Transcription performed by LeahTranscribesJACK: I’m just gonna get right into it. Yeah, I don’t even want to ask your name ‘cause I don’t even want to know who’s doing this, but tell me the first time you did this.
SPEAKER: I started a new job a couple of months back, and it’s entirely remote work from home except for the occasional trip to the office. There may be eight people in the company who work at the main office that would recognize me at any given point. So, I saw an opportunity and decided to run with it. [Music] I was gonna try something I had never done before and steal food, ‘cause this is a famous office thing. I’m a university student at the same time as being a full-time employee. So, I wanted to like — everyone talks about this as a thing in the office; might as well become a member of the professional world. So, I took — just took a sandwich.
JACK: From where?
SPEAKER: Just from the office fridge. We have three refrigerators. It’s a little two-story office. So, I just went upstairs to a floor where my team would never be on and took a sandwich.
JACK: Now, so, you open the fridge to see what’s in there. You’re hungry; that was the whole goal, is to find something to eat out of there, and do you see an old container and some spoiled milk and sandwich and decide, okay, the sandwich is the best thing, or what goes through your mind on picking it?
SPEAKER: It was a couple of different things, but I thought, what’s the most inconspicuous thing? ‘Cause the sandwich wasn’t labelled. You could tell it was fresh, but it wasn’t labelled. So, it could easily be a case of mistaken sandwich. So, I’m like, well, this gives me an out. So, I grab it, I take it back to the — to my office or to my floor where I’m working with my team, and nobody bats an eye. They’ve just assumed that I’ve brought a sandwich. So, I didn’t even think that they would question it. But every time since then, whenever I’ve gone back, I’ve slowly stepped it up. I first started not necessarily looking as carefully for plainly-wrapped sandwiches; I’d grab a container and start looking through.
I now go to the fridge that’s on just the first floor of our office space where most people are, just open it up, and will grab the first sandwich I see, trying — and seeing if I can get away with it each time. I’ve also tried a couple of different sandwiches that way. I don’t think I’ve ever had a pastrami on rye until I started and stole a sandwich. It just became a little thrill for me, which sounds crazy in some capacity, but given the people you’ve interviewed, I don’t think it’s too far out. But it’s one of those things where I always get a little bit of a rush ‘cause I know nobody will ever figure it out and nobody’s gonna piece it together since I’m there maybe once a month or so. I just — I think it’s — it’s not evil.
JACK: Well, some would call you evil.
SPEAKER: I guess some would, and I think that’s really gonna open a separate conversation of where is the line?
Intro: [Intro music] These are true stories from the dark side of the internet. I’m Jack Rhysider. This is Darknet Diaries.
JACK: So, this story is about a guy name Nickolas Sharp. We’ll call him Nick. No, it’s not that sandwich thief you just heard. That’s a different person entirely unrelated. I just wanted to hear why someone would steal something from an office fridge. Nick, the main character in this story, is a guy who’s big into cloud infrastructure, which is taking care of the computers that run online services. Nick lived in Oregon, and one of the biggest companies in Oregon is Nike Shoes. So, he got a job there doing cloud engineering. By 2018 he was working for Amazon Web Services out of Portland, Oregon. The office there handles video and media solutions such as the encoding and live streaming of video that’s handled by AWS. About a mile away from AWS is Ubiquiti. They make routers, switches, and IP cameras, and they wanted Nick to join their growing team of 800 employees, since the skills Nick picked up at AWS were perfectly aligned with what Ubiquiti needed at the time.
So, in August 2018 he quit his job at AWS and took the job at Ubiquiti, moving up in his career. [Music] Nick was thirty-two years old by then, and he was ambitious. Right from the get go he wanted to make Ubiquiti more secure and more efficient, and he had a lot of ideas, and he wanted people to listen to him. There’s some rumors about Nick on some online forums. Some people say they worked with him at Ubiquiti, so take this with a grain of salt, because you can’t believe everything you read online. But these forum posts say Nick wasn’t the easiest guy to work with. He had a big ego, and what he would sometimes do is find a problem and he would make a big deal about it; this is a huge problem. We need to fix this right away. We gotta prioritize this. Then he’d step in and solve the problem and try to act like he’s taking big credit and saving the company. Well, this tactic seemed to work. Nick was actually crushing it at Ubiquiti.
