
Show notes
Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. What do you do when the company you work for isn't securing their software up to your standards? Well, he thought he needed to teach them a lesson, but in the end, he learned an even bigger lesson.
Highlighted moments
But unbeknownst to Nick, his real IP did get logged. We're not sure how. Maybe the kill switch didn't work. Maybe the ISP outage had something to do with it. But GitHub's logs see two different IPs logging in with that username. One from a VPN and one from a house in Portland. Nick's house.
“when forensics start on Nick's home router they notice something suspicious going on. During the hours of the cyber attack there was a separate device transferring massive amounts of data about the same volume that was stolen.”
“He renames 18 sessions like his own session, the ones he started from the VPN, and he renames these sessions to make it look like they belong to the DevOps colleagues. I'm not sure if he's trying to throw his coworkers under the bus, or if he's just trying to hide his tracks.”
Transcript
Introduction
0:00I'm just going to get right into it.
0:04I don't even want to ask your name because I don't even want to know who's doing this. But some of the first time you did this. I started a new job a couple of months back. And it's entirely remote work from home, except for the occasional trip to the office. There are maybe eight people in the company who work at the main office that would recognize me at any given point. So I saw an opportunity and decided to run with it. I was going to try something I'd never done before and steal food. This is a famous office thing. I'm a university student at the same time as being a full-time employee.
0:38So I wanted to, like, everyone talks about this as a thing. And the office might as well become a member of the professional world.
Stealing Food
0:46And so I just took a sandwich. To where? Just from the office fridge. We have three refrigerators. It's a little two-story office. So I just went upstairs to a floor where my team would never be on. And took a sandwich. Now, so you open the fridge to see what's in there. You're hungry. Like, that was the whole goal is to find something to eat out of there. And do you see, like, an old container and some spoiled milk and sandwich and decide, okay, the sandwich is the best thing? Or what goes through your mind on picking it?
1:16It was a couple of different things. But I thought, what's the most inconspicuous thing? Because the sandwich wasn't labeled. You could tell it was fresh, but it wasn't labeled. So it could easily be a case of mistaken sandwich. So I'm like, well, this gives me an out. So I grab it. I take it back to my office or to my floor where I'm working with my team. And nobody bats an eye. They've just assumed that I've brought a sandwich. So I didn't even think that they would question it.
1:48But every time since then, whenever I've gone back, I've slowly stepped it up. I first started, like, not necessarily looking as carefully for, like, plainly wrapped sandwiches. I'd grab, like, a container and start looking through. I now go to the fridge that's on just, like, the first floor of our office space, where most people are. Just open it up and we'll grab the first sandwich I see. Trying and, like, seeing if I can get away with it each time. And I've also tried a couple of different sandwiches that way. And I don't think I'd ever had a pastrami on rye.
2:22Until I started and stole a sandwich.
2:25And it just became a little thrill for me, which sounds crazy in some capacity. But given the people you've interviewed, I don't think it's too far out. But it's one of those things where I always get a little bit of a rush. Because I know nobody will ever figure it out. And nobody's going to piece it together since I'm there maybe once a month or so. I just, I think it's not evil. Well, some would call you evil. I guess some would. And I think that's really going to open a separate conversation of where is the line.
Darknet Diaries Introduction
3:01These are true stories from the dark side of the internet.
3:08I'm Jack Recider. This is Darknet Diaries. This episode is sponsored by ThreatLocker. The weird part about modern cyber attacks is how normal they look. The attacker logs in from Chrome, uses PowerShell, runs a remote admin tool your IT team already trusts.
3:42There's no custom malware, no dramatic movie hacker moment, just normal tools used in the wrong way. That's part of why ThreatLocker exists. ThreatLocker helps organizations control what software can run, what it can do, and how systems communicate. If attackers get credentials or land on a machine, they'll have a much harder time moving through the environment. Because security teams are realizing something important. The problem isn't always unknown software anymore. Sometimes it's trusted software being used by the wrong person.
