep things safe.
Nick reads on.
Carlson Wagonlit Travel Company, or CWT, got hacked in July 2020.
The hacker stole two terabytes of data.
They claimed to have personal information about employees, business files, and financial documents.
Then they infected the network with ransomware.
CWT saw the infection hit and was spreading,
and they had to take their network offline to stop the spread.
When they finally got things under control,
they realized they were in pretty bad shape.
Ransomware rendered a lot of their computers worthless,
and they didn't have a way to decrypt or fix them.
Then they got a letter.
The hackers wanted $10 million from CWT in exchange for the decryption key.
CWT was hit pretty bad,
Their backups were hit too, which meant a lot of this data was unrecoverable.
So they began negotiating with the hackers and got the ransom down to $4.5 million.
CWT paid the ransom, got the decryption key, and was able to get back up and running fairly quickly after that.
And then right after that, Garmin, the GPS company gets hit with ransomware too, this time by a hacker group called Evil Corp.
Some rumors say the hackers demanded $10 million to restore the systems.
Garmin was in bad shape.
Users couldn't use their products.
Their internal systems were down.
They were offline and unusable for days.
Rumors say they hired a cybersecurity team to help do instant response and negotiate the ransom deal.
Then, suddenly, the network came back up four days after being down.
They never said if they paid the ransom or how much.
But with everything restored so suddenly, many speculate Garmin did.
Nick wasn't exactly cash-strapped.
he was getting paid $250,000 a year.
But still, he felt like he wasn't being compensated properly.
He wondered if he should go somewhere else where they'd appreciate him more.
His big boss was Robert Pera, the CEO of Ubiquity.
At 36, Robert became one of the youngest billionaires in the world.
Nick was about the same age as him.
So while Robert's success kept growing and growing and his wealth was accumulating,
Nick felt like he had plateaued at his position.
Not frustrated him.
Some online sources say they had a beef going on.
They definitely weren't buddy-buddy.
Next thing was to make a big deal out of the security issues he found in order to look like a hero and he would fix him.
And Robert was sometimes stopping him saying, no, don't focus on that.
Instead, do this other stuff.
I know how aggravating that can be.
I've been in jobs before where I felt like I was the only one who cared about the success of the company.
And I was even told to care less about my job by my boss.
and when you're in a job like that
where you see all these problems
that you think should be priorities to fix
and people are telling you to stop caring about those,
it's incredibly frustrating.
So Nick developed a chip on his shoulder.
He just wanted to be seen, to be heard, to matter.
And he thought,
God, if ubiquity got hit with a security incident,
that would surely wake them up and they'd listen to me.
And that's when it occurred to him.
What if I can demonstrate how bad,
a hacker could hurt the company.
So he thought about it.
What would be a good way to give ubiquity a lesson, a scare?
So they'd listen to me more when I warn them of this kind of stuff.
Nick looked at everything he had access to.
He had access to the AWS cloud environment.
He had access to all the source code on GitHub.
He had access to all the Slack channels.
He had a lot of access into this billion-dollar company.
So maybe he could use this access to hit a,
in some soft, squishy part of their business to give him a wake-up call.
Nick had to be smart about this.
First things first, location.
He needed a strong Wi-Fi to hash out all the details.
A cafe? Too many cameras.
A library? Same deal.
Home?
Hmm.
No, IP addresses, leave trails.
Oh, but it's 2020 now.
And VPNs have been around forever.
So he thought, all right, step one, get a VPN.
Nick went with Surf Shark, VPN.
He got a 27-month subscription and paid with his personal PayPal.
It's as if the hoodie went over his head now.
He's taken the first steps of his plan.
Meanwhile, Nick keeps showing up to work.
He's doing all the usual stuff,
maintaining AW servers, checking vulnerabilities,
and securing the cloud.
But he has to play the part.
He has to keep up this image of a dedicated, reliable cloud expert,
a star employee.
But what they didn't know is that he was cooking up another plan.
Late at night, Nick fine-tuned every deal.
of the plan. He needed to hit ubiquity where it hurts. It wasn't just to scare them anymore,
though. He's starting to feel like he wanted payback for everything they've done to him or failed to do.
