ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

IT employee found guilty of impersonating ransomware gang to extort employer

A 28-year-old man from Fleetwood, Hertfordshire, in the United Kingdom, has been convicted of unauthorized computer access with criminal intent and blackmailing his employer. The South East Regional Organised Crime Unit (SEROCU) issued a press release on Monday, shedding light on the case that unfolded in February 2018.

 

The convicted man, Ashley Liles, was employed as an IT Security Analyst at an Oxford-based company that fell victim to a ransomware attack. In typical fashion, the threat actors behind the ransomware attack contacted the company’s executives, demanding a ransom payment. Due to his role in the organization, Liles actively participated in the internal investigations and incident response procedures with the support of fellow employees and law enforcement.

 

However, it has been alleged that during this phase, Liles sought personal gain by deceiving his employer into paying him a ransom instead of the original external attacker. According to the SEROCU statement, unbeknownst to the police, his colleagues, and his employer, Liles initiated a separate and secondary attack against the company. He reportedly accessed a board member’s private emails on over 300 occasions and tampered with the original blackmail email, modifying the payment address provided by the initial attacker.

 

Liles planned to capitalize on the situation and divert the payment to a cryptocurrency wallet under his control. To further manipulate the circumstances, he created an email address that closely resembled the original attacker’s and began pressuring his employer to make the payment, as per SEROCU.

 

However, the company refused to acquiesce to the attackers’ demands. The ongoing internal investigations ultimately exposed Liles’ unauthorized access to private emails, leading them to trace the activity to his home’s IP address.

 

Although Liles, realizing he was under scrutiny, had wiped all data from his devices when SEROCU’s cyber-crime team searched his home to seize his computer, incriminating evidence was still recoverable.

Initially, Liles vehemently denied any involvement. However, five years later, during a hearing at Reading Crown Court, he pleaded guilty to the charges brought against him.

 

The rogue employee is scheduled to appear in court on July 11th, 2023, where he will receive his sentence. Under UK law, unauthorized computer access can carry a maximum penalty of up to 2 years in prison, while the offense of blackmail is punishable by a maximum imprisonment sentence of 14 years.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543