4:12If you want to see how ThreatLocker works, go to ThreatLocker.com slash Darknet and book a demo today. That's ThreatLocker.com slash Darknet to book a demo. This episode is sponsored by Drada. Let's face it, if you're leading GRC at your organization, chances are you're drowning in a sea of spreadsheets every day. Balancing security, risk, and compliance in an ever-changing landscape of threats and regulatory frameworks can feel like running a never-ending marathon.
4:45Enter Drada's agentic trust management platform designed for leaders like you. Drada automates the tedious tasks, security questionnaires, responses, continuous evidence collection, and much more, saving you hundreds of hours each year. With Drada, you can spend less time chasing documents and more time solving real security problems. With Drada, you also get access to a powerful trust center, a live, customizable product that supports you in expediting your never-ending security review requests in the deal process. It's perfect for sharing your security posture with stakeholders or potential customers, cutting down on the back-and-forth questions, and building trust at every interaction.
5:21Ready to modernize your GRC program and take back your time? Visit Drada.com slash Darknet Diaries to learn more. That's Drada, spelled D-R-A-T-A. Drada.com slash Darknet Diaries.
Nicholas Sharp Story
5:35So, this story is about a guy named Nicholas Sharp. We'll call him Nick. And no, it's not that sandwich thief you just heard. That's a different person, entirely unrelated. I just wanted to hear why someone would steal something from an office fridge. Nick. The main character in this story is a guy who's big into cloud infrastructure, which is taking care of the computers that run online services. Nick lived in Oregon. And one of the biggest companies in Oregon is Nike Shoes. So, he got a job there, doing cloud engineering.
6:07By 2018, he was working for Amazon Web Services out of Portland, Oregon. The office there handles video and media solutions, such as the encoding and live streaming of video that's handled by AWS. About a mile away from AWS is Ubiquity. They make routers, switches, and IP cameras. And they wanted Nick to join their growing team of 800 employees, since the skills Nick picked up at AWS were perfectly aligned with what Ubiquity needed at the time. So, in August 2018, he quit his job at AWS and took the job at Ubiquity, moving up in his career.
6:44Nick was 32 years old by then, and he was ambitious right from the get-go. He wanted to make Ubiquity more secure and more efficient. And he had a lot of ideas, and he wanted people to listen to him. There's some rumors about Nick on some online forums. Some people say they worked with him at Ubiquity. So, take this with a grain of salt, because you can't believe everything you read online. But these forum posts say Nick wasn't the easiest guy to work with. He had a big ego. And what he would sometimes do is find a problem, and he would make a big deal about it. This is a huge problem. We need to fix this right away.
7:14We got to prioritize this. And then he'd step in and solve the problem and try to act like he's taking big credit and saving the company. Well, this tactic seemed to work. Nick was actually crushing it at Ubiquity. Over a few years, he rose up the ranks and ended up leading the whole cloud team. And as he gained more responsibility, he gained more access to sensitive parts of Ubiquity. He seemed to like getting access to more systems and parts of the network. I don't think for any malicious reasons, some people just like feeling important,
7:45and they want access to important things. What we do know is that Nick was pulling in $250,000 a year to look after Ubiquity's cloud solutions. Even I'm impressed with that kind of pay. Dang. But after a few years, his pay rates stopped growing. Nick stopped getting raises and promotions and started to feel underappreciated. He thought he was hot stuff. He felt like his skills were rare, and he wasn't feeling respected or praised or compensated enough. Nick felt overworked, overlooked, and definitely underpaid.
8:18Meanwhile, Ubiquity's sales were going crazy. They were making hundreds of millions of dollars in profits a year. And when the pandemic hit, their stock price doubled in 2020. I guess a lot of people were working from home, and they needed internet and networking gear. And Ubiquity was ready to provide it to everyone. Nick was also working from home, like most tech workers at the time. It was a new routine to get familiar with. Still, Nick was giving it his all, clocking in, flagging security flaws, keeping systems safe for millions of customers who didn't even know his name. Even after work hours, he was glued to the news, keeping his fingers on the pulse.
