Jump to content

Engineer admits he wiped 456 Cisco WebEx VMs from AWS after leaving the biz, derailed 16,000 Teams accounts


awaraa

Recommended Posts

A former Cisco employee pleaded guilty in a San Jose federal court on Wednesday to unlawfully accessing Switchzilla's Amazon Web Services infrastructure and damaging the networking giant's cloud computing resources.

Sudhish Kasaba Ramesh, who worked at Cisco from July 2016 to April 2018, admitted in a plea agreement with prosecutors that he had deliberately connected to Cisco's AWS-hosted systems without authorization in September 2018 – five months after leaving the manufacturer. He then proceeded to delete virtual machines powering Cisco's WebEx video-conferencing service.

"During his unauthorized access, Ramesh admitted that he deployed a code from his Google Cloud Project account that resulted in the deletion of 456 virtual machines for Cisco’s WebEx Teams application, which provided video meetings, video messaging, file sharing, and other collaboration tools," the US Attorney's Office for the Northern District of California said in a statement.

According to prosecutors, Ramesh's actions resulted in the shutdown of more than 16,000 WebEx Teams accounts for up to two weeks, which cost Cisco roughly $1.4m in employee time for remediation and over $1m in customer refunds.

Ramesh is said to have admitted that he acted "recklessly" by deploying the code and that he "consciously disregarded the substantial risk that his conduct could harm to Cisco."

The specifics of the plea agreement remain under seal. And no mention is made in the accessible court filings of a motive. Nonetheless, Ramesh's current employer, personalized fashion biz Stitch Fix, appears keen to keep him on, if possible.

According to a court document, Ramesh is in the US on an H-1B visa and has a green card application pending. "Although he and his employer recognize that his guilty plea in this case may have immigration consequences, up to and including deportation, his employer … is willing to work with him regarding the possibility of his remaining in the country and continuing to work for the company," the document [PDF] says.

As far as Cisco is concerned, the main issue is that customer data wasn't lost or stolen.

"Cisco addressed the issue in September 2018 as quickly as possible, ensured no customer information was lost or compromised, and implemented additional safeguards," a Cisco spokesperson told The Register in an emailed statement.

"We brought this issue directly to law enforcement and appreciate their partnership in bringing this person to justice. We are confident processes are in place to prevent a recurrence."

Ramesh faces up to five years in the clink and a fine of $250,000 when he is sentenced, an event scheduled for December. ®

Link to comment
Share on other sites

LOL choothiye gaadu, but surprised that Cisco didn't revoke his access to their cloud servers even five months after he left the company. I guess it shows more about Cisco's complacency than anything. 

He should kiss his GC dreams a goodbye now. 

Link to comment
Share on other sites

personalized fashion biz Stitch Fix, appears keen to keep him on, if possible.According to a court document, Ramesh is in the US on an H-1B visa and has a green card application pending. "Although he and his employer recognize that his guilty plea in this case may have immigration consequences, up to and including deportation, his employer … is willing to work with him regarding the possibility of his remaining in the country and continuing to work for the company," the document [PDF] says.

 

This guy must  be a thope, or the company is just trying to be in the News.

Link to comment
Share on other sites

7 minutes ago, zarathustra said:

LOL choothiye gaadu, but surprised that Cisco didn't revoke his access to their cloud servers even five months after he left the company. I guess it shows more about Cisco's complacency than anything. 

 

+1

eedu chesina paniki network/sys admins ki moodindi

Link to comment
Share on other sites

22 minutes ago, ShruteSastry said:

personalized fashion biz Stitch Fix, appears keen to keep him on, if possible.According to a court document, Ramesh is in the US on an H-1B visa and has a green card application pending. "Although he and his employer recognize that his guilty plea in this case may have immigration consequences, up to and including deportation, his employer … is willing to work with him regarding the possibility of his remaining in the country and continuing to work for the company," the document [PDF] says.

 

This guy must  be a thope, or the company is just trying to be in the News.

https://scholar.google.com/citations?user=opDXz8oAAAAJ&hl=en

He is a thope

Link to comment
Share on other sites

11 minutes ago, Murari_Murari said:

Cisco vadiki sorry chepthay saripodhi gadha, a fine edo cisco ki direct ichestha ani agreement chesukovachu gadha. 

Aa chepthey sorry ani dulupukuni potharu, if they dont' set a strong example some other idiot will do this. No wonder they are going to make sure he gets the strongest possible punishment in this case. 

Link to comment
Share on other sites

1 hour ago, zarathustra said:

Aa chepthey sorry ani dulupukuni potharu, if they dont' set a strong example some other idiot will do this. No wonder they are going to make sure he gets the strongest possible punishment in this case. 

Why should they go after him if their management is incompetent that they didnt revoke access even after he left.

Link to comment
Share on other sites

1 hour ago, JohnSnow said:

Why should they go after him if their management is having incompetent that they didnt revoke access even after he left.

That doesn't mean he could still access their cloud servers, that's a felony right there 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...