Over a few years he rose up the ranks and ended up leading the whole cloud team. As he gained more responsibility, he gained more access to sensitive parts of Ubiquiti. He seemed to like getting access to more systems and parts of the network, I don’t think for any malicious reasons. Some people just like feeling important and they want access to important things. What we do know is that Nick was pulling in $250,000 a year to look after Ubiquiti’s cloud solutions. Even I’m impressed with that kind of pay. Dang. But after a few years his pay rate stopped growing. Nick stopped getting raises and promotions and started to feel under-appreciated. He thought he was hot stuff. He felt like his skills were rare, and he wasn’t feeling respected or praised or compensated enough. Nick felt overworked, overlooked, and definitely underpaid. Meanwhile, Ubiquiti sales were going crazy. They were making hundreds of millions of dollars in profits a year, and when the pandemic hit, their stock price doubled in 2020.
I guess a lot of people were working from home and they needed internet and networking gear, and Ubiquiti was ready to provide it to everyone. Nick was also working from home like most tech workers at the time, and it was a new routine to get familiar with. [Music] Still, Nick was giving it his all, clocking in, flagging security flaws, keeping systems safe for millions of customers who didn’t even know his name. Even after work hours he was glued to the news, keeping his fingers on the pulse. He doom-scrolled the cybersecurity headlines; data breaches, unauthorized access, ransomware attacks. They were hitting companies left, right, and center, and it drove Nick crazy. All these companies, they were thinking they’re invincible, untouchable. Well, at least the C-suite executives did. Then boom, they’re hacked. The security team and guys like him have to pick up the pieces, and the C-suite has a huge wake-up call when they realize they’ve been hacked and they’re not invulnerable.
Ubiquiti paid Nick a six-figure salary to deliver secure products and keep things safe. But he wondered if that was enough, or if they should pay him more to keep things safe. Nick reads on. Carlson Wagonlit Travel Company, or CWT, got hacked in July 2020. The hackers stole two terabytes of data. They claimed to have personal information about employees, business files, and financial documents. Then they infected the network with ransomware. CWT saw the infection hit and was spreading, and they had to take their network offline to stop the spread. When they finally got things under control, they realized they were in pretty bad shape. Ransomware rendered a lot of their computers worthless, and they didn’t have a way to decrypt or fix them. Then they got a letter. The hackers wanted $10 million from CWT in exchange for the decryption key. CWT was hit pretty bad. Their backups were hit, too, which meant a lot of this data was unrecoverable.
So, they began negotiating with the hackers and got the ransom down to $4.5 million. CWT paid the ransom, got the decryption key, and was able to get back up and running fairly quickly after that. Then right after that, Garmin, the GPS company, gets hit with ransomware, too, this time by a hacker group called Evil Corp. Some rumors say the hackers demanded $10 million to restore the systems. Garmin was in bad shape. Users couldn’t use their products. Their internal systems were down. They were offline and unusable for days. Rumors say they hired a cybersecurity team to help do incident response and negotiate the ransom deal. Then suddenly, the network came back up four days after being down. They never said if they paid the ransom or how much, but with everything restored so suddenly, many speculate Garmin did. Nick wasn’t exactly cash-strapped. He was getting paid $250,000 a year. But still, he felt like he wasn’t being compensated properly.
He wondered if he should go somewhere else where they’d appreciate him more. His big boss was Robert Pera, the CEO of Ubiquiti. At thirty-six, Robert became one of the youngest billionaires in the world. Nick was about the same age as him. So, while Robert’s success kept growing and growing and his wealth was accumulating, Nick felt like he had plateaued at his position, and that frustrated him. [Music] Some online sources say they had a beef going on. They definitely weren’t buddy, buddy. Nick’s thing was to make a big deal out of the security issues he found in order to look like a hero when he would fix them, and Robert was sometimes stopping him, saying, no, don’t focus on that. Instead, do this other stuff. Well, I know how aggravating that can be. I’ve been in jobs before where I felt like I was the only one who cared about the success of the company, and I was even told to care less about my job by my boss.