8:50He doom-scrolled the cybersecurity headlines. Data breaches, unauthorized access, ransomware attacks. They were hitting companies left, right, and center. And it drove Nick crazy. All these companies, they were thinking they're invincible, untouchable. Well, at least the C-suite executives did. And then, boom, they're hacked. The security team and guys like him have to pick up the pieces, and the C-suite has a huge wake-up call when they realize they've been hacked and they're not invulnerable. But Ubiquiti paid Nick a six-figure salary to deliver secure products and keep things safe.
9:23But he wondered if that was enough or if they should pay him more to keep things safe. Nick reads on, Carlson Wagon Lit Travel Company, or CWT, got hacked in July 2020. The hacker stole two terabytes of data. They claimed to have personal information about employees, business files, and financial documents. Then they infected the network with ransomware. CWT saw the infection hit and was spreading, and they had to take their network offline to stop the spread.
9:54When they finally got things under control, they realized they were in pretty bad shape. Ransomware rendered a lot of their computers worthless, and they didn't have a way to decrypt or fix them. Then they got a letter. The hackers wanted $10 million from CWT in exchange for the decryption key. CWT was hit pretty bad. Their backups were hit too, which meant a lot of this data was unrecoverable. So they began negotiating with the hackers and got the ransom down to $4.5 million.
10:25CWT paid the ransom, got the decryption key, and was able to get back up and running fairly quickly after that. And then right after that, Garmin, the GPS company, gets hit with ransomware too, this time by a hacker group called Evil Corp. Some rumors say the hackers demanded $10 million to restore the systems. Garmin was in bad shape. Users couldn't use their products. Their internal systems were down. They were offline and unusable for days. Rumors say they hired a cybersecurity team to help do incident response and negotiate the ransom deal.
10:57Then, suddenly, the network came back up four days after being down. They never said if they paid the ransom or how much. But with everything restored so suddenly, many speculate Garmin did. Nick wasn't exactly cash-strapped. He was getting paid $250,000 a year. But still, he felt like he wasn't being compensated properly. He wondered if he should go somewhere else where they'd appreciate him more. His big boss was Robert Perra, the CEO of Ubiquity. At 36, Robert became one of the youngest billionaires in the world.
11:30Nick was about the same age as him. So, while Robert's success kept growing and growing and his wealth was accumulating, Nick felt like he had plateaued at his position. And that frustrated him. Some online sources say they had a beef going on. They definitely weren't buddy-buddy. Nick's thing was to make a big deal out of the security issues he found in order to look like a hero when he would fix them. And Robert was sometimes stopping him, saying, No, don't focus on that. Instead, do this other stuff. I know how aggravating that can be. I've been in jobs before where I felt like I was the only one who cared about the success of the company.
12:04And I was even told to care less about my job by my boss. And when you're in a job like that, where you see all these problems that you think should be priorities to fix, and people are telling you to stop caring about those, it's incredibly frustrating. So Nick developed a chip on his shoulder. He just wanted to be seen, to be heard, to matter. And he thought, God, if Ubiquity got hit with a security incident, that would surely wake them up and they'd listen to me. And that's when it occurred to him,
12:36What if I can demonstrate how bad a hacker could hurt the company? So he thought about it. What would be a good way to give Ubiquity a lesson? A scare? So they'd listen to me more when I warned them of this kind of stuff. Nick looked at everything he had access to. He had access to the AWS cloud environment. He had access to all the source code on GitHub. He had access to all the Slack channels. He had a lot of access into this billion-dollar company. So maybe he could use this access to hit them
13:08in some soft, squishy part of their business to give them a wake-up call. Nick had to be smart about this. First things first, location. He needed a strong Wi-Fi to hash out all the details. A cafe? Too many cameras. A library? Same deal. Home? Hmm. No, IP addresses leave trails. Oh, but it's 2020 now, and VPNs have been around forever. So he thought, all right, step one, get a VPN. Nick went with Surfshark VPN.
