Former Cisco engineer gets 2-year prison sentence for Webex hack

Cisco didn't seek restitution for $2.4M in restoration and customer service costs

Cisco Webex logo under a magnifying glass

Northern California District Court has handed former Cisco software engineer Sudhish Kasaba Ramesh a two-year prison sentence for deleting 16,000 Webex collaboration accounts.

From August 2016 to April 2018, Ramesh was part of Cisco's platform team, focusing on automation, access to data, and logging metrics. This gave him access to servers on Amazon Web Services (AWS) that ran Cisco's Webex Teams application, which customers use for video conferencing, video messaging, and file sharing.

The Department of Justice (DOJ) charged Ramesh with intentionally accessing a protected computer without authorization and recklessly causing damage on July 13, 2020. He pleaded guilty in San Jose, California on August 26. 

The plea agreement said Ramesh accessed Cisco's cloud infrastructure running on AWS on September 24, 2018. He logged in via a Google Cloud Project account and used his AWS key to delete 456 virtual machines running Webex Teams.

Deleting the virtual machines shut down over 16,000 Webex Teams accounts for up to two weeks, costing around $1.4 million in employee time to restore the damage. According to the DOJ announcement in August, Cisco refunded over $1 million to affected customers de to Ramesh’s actions.

The case leaves two questions unanswered: Why Ramesh did it, and why he left such an obvious trail? He didn't explain his actions in court.

Prosecutors said they were "perplexed" at how Ramesh, who is "a highly intelligent individual," could have left such an obvious trail for the FBI investigators who caught him. He didn't use a proxy to carry out the attack and chose to launch it from his work computer instead, which contained search records querying how to delete Amazon servers. His Google Cloud Project account was also registered under his name and paid for with his credit card.

The District Court sentenced Ramesh to a two-year stint in prison and a $15,000 fine. Cisco didn't seek restitution for the incident, but reports claim he was also fired from his job at personal lifestyle website Stitch Fix. Ramesh will begin his prison sentence on February 10, 2021.

Featured Resources

BCDR buyer's guide for MSPs

How to choose a business continuity and disaster recovery solution

Download now

The definitive guide to IT security

Protecting your MSP and your customers

Download now

Cost of a data breach report 2020

Find out what factors help mitigate breach costs

Download now

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Recommended

TsuNAME vulnerability could enable DDoS attacks on major DNS servers
distributed denial of service (DDOS)

TsuNAME vulnerability could enable DDoS attacks on major DNS servers

7 May 2021
Security researchers take control of a Tesla via drone
ethical hacking

Security researchers take control of a Tesla via drone

5 May 2021
New report highlights the need for diversity in cyber security recruitment
cyber security

New report highlights the need for diversity in cyber security recruitment

28 Apr 2021
Hackers could abuse legitimate Windows AD FS to steal data
Microsoft Windows

Hackers could abuse legitimate Windows AD FS to steal data

28 Apr 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021