When you’re in a job like that where you see all these problems that you think should be priorities to fix and people are telling you to stop caring about those, it’s incredibly frustrating. So, Nick developed a chip on his shoulder. He just wanted to be seen, to be heard, to matter. He thought, gah, if Ubiquiti got hit with a security incident, that would surely wake them up and they’d listen to me. That’s when it occurred to him; what if I can demonstrate how bad a hacker could hurt the company? So, he thought about it. What would be a good way to give Ubiquiti a lesson, a scare so they’d listen to me more when I warn them of this kind of stuff? Nick looked at everything he had access to. He had access to the AWS cloud environment. He had access to all the source code on GitHub. He had access to all the Slack channels. He had a lot of access into this billion-dollar company. So, maybe he could use this access to hit them in some soft, squishy part of their business to give them a wake-up call.
Nick had to be smart about this. First thing’s first; location. He needed a strong Wi-Fi to hash out all the details. A cafe? Too many cameras. A library? Same deal. Home? No, IP addresses leave trails. But it’s 2020 now, and VPNs have been around forever. So he thought, alright, step one, get a VPN. Nick went with Surfshark VPN. He got a twenty-seven-month subscription and paid with his personal PayPal. It’s as if the hoodie went over his head now. He’s taken the first steps of his plan. Meanwhile, Nick keeps showing up to work. He’s doing all the usual stuff, maintaining AWS servers, checking vulnerabilities, and securing the cloud. But he has to play the part. He has to keep up this image of a dedicated, reliable cloud expert, a star employee. But what they didn’t know was that he was cooking up another plan. Late at night, Nick fine-tuned every detail of the plan. He needed to hit Ubiquiti where it hurts. It wasn’t just to scare them anymore, though.
He was starting to feel like he wanted payback for everything they’ve done to him or failed to do. Despite him getting multiple promotions and multiple raises and making $250,000 a year, he felt upset for not getting enough promotions, enough raises, and he wasn’t feeling like the big shot he wanted to feel. By now it’s December 2020. The festive season is in full swing in Portland, Oregon. It’s freezing outside, and Nick’s dreaming of sunny California. He’s been eyeing a job over there, good weather, and it’s only a nine-hour drive away. It looks good, but there’s something he needs to do here first before he leaves town. [Music] He’s been working on this job application. It’s for a tech company. See, for Nick’s plan to work, he had to still be employed at Ubiquiti. Nick sends off this job application and then late that same night — or, actually more like early morning around 3:00 a.m., Nick fires up his work laptop. He logs into Ubiquiti’s cloud environment on AWS.
He doesn’t use a backdoor or hack his way in. He logs in with his normal Ubiquiti company credentials just like when he’s normally working from home. But tonight was different. Nick was searching for something, a key, and not just a random key. This one was special. This was the key that unlocked access to all the other credentials within Ubiquiti’s systems, kind of like access to a password vault. It was the key to the castle. Nick found the key and got into the vault. He starts testing things, making sure everything works, double-checking that these passwords are correct. Then he logs out at 3:16 a.m. Two minutes later, at 3:18 a.m., someone else logs into the AWS system. It’s not from Nick’s IP. It’s not using Nick’s credentials. The attacker’s IP address is hidden behind a VPN. Whoever it is, they were trying to cover their tracks. This mysterious hacker had to get into the system somehow, so how’d they do it? Well, they used the same key that Nick had just accessed.
One of the things Nick complained about is that users and passwords weren’t audited enough or locked down. The principle of least privilege is something he tried to tell them about, where a user should only get access to what they need. But at Ubiquiti, some keys and users had wide-open access, which would give an attacker a lot of access if they had malicious intent. So, Nick decided to teach them a lesson firsthand. He was posing as an outsider to hack into his own company in the middle of the night from the comfort of his own home. Nick then runs a command called get-caller-identity. It’s a simple way to verify if he’s the user he thinks he is, and that’s it. That’s all he does. He logged in, checks the status of his account, and logs back out. This at least proves to him that he’s got what he needs to carry out something bigger if he chooses. Also, it’s a test to see if anyone notices. For the next week or so, Nick’s just sitting tight, playing it cool. On December 21st, Nick decides it’s go time.