13:39He got a 27-month subscription and paid with his personal PayPal. It's as if the hoodie went over his head now. He's taking the first steps of his plan. Meanwhile, Nick keeps showing up to work. He's doing all the usual stuff, maintaining AWS servers, checking vulnerabilities, and securing the cloud. But he has to play the part. He has to keep up this image of a dedicated, reliable cloud expert, a star employee. But what they didn't know is that he was cooking up another plan. Late at night, Nick fine-tuned every detail of the plan.
14:10He needed to hit Ubiquity where it hurts. It wasn't just to scare them anymore, though. He's starting to feel like he wanted payback for everything they've done to him or failed to do. Despite him getting multiple promotions and multiple raises and making $250,000 a year, he felt upset for not getting enough promotions, enough raises, and he wasn't feeling like the big shot he wanted to feel. By now, it's December 2020. The festive season is in full swing in Portland, Oregon. It's freezing outside,
14:41and Nick's dreaming of sunny California. He's been eyeing a job over there. Good weather, and it's only a nine-hour drive away. It looks good, but there's something he needs to do here first before he leaves town. He's been working on this job application. It's for a tech company. See, for Nick's plan to work, he had to still be employed at Ubiquity. Nick sends off this job application, and then late that same night, or actually more like early morning, around 3 a.m.,
15:11Nick fires up his work laptop. He logs into Ubiquity's cloud environment on AWS. He doesn't use a backdoor or hack his way in. He logs in with his normal Ubiquity company credentials, just like when he's normally working from home. But tonight was different. Nick was searching for something. A key. And not just a random key. This one was special. This was the key that unlocked access to all the other credentials within Ubiquity's systems. Kind of like access to a password vault. It was the key to the castle.
15:42Nick found the key and got into the vault, and he starts testing things, making sure everything works, double-checking that these passwords are correct. Then, he logs out at 3.16 a.m. Two minutes later, at 3.18 a.m., someone else logs into the AWS system. It's not from Nick's IP. It's not using Nick's credentials. The attacker's IP address is hidden behind a VPN. Whoever it is, they were trying to cover their tracks. This mysterious hacker had to get into the system somehow.
16:15So how'd they do it? Well, they used the same key that Nick had just accessed. One of the things Nick complained about is that users and passwords weren't audited enough or locked down. The principle of least privilege is something he tried to tell them about, where a user should only get access to what they need. But at Ubiquity, some keys and users had wide-open access, which would give an attacker a lot of access if they had malicious intent. So Nick decided to teach them a lesson firsthand. He was posing as an outsider to hack into his own company
16:47in the middle of the night from the comfort of his own home. Nick then runs a command called git caller identity. It's a simple way to verify if he's the user he thinks he is, and that's it. That's all he does. He logged in, checks the status of his account, and logs back out. This at least proves to him that he's got what he needs to carry out something bigger if he chooses. And also, it's a test to see if anyone notices. For the next week or so, Nick's just sitting tight, playing it cool.
17:17On December 21st, Nick decides it's go time. He's given his test run enough time. He's confident a quote-unquote hacker could slip in again unnoticed. So, after dinner, Nick logs into Ubiquity's GitHub account. GitHub is where Ubiquity stores their source code. Nick is allowed access to it. He goes through the standard login process like nothing's up. He's got nothing to hide. Now, GitHub is where Ubiquity keeps a lot of source code. Details on software launches and product blueprints.
17:48Many of these projects are public for anyone to see, but Ubiquity also uses GitHub to host private data. Stuff not meant for the public. Some of which is pretty sensitive information. Nick starts scrolling through some of the private data repositories. These are folders that store every change made to the source code. Nick logs out of GitHub. And a minute later, he logs back in. This time, using a VPN and with a different account. He logged in using a GitHub account, which has full access to all the projects on GitHub,
18:19including all the private ones. It's a shared account, not exactly tied to Nick specifically, almost like the master password for Ubiquity. Nick connects using a VPN and is in GitHub using this shared high-level account. He connects via SSH. His IP is hidden, and he feels like he can move secretly around the files and folders now. He quickly pulls up the names of the data repositories, the same files he had just casually scrolled through on his normal account. Wasting no time, he starts running commands to clone these top-secret files.