Despite him getting multiple promotions and multiple raises and making $250,000 a year,
he felt upset for not getting enough promotions, enough raises, and he wasn't feeling like the big shot he wanted to feel.
By now, it's December 2020. The festive season is in full swing,
Portland, Oregon. It's freezing outside, and Nick's dreaming of sunny California. He's been
eyeing a job over there, good weather, and it's only a nine-hour drive away. It looks good,
but there's something he needs to do here first before he leaves town. He's been working on this
job application. It's for a tech company. See, for Nick's plan to work, he had to still be
employed at ubiquity. Nick sends off this job application, and then late that same night,
actually more like early morning, around 3 a.m., Nick fires up his work laptop.
He logs into Ubiquity's cloud environment on AWS.
He doesn't use a backdoor or hack his way in.
He logs in with his normal ubiquity company credentials,
just like when he's normally working from home.
But tonight was different.
Nick was searching for something.
A key.
And not just a random key.
This one was special.
This was the key that unlocked access to all the other credentials within ubiquity systems.
Kind of like access to a part.
password vault. It was the key to the castle. Nick found the key and got into the vault,
and he starts testing things, making sure everything works, double-checking that these passwords are
correct. Then he logs out at 3.16 a.m. Two minutes later, at 3.18 a.m., someone else logs into
the AWS system. It's not from Nick's IP. It's not using Nick's credentials. The attacker's
IP address is hidden behind a VPN. Whoever it is, they were trying to cover their tracks.
This mysterious hacker had to get into the system somehow. So how'd they do it? Well, they used
the same key that Nick had just accessed. One of the things Nick complained about is that users
and passwords weren't audited enough or locked down. The principle of least privilege is something
he tried to tell them about where a user should only get access to what they need. But at
ubiquity, some keys and users had wide open access, which would give an attacker a lot of access
if they had malicious intent. So Nick decided to teach them a lesson firsthand. He was posing as an
outsider to hack into his own company in the middle of the night from the comfort of his own home.
Nick then runs a command called Git Caller Identity. It's a simple way to verify if he's the user
he thinks he is, and that's it. That's all he does. He logged in, checks the status of his account,
and then logs back out.
This at least proves to him
that he's got what he needs
to carry out something bigger
if he chooses.
And also, it's a test
to see if anyone notices.
For the next week or so,
Nick's just sitting tight,
playing it cool.
On December 21st,
Nick decides it's go time.
He's given his test run
enough time.
He's confident a quote-unquote hacker
could slip in again unnoticed.
So, after dinner,
Nick logs in to you,
Ubiquity's GitHub account.
GitHub is where Ubiquity stores their source code.
Nick is allowed access to it.
He goes through the standard login process like nothing's up.
He's got nothing to hide.
Now, GitHub is where Ubiquity keeps a lot of source code.
Details on software launches and product blueprints.
Many of these projects are public for anyone to see,
but Ubiquity also uses GitHub to host private data,
stuff not meant for the public, some of which is pretty sensitive information.
Nick starts scrolling through some of the private data
repositories. These are folders that store every change made to the source code. Nick logs out of GitHub, and a minute later, he logs back in, this time using a VPN and with a different account. He logged in using a GitHub account, which has full access to all the projects on GitHub, including all the private ones. It's a shared account, not exactly tied to Nick specifically, almost like the master password for ubiquity. Nick connects using a VPN and is in GitHub using the
shared high-level account. He connects via SSH. His IP is hidden and he feels like he can move
secretly around the files and folders now. He quickly pulls up the names of the data repositories,
the same files he had just casually scrolled through on his normal account, wasting no time,
he starts running commands to clone these top secret files. He downloads them straight to his
home computer. But he's not stopping there. He also wants the entire history of changes to these files.
Every time a ubiquity developer tweaks the source code, that change is logged.
Nick leans in.
This is the beginning of his big plan.
It started.
He's sitting behind his computer screen and he slams in another command.
Now he's cloned all the logs too.
His screen is lit up in the dark of the night and he watches file after file stream into his computer.
He's almost got it all.
He's almost got what he needs.
And just when he's on the verge of mission complete, everything stops.
The cloning stops.
Minutes pass with nothing happening.
Something went wrong.
Nick's internet went out.
Nick picks up the phone and makes a friend to call to his ISP.
