178: Ubiquiti

Summary of 178: Ubiquiti

by Jack Rhysider

36mAugust 4, 2026

Overview of Darknet Diaries: Ubiquiti

This episode tells the story of Nicholas “Nick” Sharp, a cloud engineer at Ubiquiti who used his legitimate access to steal internal company data, attempt an extortion scheme, and then try to pose as a whistleblower after the attack unraveled. What began as resentment over pay, status, and security complaints escalated into a full-blown insider breach that drew in the FBI, the press, regulators, and a major stock selloff.

What Happened

Nick’s background and motivation

  • Nick worked in cloud infrastructure and rose quickly at Ubiquiti after joining in 2018.
  • He gained broad access to AWS, GitHub, Slack, and other internal systems.
  • Although he was well paid, he felt underappreciated, overworked, and stuck in place while Ubiquiti’s business and leadership kept growing.
  • He became increasingly fixated on security failures and believed the company wasn’t taking his warnings seriously.

The insider attack

  • In late 2020, Nick began testing how much access he could exploit without being noticed.
  • He used his normal credentials, plus a VPN, to access internal systems from home.
  • He cloned and downloaded over 100 private repositories and their commit histories from Ubiquiti’s GitHub environment.
  • He then tried to hide his tracks by:
    • changing AWS log retention settings,
    • renaming sessions to make them look like other employees’ activity,
    • and relying on a VPN kill switch to avoid exposing his home IP.

The extortion attempt

  • After exfiltrating the data, Nick sent an anonymous ransom note demanding 25 Bitcoin, with a second demand tied to a supposed “hidden backdoor.”
  • Ubiquiti debated whether to pay, especially as the threat became public and internal response teams got involved.
  • Nick uploaded proof of the stolen data to Keybase and tried to pressure executives and employees directly.
  • Keybase removed the data, undermining his leverage.

Investigation and exposure

  • Ubiquiti and investigators discovered clues tying the attack to Nick, including:
    • his home IP address,
    • evidence of VPN usage,
    • and router/network traffic showing a large data transfer from a separate MacBook.
  • The FBI eventually searched his house and seized evidence.
  • Nick denied involvement and claimed he was being framed.

The Public Fallout

The KrebsOnSecurity angle

  • Nick contacted journalist Brian Krebs anonymously, presenting himself as a whistleblower.
  • He claimed Ubiquiti had seriously downplayed the breach and lied to customers.
  • Krebs published the story, which intensified public anger and badly damaged Ubiquiti’s reputation.

Business impact

  • Ubiquiti’s stock dropped sharply, wiping out billions in market value.
  • Customers and investors reacted strongly to the breach and the company’s confusing public messaging.
  • Nick also contacted regulators, pushing the narrative that Ubiquiti had misled the public.

Legal Outcome

Charges and plea

  • Nick was arrested in December 2021 and indicted on multiple counts, including wire fraud.
  • In 2023, he pleaded guilty to:
    • intentionally damaging protected computers,
    • wire fraud,
    • and making false statements to the FBI.

Sentence

  • Nick later argued that the attack was really an unsanctioned “security drill” meant to force Ubiquiti to take security more seriously.
  • The court rejected that framing.
  • He was sentenced to six years in prison.

Key Takeaways

  • Insider threats can be more dangerous than outside hackers. Nick had legitimate access, so he didn’t need to “break in” in the traditional sense.
  • Excessive permissions create huge risk. Broad access to source code, cloud systems, and shared credentials made the breach possible.
  • Logs and segmentation matter. Retaining audit trails and limiting access could have reduced the damage and sped up detection.
  • A bad internal security culture can escalate problems. Nick’s frustration over being ignored appears to have contributed to his decision-making.
  • Attempting to control the narrative can backfire. Nick’s whistleblower story gained traction, but it also worsened the fallout and didn’t stop the investigation.

Notable Theme

The episode is less about a sophisticated external hack and more about how ego, resentment, and poor access controls can turn a trusted employee into a major security threat. It’s a reminder that strong cybersecurity is as much about internal governance and visibility as it is about keeping outsiders out.