AI Summary
5 min readIn late 2020, Nicholas Sharp, a 32-year-old cloud engineer at Ubiquiti, a billion-dollar networking equipment company, sat in his Portland home and decided to hack his own employer. He wasn't a bored outsider looking for a thrill. He was the senior cloud team lead, making $250,000 a year, and he felt underappreciated, overlooked, and underpaid. His plan was to break in, steal company secrets, and demand a ransom—not just for the money, but to prove a point about Ubiquiti's security failures. What followed was a strange, self-defeating heist that cratered the company's stock by $4 billion and landed Sharp in federal prison.
The insider who wanted to be a hero
Sharp joined Ubiquiti in August 2018 after working at Amazon Web Services. He was ambitious and opinionated. According to anonymous forum posts from people who claim to have worked with him, Sharp had a big ego and a habit of finding problems, making a huge fuss about them, and then stepping in to solve them himself—like a self-appointed hero. The tactic worked. Over a few years, he rose to lead the entire cloud team, gaining access to Ubiquiti's most sensitive systems: the AWS cloud environment, the GitHub source code repositories, and all internal Slack channels.
Continue reading the full summary in the app — free to try.
Read Full Summary →Free • No credit card required
Never miss an episode of Darknet Diaries
Get every new episode summarized in your inbox — free, ~5 minutes to read.
No spam. Unsubscribe anytime.
What you'll learn
- 1 Ubiquiti — Darknet Diaries
- 2 Timestamped Outline
- 3 (06:41) **Introducing Nicholas "Nick" Sharp** - A cloud engineer who worked at Nike and AWS before joining Ubiquiti in 2018
- 4 (10:40) **The Ransomware Landscape That Inspired Nick** - Nick watched high-profile ransomware attacks on CWT and Garmin
- 5 (13:39) **Nick's Plan Takes Shape** - He decided to hack his own company to prove how vulnerable they were
- 6 (14:19) **Setting Up the Attack Infrastructure** - Nick took precautions to hide his identity
- 7 (16:14) **The First Breach - Finding the Master Key** - At 3 AM, Nick logged into Ubiquiti's AWS environment using his legitimate credentials
+ Full timestamped outline available in the app
Show Notes
Nickolas Sharp worked for Ubiquiti, a company that makes networking equipment. He noticed that there were some security problems at work. He tried to point them out, but didn't feel like he was being listened to enough. What do you do when the company you work for isn't securing their software up to your standards? Well, he thought he needed to teach them a lesson, but in the end, he learned an even bigger lesson.
Sponsors
This show is brought to you by Drata. Drata is the trust management platform that uses AI-driven automation to modernize governance, risk, and compliance, helping thousands of businesses stay audit-ready and scale securely. Learn more at drata.com/darknetdiaries.
This show is sponsored by Material Security. Your cloud office (think Google Workspace or Microsoft 365) is the core of your business, but it’s often protected by scattered tools and manual fixes. Material is a purpose-built detection and response platform that closes the gaps those point solutions leave behind. From email threats to misconfigurations and account takeovers, Material monitors everything and steps in with real-time fixes to keep your data flowing where it should. Learn more at https://material.security.
Support for this show comes from ThreatLocker. ThreatLocker is a Zero Trust Platform that gives organizations control over what can run and what users and devices can access. It combines prevention with real time detection and automated response, helping security teams stop unauthorized activity and quickly contain compromised machines. Learn how ThreatLocker can strengthen your defenses at threatlocker.com/Darknet.
Sources
Full list of sources on the show page: https://darknetdiaries.com/episode/178/
More from this podcast
Darknet Diaries →