18:53He downloads them straight to his home computer. But he's not stopping there. He also wants the entire history of changes to these files. Every time a Ubiquity developer tweaks the source code, that change is logged. Nick leans in. This is the beginning of his big plan. It started. He's sitting behind his computer screen, and he slams in another command. Now he's cloned all the logs, too. His screen is lit up in the dark of the night, and he watches file after file stream into his computer. He's almost got it all. He's almost got what he needs.
19:24And just when he's on the verge of mission complete, everything stops. The cloning stops. Minutes pass with nothing happening. Something went wrong. Nick's internet went out. Nick picks up the phone and makes a frantic call to his ISP. Hey, this was not part of the plan. The internet is down, he tells the customer service rep. He's freaking out. Are you kidding? This can't be happening now. Right in the middle of his big plan. He was so close, too.
19:55Now remember, Nick was connected behind that Surfshark VPN. And there's a chance that if the VPN drops the connection, and then somehow resumes before the VPN can come back up, it could expose his real IP. This worried him. He might have botched the whole thing. Okay, but wait. Nick is a tech guy. He thought about that and enabled a VPN kill switch, which means if the VPN is down, no connections will go out. For 30 agonizing minutes, Nick is on the phone with his internet service provider. Tonight of all nights,
20:25after a half an hour, the red light turns green. Nick hangs up and gets straight back into it. He resumes his connection to GitHub and continues to clone and download all the private repositories. But unbeknownst to Nick, his real IP did get logged. We're not sure how. Maybe the kill switch didn't work. Maybe the ISP outage had something to do with it. But GitHub's logs see two different IPs logging in with that username. One from a VPN and one from a house in Portland. Nick's house.
20:56Nick made sure the VPN was working. But he's nervous and frantic and isn't always thinking straight. He continues cloning more data repositories for hours. By 5 a.m., he's cloned and downloaded over 100 repositories. That's gigabytes of confidential company data. Exhausted and bleary-eyed, he calls it a night. We're going to take a quick break here, but stay with us because when we come back, Nick makes some really bad decisions.
Ransom Note
21:22This episode is sponsored by Material Security. Your cloud office is the heart of your business, but it's still protected by a patchwork of point solutions and manual workarounds. Yet while other critical assets have purpose-built security, your cloud office remains exposed. It's time to protect this system your business relies on with dedicated security built for cloud workspaces. Material Security is a detection and response platform purpose-built for protecting your Google workspace and Microsoft 365.
21:53Siloed point solutions might stop some threats at the gate, but leave massive gaps between tools. Sophisticated email attacks, risky misconfigurations, shadow IT, account takeovers. Material not only monitors everything continuously, it applies fixes and steps in to make sure information only flows where it's supposed to go. So if you're ready to stop trying to fill the gaps and start getting ahead of threats, check out Material Security. Learn more at their website, material.security. The website is material.security.
22:27The next day, Nick now has a crazy amount of company data sitting on his personal computer. Data that he has full legit access to for work, but isn't supposed to be downloading it to his personal home computer. You'd think he'd have some great idea for what to do next. But he seems a little lost. He messages a colleague, and he wants to know whether someone like him, a Ubiquiti employee, could cash in on the company's bug bounty program. This program, run by HackerOne, rewards people for finding vulnerabilities. It essentially outsources company security to the hacker community.
22:59Ethical hacking. Nick asks his colleague, Hey, can I, as an employee, get paid if I discover some security issue? Nick's colleague writes back and tells him, Well, not exactly. Ubiquiti only pays people for reporting found credentials. He finds Nick's message suspicious, though. Did Nick find something, and he's not saying something about it? He saves the message just in case. Still, apart from one suspicious colleague, no one else notices anything.
23:30No one reports any stolen data, and Nick is feeling pretty validated. Case in point, right? See, if someone broke in and downloaded all the source code, nobody would even know. He thought Ubiquiti's security was a total joke, and Nick has just nailed the first step to prove it. But he's got a problem. He hasn't fully covered his tracks. Or maybe he was just winging this whole thing, after all. Nick logs back into AWS. He changes the lifecycle retention policies to just one day. This will delete the logs. So while he was poking around downloading things, that all should be deleted by now.