This was not part of the plan.
The internet is down.
He tells the customer service rep.
He's freaking out.
Are you kidding?
This can't be happening now.
Right in the middle of his big plan.
He was so close to you.
Now remember, Nick was connected behind that Surf Shark VPN.
And there's a chance that if the VPN drops the connection,
and then somehow resumes before the VPN can come back up,
it could expose his real IP.
This worried him.
He might have botched the whole thing.
Okay, but wait, Nick is a tech guy.
He thought about that and enabled a VPN kill switch,
which means if the VPN is down, no connections will go out.
For 30 agonizing minutes, Nick is on the phone with his internet service provider.
Tonight, of all nights, after a half an hour, the red light turns green.
Nick hangs up and gets straight back into it.
He resumes his connection to GitHub and continues to clone and download all the private repositories.
But unbeknownst to Nick, his real IP did get logged.
We're not sure how.
Maybe the kill switch didn't work.
Maybe the ISP outage had something to do with it.
But GitHub's logs see two different IPs logging in with that username.
One from a VPN and one from a house in Portland, Nick's house.
Nick made sure the VPN was working, but he's nervous and frantic and his.
He isn't always thinking straight.
He continues cloning more data repositories for hours.
By 5 a.m., he's cloned and downloaded over 100 repositories.
That's gigabytes of confidential company data.
Exhausted and bleary-eyed, he calls it a night.
We're going to take a quick break here, but stay with us because when we come back, Nick makes
some really bad decisions.
This episode is sponsored by Material Security.
Your cloud office is the heart of your business, but it's still protected by a patchwork
of point solutions and manual workarounds.
Yet while other critical assets have purpose-built security,
your cloud office remains exposed.
It's time to protect this system your business relies on
with dedicated security built for cloud workspaces.
Material security is a detection and response platform.
Purpose built for protecting your Google workspace and Microsoft 365.
Siloed point solutions might stop some threats at the gate,
but leave massive gaps between tools.
Sophisticated email attacks, risky misconfigurations,
shadow IT account takeovers,
Material not only monitors everything continuously,
it applies fixes and steps in
to make sure information only flows where it's supposed to go.
So if you're ready to stop trying to fill the gaps
and start getting ahead of threats,
check out Material Security.
Learn more at their website, material.security.
The website is material.com security.
The next day, Nick now has a crazy amount of company data
sitting on his personal computer,
data that he has full legit access to for work,
but isn't supposed to be downloading it to his personal home computer?
You'd think he'd have some great idea for what to do next.
But he seems a little lost.
He messages a colleague,
and he wants to know whether someone like him,
a ubiquity employee, could cash in on the company's bug bounty program.
This program, run by a hacker one,
rewards people for finding vulnerabilities.
It essentially outsources company's security
to the hacker community, ethical hacking.
Nick asks his colleague,
Hey, can I, as an employee, get paid if I discover some security issue?
Nick's colleague writes back and tells him,
well, not exactly.
Eubiquity only pays people for reporting found credentials.
He finds Nick's message suspicious, though.
Did Nick find something, and he's not saying something about it?
He saves the message just in case.
Still, apart from one suspicious colleague,
no one else notices anything.
No one reports any stolen data.
And Nick is feeling pretty validated.
Case in point, right?
See, if someone broke in and downloaded all the source code,
nobody would even know.
He thought Ubikuti's security was a total joke.
And Nick has just nailed the first step to prove it.
But he's got a problem.
He hasn't fully covered his tracks.
Or maybe he was just winging this whole thing after all.
Nick logs back into AWS.
He changes the lifecycle retention policies to just one day.
This will delete the logs.
So while he was poking around downloading things,
that all should be deleted by now.
And Nick has a good point.
He shouldn't have all this access to all the company's products, the source code,
root access to the whole AWS environment.
Data should be segmented.
And only the people who need access should have access.
If he was working on one of the products software, that's what he should have access to,
just that product source code.
And he just thinks, man, if a hacker were to get all these credentials,
we'd have a big problem just like CWT or Garmin.
This level of access that he has shouldn't have been allowed.
Plus, everything that gets accessed should be tracked, logged, and secured.
If an unauthorized user logged in, the security team should immediately be alerted.