[Music] He’s given his test run enough time. He’s confident a quote, unquote, “hacker” could slip in again unnoticed. So, after dinner Nick logs into Ubiquiti’s GitHub account. GitHub is where Ubiquiti stores their source code. Nick is allowed access to it. He goes through the standard log-in process like nothing’s up. He’s got nothing to hide. Now, GitHub is where Ubiquiti keeps a lot of source code, details on software launches and product blueprints. Many of these projects are public for anyone to see, but Ubiquiti also uses GitHub to host private data, stuff not meant for the public, some of which is pretty sensitive information. Nick starts scrolling through some of the private data repositories. These are folders that store every change made to the source code. Nick logs out of GitHub, and a minute later he logs back in, this time using a VPN and with a different account. He logged in using a GitHub account which has full access to all the projects on GitHub, including all the private ones.
It’s a shared account, not exactly tied to Nick specifically, almost like the master password for Ubiquiti. Nick connects using a VPN and is in GitHub using the shared high-level account. He connects via SSH. His IP is hidden and he feels like he can move secretly around the files and folders now. He quickly pulls up the names of the data repositories, the same files he had just casually scrolled through on his normal account. Wasting no time, he starts running commands to clone these top-secret files. He downloads them straight to his home computer, but he’s not stopping there. He also wants the entire history of changes to these files. Every time a Ubiquiti developer tweaks the source code, that change is logged. Nick leans in. This is the beginning of his big plan. It started. He’s sitting behind his computer screen and he slams in another command. Now he’s cloned all the logs, too. His screen is lit up in the dark of the night, and he watches file after file stream into his computer. He’s almost got it all.
He’s almost got what he needs, and just when he’s on the verge of mission complete, everything stops. The cloning stops. Minutes pass with nothing happening. Something went wrong. Nick’s internet went out. [Music] Nick picks up the phone and makes a frantic call to his ISP. This was not part of the plan. The internet is down, he tells the customer service rep. He’s freaking out. Are you kidding? This can’t be happening now, right in the middle of his big plan. He was so close, too. Now remember, Nick was connected behind that Surfshark VPN, and there’s a chance that if the VPN drops the connection and then somehow resumes before the VPN can come back up, it could expose his real IP. This worried him. He might have botched the whole thing. Okay, but wait, Nick is a tech guy. He thought about that and enabled a VPN kill switch, which means if the VPN is down, no connections will go out.
For thirty agonizing minutes Nick is on the phone with his internet service provider, tonight of all nights. After a half an hour, the red light turns green. Nick hangs up and gets straight back into it. He resumes his connection to GitHub and continues to clone and download all the private repositories. But unbeknownst to Nick, his real IP did get logged. We’re not sure how. Maybe the kill switch didn’t work. Maybe the ISP outage had something to do with it, but GitHub’s logs see two different IPs logging in with that username, one from a VPN and one from a house in Portland, Nick’s house. Nick made sure the VPN was working, but he’s nervous and frantic and isn’t always thinking straight. He continues cloning more data repositories for hours. By 5:00 a.m. he’s cloned and downloaded over 100 repositories. That’s gigabytes of confidential company data. Exhausted and bleary-eyed, he calls it a night.
We’re gonna take a quick break here, but stay with us, ‘cause when we come back, Nick makes some really bad decisions. The next day, Nick now has a crazy amount of company data sitting on his personal computer, data that he has full, legit access to for work, but isn’t supposed to be downloading it to his personal home computer. You’d think he’d have some great idea for what to do next, but he seems a little lost. He messages a colleague. He wants to know whether someone like him, a Ubiquiti employee, could cash in on the company’s bug bounty program. This program, run by HackerOne, rewards people for finding vulnerabilities. It essentially outsources company security to the hacker community, ethical hacking. Nick asks his colleague, hey, can I as an employee get paid if I discover some security issue? Nick’s colleague writes back and tells him, well, not exactly. Ubiquiti only pays people for reporting found credentials. He finds Nick’s message suspicious, though.
Did Nick find something and he’s not saying something about it? He saves the message just in case. Still, apart from one suspicious colleague, no one else notices anything. No one reports any stolen data, and Nick is feeling pretty validated. Case and point, right? See, if someone broke in and downloaded all the source code, nobody would even know. He thought Ubiquiti’s security was a total joke, and Nick has just nailed the first step to prove it. [Music] But he’s got a problem. He hasn’t fully covered his tracks. Maybe he was just winging this whole thing, after all. Nick logs back into AWS. He changes the life cycle retention policies to just one day. This will delete the logs, so while he was poking around downloading things, that all should be deleted by now. Nick has a good point; he shouldn’t have all this access to all the company’s products, the source code, root access to the whole AWS environment.
