fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Ex-Cisco Engineer Who Nuked 16k WebEx Accounts Goes To Prison

Ex-Cisco Engineer Who Nuked 16k WebEx Accounts Goes To Prison

Sudhish Kasaba Ramesh, a former Cisco engineer, was sentenced on Wednesday to two years in prison and ordered to pay a $15,000 fine for shutting down more than 16,000 WebEx Teams accounts and over 450 virtual machines in 2018,

A plea agreement filed in July 2020 revealed that the 30-year-old man accessed Cisco’s cloud infrastructure hosted on Amazon Web Services without permission on September 24, 2018, after resigning from the company five months earlier, in April 2018.

Customer data not compromised during the intrusion

“[D]uring his unauthorized access he deployed a code from his Google Cloud Project account that resulted in the deletion of 456 virtual machines for Cisco’s WebEx Teams application, which provides video meetings, video messaging, file sharing, and other collaboration tools,” a Department of Justice press release says.

As a direct result of his activity, over 16,000 WebEx Teams accounts had to be shut down for roughly two weeks which resulted in Cisco having to spend around $2,400,000 in customer refunds and employee time for restoring the damage caused by Ramesh.

Also Read: Letter of Consent MOM: Getting the Details Right

However, no customer data was compromised due to his malicious conduct as the prosecutors explained in the DoJ press release.

Ramesh admitted to his reckless actions in his guilty plea and said that he also consciously disregarded the substantial risk and damage deleting the virtual machines from Cisco’s systems would cause.

“Cisco addressed the issue in September 2018 as quickly as possible, ensured no customer information was lost or compromised, and implemented additional safeguards,” Cisco said in a statement.

“We brought this issue directly to law enforcement and appreciate their partnership in bringing this person to justice. We are confident processes are in place to prevent a recurrence.”

Sentenced to two years in prison

Ramesh received a sentence of 24 months in prison after being found guilty of a count of Intentionally Accessing a Protected Computer Without Authorization and Recklessly Causing Damage.

He was further sentenced to pay a $15,000 fine and to serve one year of supervised release after two years imprisonment.

The maximum statutory penalty he faced for his actions after pleading guilty in August 2020 was five years imprisonment and a $250,000 fine.

Despite having a green card application pending and having an H1 visa, Ramesh also faces deportation to his native country of India following his sentence.

Also Read: How to Send Mass Email Without Showing Addresses: 2 Great Workarounds

At the moment, “the defendant is out of custody and will begin serving the sentence on February 10, 2021,” according to the U.S. Attorney’s Office for the Northern District of California.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us