ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

California man pleads guilty in AI tool scam that led to major Disney data breach

Linked InXFacebook
bookmark_borderSave to Library

A 25-year-old California man has pleaded guilty to federal cybercrime charges after orchestrating a sophisticated hacking scheme that exploited artificial intelligence software to infiltrate The Walt Disney Company’s internal systems, leading to the theft of over one terabyte of sensitive information.


According to the U.S. Attorney’s Office for the Central District of California, Ryan Mitchell Kramer of Santa Clarita admitted to developing and distributing a fake version of ComfyUI, a popular open-source AI image generator. Branded as “ComfyUI_LLMVISION,” the counterfeit software was embedded with malware capable of extracting passwords, financial information, and confidential files. Kramer hosted the infected tool on GitHub under the online alias NullBulge, presenting it as an enhancement for AI-generated artwork.


Once installed, the software covertly transmitted stolen data to a Discord server operated by Kramer. Investigators determined that he disguised files with names referencing legitimate AI firms, including OpenAI and Anthropic, in an apparent attempt to mislead users.


In April 2024, a Disney employee unknowingly downloaded the malware, enabling Kramer to gain access to the company’s Slack channels and internal network. He subsequently stole approximately 1.1 terabytes of data, including proprietary content, source code, and employee personal records. Months later, Kramer impersonated a hacktivist group member and contacted the employee. After receiving no response, he publicly leaked the data, which contained the employee’s financial and medical records.


Prosecutors say Kramer also admitted to compromising at least two additional victims through the same malware. Following the breach, Disney reportedly terminated the employee involved and ceased using Slack for internal communication. The former employee has filed a wrongful termination complaint.


Kramer has pleaded guilty to one count each of accessing a protected computer to obtain information and threatening to damage a protected computer. Each charge carries a potential prison sentence of up to five years. The FBI’s investigation into the incident remains ongoing.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543