Data should be segmented, and only the people who need access should have access. If he was working on one of the product’s software, that’s what he should have access to, just that product’s source code. He just thinks, man, if a hacker were to get all these credentials, we’d have a big problem just like CWT or Garmin. This level of access that he has shouldn’t have been allowed. Plus, everything that gets accessed should be tracked, logged, and secured. If an unauthorized user logged in, the security team should immediately be alerted. If unauthorized downloads happen, that should trip some alarm. But nothing. Nobody noticed him downloading or accessing any of this data. He logs into AWS and he starts renaming sessions. He renames eighteen sessions like his own session, the ones he started from the VPN, and he renames these sessions to make it look like they belong to the DevOps colleagues.
I’m not sure if he’s trying to throw his coworkers under the bus or if he’s just trying to hide his tracks. He does this just in the nick of time, because then, [Music] boom, Ubiquiti drops a company-wide announcement. A couple of employees spot it, strange activity on the systems. Somebody has been poking around where they shouldn’t have, and data has been exfiltrated. Immediately Ubiquiti sets up an internal team like an incident response task force. They need their best people on this fast. Guess who they call in to help investigate? Nickolas Sharp himself, the guy who loves being a hero. Nick swings into action. He’s playing the part of a tireless investigator, clocking in long hours, combing through logs, but he’s just dead weight. He’s drumming up pointless work and adding no value at all to the investigation. As the investigation heats up, some people zero in on the VPN used in the attack. Nick plays it cool. Surfshark VPN, you say? Oh, I’ve never used that, he insists. Deny, divert, distract.
That’s all he can do. The new year rolls around. Nick is still in fake investigator mode. That is, until one morning at the ungodly hour of 4:00 a.m. A few senior employees at Ubiquiti are awoken. Their phone screens light up. An e-mail has come in, and it’s a ransom note. It’s from an anonymous hacker claiming responsibility for the attack. [Music] The hacker has given Ubiquiti an ultimatum; either cough up twenty-five Bitcoin or your stolen data will be published online. Now, at the time, twenty-five Bitcoin is worth about $2 million. That was Nick’s grand plan, extort his own company for money. He thought this would both fix the security problems he sees, but also pay him properly for the security problems he’s discovered. There’s more to this ransom note. Nick has tossed in an extra tidbit. He needed to make it more convincing that an outsider was behind this. So, to sweeten the deal, the hacker will share a secret.
He’s found a hidden backdoor to Ubiquiti’s systems, and if they want to know what it is, pay another twenty-five Bitcoin. The deadline was set; midnight, January 9th, 2021. Pay the ransom or watch the data go public. At this point Ubiquiti had a market cap of over $23 billion. Sure, paying a $1.9 million ransom would sting, but in the grand scheme of things, it’s hardly catastrophic. They could take the hit and move on. At this point the senior leadership is notified and are debating what to do. CWT paid the ransom. Garmin might have paid the ransom, but that’s because this had ransomware installed on their key systems and their business came to a total halt. There was no ransomware on Ubiquiti systems, just someone threatening to publish the private source code to the company. While they were debating what to do, another senior employee gets a message on Keybase. Keybase is a chat app, and it just seems a little too personal for a random senior employee to get a direct message from the hacker.
Nick himself was active on Keybase and he had connections with other friends and employees on there, too, but for a hacker to message a senior employee on there, it just seems a little odd, almost like a random employee was getting a text message from the hacker. Why this employee? Why choose Keybase to reach out, and how did they know this Keybase username, you know? The employee decrypts the message and reads it. It’s a copy of the ransom e-mail. There’s also an attachment. It contains proof of the stolen data; source code, company secrets, unreleased products, all of it. By now, all hell is breaking loose in the company. Crisis teams have been called in, select stakeholders looped in, and law enforcement is on the case. It’s stressful not just for the leadership of Ubiquiti, but for many employees who were there to clean up the mess, especially over the holiday season. Some reports say that people were quitting over this.
