ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Former Ubiquiti employee jailed for six years for stealing company data

A former Ubiquiti employee who stole several gigabytes of corporate data from the company’s network has been sentenced to prison for six years.In January 2021, IoT and cloud-enabled networked devices maker Ubiquiti suffered a cyber security incident that involved a threat actor obtaining unauthorised access to certain information technology systems hosted by a third-party cloud provider.A Ubiquiti employee told KrebsOnSecurity that hackers gained full access to Ubiquiti databases hosted by Amazon Web Services (AWS). “Ubiquiti’s breach disclosure was “downplayed and purposefully written to imply that a 3rd party cloud vendor was at risk and that Ubiquiti was merely a casualty of that, instead of the target of the attack,” he added.Nickolas Sharp, a former employee of the company was found responsible for the security incident and was arrested in December 2021 for using his senior developer credentials to steal sensitive company information. Sharp also sent an anonymous email asking Ubiquiti to pay 50 bitcoins (about $2 million at the time) as ransom in exchange for the stolen information.“SHARP repeatedly misused his administrative access to download gigabytes of confidential data from his employer,” the U.S. Department of Justice said. Sharp also created false stories about the security incident and the company’s response in dealing with the same.“SHARP identified himself as an anonymous whistleblower within Company-1 who had worked on remediating the Incident and falsely claimed that Company-1 had been hacked by an unidentified perpetrator who maliciously acquired root administrator access to Company-1’s AWS accounts.“In fact, as SHARP well knew, SHARP himself had taken Company-1’s data using credentials to which he had access, and SHARP had used that data in a failed attempt to extort Company-1 for millions of dollars,” DoJ added.In February, Sharp pleaded guilty to “transmitting a program to a protected computer that intentionally caused damage,” “wire fraud” and “making false statements to the FBI”.The Southern District Court of New York has sentenced Sharp to six years in prison, and three years of supervised release, and ordered him to pay $1,590,487 as restitution.In a statement, US Attorney Damian Williams said, “Nickolas Sharp was paid close to a quarter million dollars a year to help keep his employer safe.“He abused that trust by stealing a massive amount of sensitive data, attempting to implicate innocent employees in his attack, extorting his employer for ransom, obstructing law enforcement, and spreading false news stories that harmed the company and anyone who invested in the company.“Sharp now faces serious penalties for his callous crimes,” Williams added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543