24:02And Nick has a good point. He shouldn't have all this access to all the company's products, the source code, root access to the whole AWS environment. Data should be segmented, and only the people who need access should have access. If he was working on one of the product's software, that's what he should have access to, just that product's source code. And he just thinks, man, if a hacker were to get all these credentials, we'd have a big problem, just like CWT or Garmin. This level of access that he has shouldn't have been allowed. Plus, everything that gets accessed should be tracked, logged, and secured.
24:35If an unauthorized user logged in, the security team should immediately be alerted. If unauthorized downloads happen, that should trip some alarm. But nothing. Nobody noticed him downloading or accessing any of this data. He logs into AWS, and he starts renaming sessions. He renames 18 sessions like his own session, the ones he started from the VPN, and he renames these sessions to make it look like they belong to the DevOps colleagues. I'm not sure if he's trying to throw his coworkers under the bus, or if he's just trying to hide his tracks. And he does this just in the nick of time,
25:07because then, boom, ubiquity drops a company-wide announcement. A couple of employees have spotted strange activity on the systems. Somebody has been poking around where they shouldn't have, and data has been exfiltrated. Immediately, ubiquity sets up an internal team, like an incident response task force. They need their best people on this, fast. And guess who they call in to help investigate? Nicholas Sharp himself, the guy who loves being a hero. Nick swings in action. He's playing the part of a tireless investigator,
25:39clocking in long hours, combing two logs. But he's just dead weight. He's drumming up pointless work, and adding no value at all to the investigation. As the investigation heats up, some people zero in on the VPN used in the attack. Nick plays it cool. Surf? Surf shark VPN, you say? Oh, I've never used that. He insists. Deny. Divert. Distract. That's all he can do. The new year rolls around. Nick is still in fake investigator mode. That is, until one morning at the ungodly hour of 4 a.m.,
26:11a few senior employees at Ubiquity are awoken. Their phone screens light up. An email has come in, and it's a ransom note. It's from an anonymous hacker, claiming responsibility for the attack. The hacker has given Ubiquity an ultimatum. Either cough up 25 Bitcoin, or your stolen data will be published online. Now, at the time, 25 Bitcoin is worth about $2 million. That was Nick's grand plan. Extort his own company for money.
26:41He thought this will both fix the security problems he sees, but also pay him properly for the security problems he's discovered. There's more to this ransom note. Nick has tossed in an extra tidbit. He needed to make it more convincing that an outsider was behind this. So, to sweeten the deal, the hacker will share a secret. He's found a hidden backdoor to Ubiquity Systems, and if they want to know what it is, pay another 25 Bitcoin. The deadline was set. Midnight, January 9th, 2021. Pay the ransom, or watch the data go public.
27:13At this point, Ubiquity had a market cap of over $23 billion. Sure, paying a $1.9 million ransom would sting, but in the grand scheme of things, it's hardly catastrophic. They could take the hit and move on. At this point, the senior leadership is notified, and are debating what to do. So, CWT paid the ransom. Garmin might have paid the ransom. But that's because this had ransomware installed on their key systems, and their business came to a total halt. There was no ransomware on Ubiquity Systems, just someone threatening to publish the private source code to the company.
27:47While they were debating what to do, another senior employee gets a message on Keybase. Keybase is a chat app, and it just seems a little too personal for a random senior employee to get a direct message from the hacker. Nick himself was active on Keybase, and he had connections with other friends and employees on there too. But for a hacker to message a senior employee on there, it just seems a little odd, almost like a random employee was getting a text message from the hacker. Why this employee? Why choose Keybase to reach out?