If unauthorized downloads happen, that should trip some alarm.
But nothing.
Nobody noticed him downloading or accessing any of this data.
He logs into AWS and he starts renaming sessions.
He renames 18 sessions like his own session, the ones he started from the VPN,
and he renames these sessions to make it look like they belong to the DevOps colleagues.
I'm not sure if he's trying to throw his coworkers under the bus or if he's just trying to hide his tracks.
And he does this just in the nick of time because then, boom, ubiquity drops, a company-wide announcement.
A couple of employees spotted strange activity on the systems.
Somebody has been poking around where they shouldn't have and data has been exfiltated.
Immediately, ubiquity sets up an internal team like an incident response task force.
They need their best people on this fast.
And guess who they call in to help investigate?
Nicholas Sharp himself, the guy who loves being a hero.
Nick swings in action.
He's playing the part of a tireless investigator,
clocking in long hours, combing two logs.
But he's just dead weight.
He's drumming up pointless work
and adding no value at all to the investigation.
As the investigation heats up,
some people zero in on the VPN used in the attack.
Nick plays it cool.
Surf Shark VPN, you say?
I've never used that.
He insists.
Denied.
divert, distract, that's all he can do.
The new year rolls around.
Nick is still in fake investigator mode.
That is, until one morning, at the ungodly hour of 4 a.m.,
a few senior employees at Ubiquity are awoken.
Their phone screens light up.
An email has come in, and it's a ransom note.
It's from an anonymous hacker claiming responsibility for the attack.
The hacker has given ubiquity an ultimatum,
Either cough up, 25 Bitcoin or your stolen data will be published online.
Now, at the time, 25 Bitcoin is worth about $2 million.
That was Nick's grand plan.
Extort his own company for money.
He thought this will both fix the security problems he sees,
but also pay him properly for the security problems he's discovered.
There's more to this ransom note.
Nick has tossed in an extra tidbit.
He needed to make it more convincing that an outsider was behind this.
So, to sweeten the deal, the hacker will share.
a secret. He's found a hidden back door to Ubiquity systems, and if they want to know what it is,
pay another 25 Bitcoin. The deadline was set. Midnight, January 9th, 2021, pay the ransom,
or watch the data go public. At this point, Ubiquity had a market cap of over $23 billion.
Sure, paying a $1.9 million ransom would sting, but in the grand scheme of things, it's hardly
catastrophic. They could take the hit and move on. At this point, the senior leadership is notified,
and are debating what to do.
CWT paid the ransom.
Garmin might have paid the ransom.
But that's because this had ransomware installed on their key systems
and their business came to a total halt.
There was no ransomware on ubiquity systems,
just someone threatening to publish the private source code to the company.
While they were debating what to do,
another senior employee gets a message on Keybase?
Keybase is a chat app,
and it just seems a little too personal
for random senior employee to get a direct message from the hacker.
Nick himself was active on Keybase,
and he had connections with other friends and employees on there too.
But for a hacker to message a senior employee on there,
it just seems a little odd,
almost like a random employee was getting a text message from the hacker.
Why this employee?
Why choose Keybase to reach out?
And how did they know this Keybase username?
You know, the employee decrypts the message and reads it.
It's a copy of the ransom email.
There's also an attachment.
It contains proof of the stolen data.
Source code, company secrets, unreleased products, all of it.
By now, all hell is breaking loose in the company.
Crisis teams have been called in, select stakeholders looped in,
and law enforcement is on the case.
It's stressful, not just for the leadership of ubiquity,
but for many employees who were there to clean up the mess,
especially over the holiday season.
Some reports say that people were quitting over this.
Leadership was still debating.
Pay the ransom or not pay the ransom.
him. Ubikwity was taking this threat seriously.
Meanwhile, Nick was waiting and waiting, waiting.
He wants a response, and sometimes he even checks his Bitcoin wallet to see if anything's
been deposited yet.
He watches the clock as the midnight deadline draws closer.
Ubiquity seemed to ignore his threats.
The deadline arrived and no message came.
No Bitcoin came.
He has a bad feeling about this.
He realizes.
he's not getting the money.
So he decides to amp up the stress.
He gets back on Keybase to message that same employee.
No BTC, he types out.
No talk.
We done here.