Leadership was still debating; pay the ransom or not pay the ransom. Ubiquiti was taking this threat seriously. [Music] Meanwhile, Nick was waiting and waiting and waiting. He wants a response, and sometimes even checks his Bitcoin wallet to see if anything has been deposited yet. He watches the clock as the midnight deadline draws closer. Ubiquiti seemed to ignore his threats. The deadline arrived, and no message came. No Bitcoin came. He has a bad feeling about this. He realizes he’s not getting the money, so he decides to amp up the stress. He gets back on Keybase to message that same employee. No BTC, he types out. No talk. We done here. Nick uploads the stolen data to a public Keybase folder. He shows the public folder to the senior employee on Keybase. He’s exposed it all to the public. Mission complete, right? Wrong. Nick’s no longer feeling confident. He’s second guessing every move. What if Keybase isn’t secure, he thought?
He jumps online and googles, can Keybase data be subpoenaed? But it’s too late to turn back now. Ubiquiti has sprung into action. They contact Keybase, and just like that, Keybase removes all the data that Nick uploaded. Now Nick has nothing to work with. He was counting on Keybase. He thought they would never fold to a take-down request. It’s just like what Teddy Lewis says in Body Heat; there’s fifty ways you can screw up a crime, and a genius can only think of twenty-five. [Music] Things were getting worse for Nick. Now the federal authorities were involved. His extortion scheme has failed. He’s furious at Ubiquiti, at himself. He blew it. Now all he can do is wait. For what, an arrest? Perhaps. But first he needs Ubiquiti to show its true colors just one more time. Just like that, they do. Ubiquiti leadership thought there’s a high chance that this anonymous hacker will release this company data, and they wanted to be ahead of that news to let their users know first.
So, they sent out an e-mail to the users saying, we recently became aware of unauthorized access to certain information technology systems hosted by a third-party cloud provider. We have no indication that there has been unauthorized activity with respect to any users’ accounts. But the language was concerning to customers, who started to worry that their home address and passwords were leaked and in the hacker’s hands. They relied on Ubiquiti’s equipment to be safe and secure, and now are unsure exactly how safe it is. Nick’s fuming. This messaging he felt was sweeping the issue under the rug. It wasn’t honest with the customers, and it had confusing language. The way it’s written, you could think that a third-party provider was part of the problem. This news was a PR problem, but not a PR disaster yet. Nick could use all this to his advantage. He knows the customers are angry. He knows Ubiquiti is lying about what happened. He knows they have very little logs, since he destroyed them.
But before he gets too excited, Nick finds out that he’s in trouble, big trouble. His home IP address was found in the investigation. Nick’s in the hot seat. The FBI is looking at this evidence. It’s just a matter of time before they ask the ISP, which customer had that IP that day? Ubiquiti wants answers. They just hired a forensics team. Nick is a suspect now since his IP is also the IP he’s been connecting to from work, and the IPs match. Nick is ordered to hand over everything; his company provider router, video cameras, and his computer. So, he hands it over, and the forensics team is all over his stuff. They start with the video camera and go through hours of footage. Nothing there. They go through his computer, dissecting it bit by bit. Deleted files are pulled back up, and hard drives are pulled apart. They find nothing. [Music] That’s because his hack was from a different computer, not the company laptop. But when forensics start on Nick’s home router, they notice something suspicious going on.
During the hours of the cyber-attack, there was a separate device transferring massive amounts of data about the same volume that was stolen. Turns out, a MacBook laptop was used to connect to the router, a separate device from the one Nick handed over. So, while he used a different device and a VPN, forensics can still see some stuff. When his laptop connects to the Wi-Fi router, that’s a layer 2 connection of the OSI model, MAC addresses. A VPN works on layer 3, IP addresses. So, they can see which MAC address connected to that Ubiquiti router, and it was a MacBook. Then when it comes to VPN traffic, while you can’t see what’s in that data, you can see how much data is passing through and which direction. So, they were able to see a large amount of data downloaded the same night someone took it all from GitHub. The second laptop was a game changer. If the FBI could get their hands on it, they’d have a clear link to the crime. But not so fast.
They needed a search warrant, and those things take time. Nick does what every guy with secrets would do; he wipes and resets his personal MacBook, the one that hasn’t been confiscated yet. He keeps the laptop in his house, tries to think of what other evidence they might have on him. Months pass, and Nick is keeping a low profile and staying out of trouble. But then on March 24th, 2021, the FBI pull up to his house in Portland, search warrant in hand. [Music] They bang on the door, calling his name. Nick has no choice. He has to let them in, so he does. He watches as his house gets turned upside-down. Agents are everywhere, rummaging through drawers, tossing stuff into evidence bags, including his MacBook. They also want answers. The agents grill Nick about his involvement. He denies everything. They hit him with cold, hard proof. We have evidence you purchased a Surfshark VPN back in July 2020, one agent tells him. Nick knew they knew this.