28:19And how did they know this Keybase username, you know? The employee decrypts the message and reads it. It's a copy of the ransom email. There's also an attachment. It contains proof of the stolen data. Source code, company secrets, unreleased products, all of it. By now, all hell is breaking loose in the company. Crisis teams have been called in, select stakeholders looped in,
Investigation Begins
28:40and law enforcement is on the case. It's stressful, not just for the leadership of Ubiquity, but for many employees who are there to clean up the mess, especially over the holiday season. Some reports say that people were quitting over this. Leadership was still debating, pay the ransom or not pay the ransom. Ubiquity was taking this threat seriously. Meanwhile, Nick was waiting, and waiting, and waiting. He wants a response, and sometimes even checks his Bitcoin wallet to see if anything's been deposited yet. He watches the clock as the midnight deadline draws closer.
29:12Ubiquity seemed to ignore his threats. The deadline arrived, and no message came. No Bitcoin came. He has a bad feeling about this. He realizes he's not getting the money. So he decides to amp up the stress. He gets back on Keybase to message that same employee. No BTC, he types out. No talk. We done here. Nick uploads the stolen data to a public Keybase folder. He shows the public folder to the senior employee on Keybase.
29:43He's exposed it all to the public. Mission complete, right? Wrong. Nick's no longer feeling confident. He's second-guessing every move. What if Keybase isn't secure, he thought. He jumps online and Googles. Can Keybase data be subpoenaed? But it's too late to turn back now. Ubiquity has sprung into action. They contact Keybase, and just like that, Keybase removes all the data that Nick uploaded. Now Nick has nothing to work with. He was counting on Keybase. He thought they would never fold to a takedown request.
30:14It's just like what Teddy Lewis says in Body Heat. There's 50 ways you can screw up a crime, and a genius can only think of 25. Things were getting worse for Nick. Now the federal authorities were involved. His extortion scheme has failed. He's furious at Ubiquity, at himself. He blew it. Now all he can do is wait. For what? An arrest? Perhaps. But first, he needs Ubiquity to show its true colors just one more time. And just like that, they do. Ubiquity leadership thought
30:44there's a high chance that this anonymous hacker will release this company data. And they wanted to be ahead of that news to let their users know first. So they sent out an email to the users saying, We recently became aware of unauthorized access to certain information technology systems hosted by a third-party cloud provider. We have no indication that there has been unauthorized activity with respect to any users' accounts. But the language was concerning to customers who started to worry that their home address and passwords were leaked and in the hackers' hands.
31:14They relied on Ubiquity's equipment to be safe and secure. And now are unsure exactly how safe it is. Nick's fuming. This messaging, he felt, was sweeping the issue under the rug. It wasn't honest with the customers and it had confusing language. The way it's written, you could think that a third-party provider was part of the problem. This news was a PR problem, but not a PR disaster yet. Nick could use all this to his advantage. He knows the customers are angry. He knows Ubiquity is lying about what happened.
31:46He knows they have very little logs since he destroyed them. But before he gets too excited, Nick finds out that he's in trouble. Big trouble. His home IP address was found in the investigation. Nick's in the hot seat. The FBI is looking at this evidence. It's just a matter of time before they ask the ISP which customer had that IP that day. And Ubiquity wants answers. They just hired a forensics team. Nick is a suspect now since his IP is also the IP
32:17he's been connected to from work and the IP's matched. Nick is ordered to hand over everything. His company provide a router, video cameras, and his computer. So he hands it over and the forensics team is all over his stuff. They start with a video camera and go through hours of footage. Nothing there. They go through his computer dissecting it bit by bit. Deleted files are pulled back up and hard drives are pulled apart and they find nothing. That's because his hack was from a different computer not the company laptop. But when forensics start on Nick's home router
32:48they notice something suspicious going on. During the hours of the cyber attack there was a separate device transferring massive amounts of data about the same volume that was stolen. Turns out a MacBook laptop was used to connect to the router. A separate device from the one Nick handed over. So while he used a different device and a VPN forensics can still see some stuff. When his laptop connects to the Wi-Fi router that's a layer 2 connection of the OSI model Mac addresses. A VPN works on layer 3
33:19IP addresses so they can see which MAC address connected to that Ubiquiti router and it was a MacBook. Then when it comes to VPN traffic while you can't see what's in that data you can see how much data is passing through and which direction. So they were able to see a large amount of data downloaded the same night someone took it all from GitHub. The second laptop was a game changer. If the FBI could get their hands on it they'd have a clear link to the crime but not so fast. They needed a search warrant and those things take time.