Nick uploads the stolen data to a public Keybase folder.
He shows the public folder to the senior employee on Keybase.
He's exposed it all to the public.
Mission complete, right?
Wrong.
Nick's no longer feeling confident.
He's second-guessing every move.
What if Keybase isn't?
secure, he thought. He jumps online and Googles. Can Keybase data be subpoenaed? But it's too late to
turn back now. Ubiquity has sprung into action. They contact Keybase, and just like that,
Keybase removes all the data that Nick uploaded. Now Nick has nothing to work with. He was
counting on Keybase. He thought they would never fold to a takedown request. It's just like what
Teddy Lewis says in body heat. There's 50 ways you can screw up a crime, and a genius can only think of
25. Things were getting worse for Nick.
the federal authorities were involved.
His extortion scheme has failed.
He's furious at ubiquity, at himself.
He blew it.
Now, all he can do is wait.
For what?
An arrest?
Perhaps.
But first, he needs ubiquity to show its true colors.
Just one more time.
And just like that, they do.
Ubiquity leadership thought there's a high chance that this anonymous hacker
will release this company data.
And they wanted to be ahead of that news to let their users know first.
So they sent out an email to the users,
We recently became aware of unauthorized access to certain information technology systems
hosted by a third-party cloud provider.
We have no indication that there has been unauthorized activity with respect to any user's accounts.
But the language was concerning to customers or started to worry that their home address and passwords were leaked and in the hacker's hands.
They relied on ubiquity's equipment to be safe and secure, and now are unsure exactly how safe it is.
Nick's fuming.
This messaging, he felt, was sweeping the issue under the rug.
It wasn't honest with the customers and had confusing language.
The way it's written, you could think that a third-party provider was part of the problem.
This news was a PR problem, but not a PR disaster yet.
Nick could use all this to his advantage.
He knows the customers are angry.
He knows ubiquity is lying about what happened.
He knows they have very little logs since he destroyed them.
But before he gets too excited, Nick finds out that he's...
in trouble. Big trouble. His home IP address was found in the investigation. Nixon, the hot seat.
The FBI is looking at this evidence. It's just a matter of time before they asked the ISP,
which customer had that IP that day? And ubiquity wants answers. They just hired a forensics
team. Nick is a suspect now. Since his IP is also the IP he's been connected to from work and
the IPs match, Nick is ordered to hand over everything.
His company provide a router, video cameras, and his computer.
So he hands it over, and the forensics team is all over his stuff.
They start with a video camera and go through hours of footage.
Nothing there.
They go through his computer, dissecting it bit by bit.
Deleted files are pulled back up, and hard drives are pulled apart, and they find nothing.
That's because his hack was from a different computer, not the company laptop.
But when forensics start on Nick's home router, they notice something suspicious going on.
During the hours of the cyber attack, there was a separate device transferring massive amounts of data about the same volume that was stolen.
Turns out, a MacBook laptop was used to connect to the router, a separate device from the one Nick handed over.
So while he used a different device and a VPN, forensics can still see some stuff.
When his laptop connects to the Wi-Fi router, that's a layer two connection of the OSI model, Mac addresses.
A VPN works on layer three, IP addresses.
so they can see which Mac address connected to that ubiquity router,
and it was a MacBook.
Then when it comes to VPN traffic,
while you can't see what's in that data,
you can see how much data is passing through and which direction.
So they were able to see a large amount of data
downloaded the same night.
Someone took it all from GitHub.
The second laptop was a game changer.
If the FBI could get their hands on it,
they'd have a clear link to the crime.
But not so fast.
They needed a search warrant, and those things take time.
Nick does what every guy with Secrets would do.
He wipes and resets his personal MacBook,
the one that hasn't been confiscated yet.
He keeps a laptop in his house.
It tries to think of what other evidence they might have on him.
Months, pass, and Nick is keeping a low profile and staying out of trouble.
But then on March 24, 2021, the FBI pull up to his house in Portland.
Search warrant in hand.
They bang on the door, calling his name.
Nick has no choice.
He has to let them in.
So it does. He watches as his house gets turned upside down.
Agents are everywhere rummaging through drawers, tossing stuff in evidence bags, including his MacBook.