He had time to come up with an excuse or a confession, but this is what he goes with; he pulls the victim card. He tells the FBI, I’m being framed. Someone must have used my PayPal account. He’s lying, and they’re not stupid. But they wrap up their questioning. They take their evidence and get out of there. Nick was dangerously close to being arrested, but the FBI just came to collect things and didn’t apprehend him yet. He has to use his time wisely, so what does he do? Does he cover his tracks? Does he hire a lawyer? Work on his defence? Flee the country or make a final attempt to clear his name? Nope. Nick jumps online and reaches out to Brian Krebs. Brian Krebs is a journalist who runs a site called krebsonsecurity.com. He’s well known in the cybersecurity world and reports on profit-driven cyber-criminals. He’s the perfect guy for Nick’s story, not because Nick wanted to out himself as a profit-driven cyber-criminal.
Nope, he wanted to expose Ubiquiti as a lying corporation putting profits over security. So, Nick types up his e-mail, keeping it anonymous. He’s posting as a whistleblower with an inside scoop about the recent Ubiquiti breach. Brian Krebs replies almost immediately; tell me more. [Music] Nick tells Brian that Ubiquiti seriously downplayed what happened. They lied to their customers big time to save their stock price. Here’s what really happened, Nick wrote. Hackers got root access to Ubiquiti. They got into the AWS servers because Ubiquiti stores log-ins in a LastPass account. How irresponsible. He’s not wrong. Ubiquiti did lie in their public statements. They framed it as a third-party issue rather than admitting that all their company data had just been stolen and used to demand ransom. Which one is better, a third-party breach or an inside job? On top of that, Nick said that Ubiquiti doesn’t keep logs. So, of course there was no evidence of customer data accessed.
The allegations seemed legit enough, so Brian Krebs ran with the story. The article goes live with the headline, ‘Whistleblower: Ubiquiti Breach Catastrophic’. The news hit hard and fast. Customers were pissed off all over again. They feel completely violated knowing a hack could have gotten into their stuff. This set off a chain reaction. Investors catch wind of the fallout and start selling their shares, not just a couple, but a whole lot of them. In just two days Ubiquiti’s stock crashes by 20%. That’s $4 billion in market capitalization poof, gone, practically overnight. What was a PR problem has now turned into a PR disaster for Ubiquiti, but not for Nick. [Music] He’s gotten his revenge. He’s pulled it off. He’s still a free man for now. He couldn’t stop now. Why quit while he’s ahead? Watching Ubiquiti’s downfall was just too sweet. Nick then contacts a bunch of regulators both home and abroad. He tells them all about Ubiquiti’s misleading disclosures, how they lied.
Perhaps they should take a closer look at what’s going on there. But all good things come to an end. In December 2021, the feds finally made their move. Nickolas Sharp was arrested on a four-count indictment, the serious charge being wire fraud. This could land him twenty years in prison. Nick hires lawyers and gets a defense prepared. In February 2023 he pleads guilty to three counts; intentionally damaging protected computers, wire fraud, and making false statements to the FBI. Nick admits that it was all planned for financial gain. But then he has a change of heart, or maybe his lawyers come up with a new strategy. In his pre-sentencing, Nick insists it wasn’t about the money. He pleads with the judge, please, no prison time. The whole thing was just an unsanctioned security drill to make Ubiquiti a safer place. I wanted Ubiquiti to finally pay attention to its ongoing security issues. I got carried away, sure, but I had really good intentions. Yeah, well, security drill or not, the judge sentenced Nick to six years in prison, and that’s where he remains today.
(Outro): [Outro music] This episode was created by me, Mr. Glitchy Pants, Jack Rhysider. This episode was researched and written by Clippy’s revenge, Laura Woods. Our editor is the Wi-Fi whisperer, Tristan Ledger, sound design by the pin king, Andrew Meriwether, mixing done by Proximity Sound, and our intro music is by the mysterious Breakmaster Cylinder. Why don’t aliens visit Earth? They can’t figure out the ‘are you human?’ CAPTCHAs. This is Darknet Diaries.