33:51Nick does what every guy with secrets would do. He wipes and resets his personal MacBook the one that hasn't been confiscated yet. He keeps a laptop in his house. Tries to think of what other evidence they might have on him.
Nick's Downfall
34:04Months pass and Nick is keeping a low profile and staying out of trouble. But then on March 24th 2021 the FBI pull up to his house in Portland search warrant in hand. They bang on the door calling his name. Nick has no choice he has to let them in. So he does he watches as his house gets turned upside down. Agents are everywhere rummaging through drawers tossing stuff into evidence bags including his MacBook. They also want answers. The agents grill Nick about his involvement.
34:35He denies everything. They hit him with cold hard proof. We have evidence you purchased a Surfshark VPN back in July 2020 one agent tells him. Nick knew they knew this. He had time to come up with an excuse or a confession but this is what he goes with. He pulls the victim card he tells the FBI I'm being framed someone must have used my PayPal account. He's lying and they're not stupid but they wrap up their questioning they take their evidence and get out of there. Nick was dangerously close to being arrested
35:05but the FBI just came to collect things and didn't apprehend him yet. He has to use his time wisely. So what does he do? Does he cover his tracks? Does he hire a lawyer? Work on his defense? Flee the country? Or make a final attempt to clear his name? Nope. Nick jumps online and reaches out to Brian Krebs. Brian Krebs is a journalist who runs a site called KrebsOnSecurity.com He's well known in the cybersecurity world and reports on profit-driven cybercriminals. He's the perfect guy for Nick's story.
35:36Not because Nick wanted to out himself as a profit-driven cybercriminal. Nope. He wanted to expose Ubiquity as a lying corporation putting profits over security. So Nick types up his email keeping it anonymous. He's posting as a whistleblower with an inside scoop about the recent Ubiquity reach. Brian Krebs replies almost immediately Tell me more. Nick tells Brian that Ubiquity seriously downplayed what happened. They lied to their customers big time to save their stock price. Here's what really happened Nick wrote.
36:07Hackers got rude access to Ubiquity. They got into the AWS servers because Ubiquity stores logins in a LastPass account. How irresponsible. And he's not wrong. Ubiquity did lie in their public statements. They framed it as a third-party issue rather than admitting that all their company data had just been stolen and used to demand ransom. Which one is better? A third-party breach or an inside job? On top of that Nick said that Ubiquity doesn't keep logs. So of course there was no evidence of customer data accessed. The allegations
36:37seemed legit enough. So Brian Krebs ran with the story. The article goes live with the headline Whistleblower Ubiquity Breach Catastrophic. The news hit hard and fast. Customers were pissed off all over again. They feel completely violated knowing a hacker could have gotten into their stuff. This set off a chain reaction. Investors catch wind of the fallout and start selling their shares. Not just a couple but a whole lot of them. In just two days Ubiquity stock crashes by 20%. That's four billion dollars
37:08in market capitalization. Poof. Gone. Practically overnight. What was a PR problem has now turned into a PR disaster for Ubiquity but not for Nick. He's gotten his revenge. He's pulled it off. He's still a free man for now. And he couldn't stop now. Why quit while he's ahead? Watching Ubiquity's downfall was just too sweet. Nick then contacts a bunch of regulators both home and abroad. He tells them all about Ubiquity's misleading disclosures. How they lied. Perhaps they should take a closer look
37:39at what's going on there. But all good things come to an end.
Arrest and Aftermath
37:43In December 2021 the feds finally made their move. Nicholas Sharp was arrested on a four count indictment. The serious charge being wire fraud. This could land him 20 years in prison. Nick hires lawyers and gets a defense prepared. In February 2023 he pleads guilty to three counts. Intentionally damaging protected computers wire fraud and making false statements to the FBI. Nick admits that it was all planned for financial gain. But then he has a change of heart.