They also want answers. The agents grill Nick about his involvement. He denies everything.
They hit him with cold hard proof.
We have evidence you purchased a Surf Shark VPN back in July 2020 when agent tells him.
Nick knew they knew this. He had time to come up with an excuse or a confession, but this is a
is what he goes with. He pulls the victim card. He tells the FBI, I'm being framed. Someone must
have used my PayPal account. He's lying and they're not stupid. But they wrap up their questioning.
They take their evidence and get out of there. Nick was dangerously close to being arrested,
but the FBI just came to collect things and didn't apprehend him yet. He has to use his time wisely.
So what does he do? Does he cover his tracks? Does he hire a lawyer, work on his defense,
flee the country, or make a final attempt to clear his name?
Nope.
Nick jumps online and reaches out to Brian Krebs.
Brian Krebs is a journalist who runs a site called crebsonsecurity.com.
He's well known in the cybersecurity world and reports on profit-driven cybercriminals.
He's the perfect guy for Nick's story.
Not because Nick wanted to out himself as a profit-driven cybercriminal.
Nope.
He wanted to expose ubiquity as a lying corporation putting profits over security.
So Nick types up his email, keeping it anonymous.
He's posting as a whistleblower with an inside scoop about the recent Ubiquity reach.
Brian Krebs replies almost immediately, tell me more.
Nick tells Brian that Ubiquity seriously downplayed what happened.
They lied to their customers big time to save their stock price.
Here's what really happened, Nick wrote.
Hackers got rude access to Ubiquity.
They got into the AWS servers because Ubiquity stores logins in a last-pass account.
How irresponsible!
And he's not wrong.
Ubiquity did lie in their public statements.
They framed it as a third-party issue
rather than admitting that all their company data
had just been stolen and used to demand ransom.
Which one is better?
A third-party breach or an inside job.
On top of that, Nick said that ubiquity doesn't keep logs.
So, of course, there was no evidence of customer data accessed.
The allegations seemed legit enough.
So Brian Krebs ran with the story.
The article goes live with the headline, Whistleblower.
Ubuy breach, catastrophic.
The news hit hard and fast.
Customers were pissed off all over again.
They feel completely violated, knowing a hacker could have gotten into their stuff.
This set off a chain reaction.
Investors catch wind of the fallout and start selling their shares.
Not just a couple, but a whole lot of them.
In just two days, ubiquity stock crashes by 20%.
That's $4 billion in market capitalization.
Hoof, gone, practically overnight.
What was a PR?
has now turned into a PR disaster for ubiquity, but not for Nick.
He's gotten his revenge. He's pulled it off. He's still a free man for now.
And he couldn't stop now. Why quit while he's ahead? Watching ubiquity's downfall was just too sweet.
Nick then contacts a bunch of regulators, both home and abroad. He tells them all about ubiquity's
misleading disclosures, how they lied. Perhaps they should take a closer look at what's going on there.
But all good things come to an end in December 2021.
the feds finally made their move.
Nicholas Sharp was arrested on a four-count indictment.
The serious charge being wire fraud.
This could land him 20 years in prison.
Nick hires lawyers and gets a defense prepared.
In February 2023, he pleads guilty to three counts,
intentionally damaging protected computers, wire fraud,
and making false statements to the FBI.
Nick admits that it was all planned for financial gain.
But then he has a change of heart,
or maybe his lawyers come up with a new strategy.
In his pre-sentencing, Nick insists it wasn't about the money.
He pleads with the judge.
Please, no prison time.
The whole thing was just an unsanctioned security drill to make ubiquity a safer place.
I wanted ubiquity to finally pay attention to its ongoing security issues.
I got carried away, sure, but I had really good intentions.
Yeah, well, security drill or not, the judge sentenced Nick to six years in prison.
And that's where he remains today.
This episode was created by me, Mr. Glitchie Pants, Jack Recyter.
This episode was researched and written by Clippy's Revenge, Laura Woods.
Our editor is the Wi-Fi whisperer, Tristan Ledger, sound designed by the Ping King, Andrew Meriwether.
Mixing done by proximity sound and our intro music is by the mysterious brickmaster cylinder.
Why don't aliens visit Earth?
They can't figure out the R-U-human captas.
This is Darknet Diaries.
