Ex-Cisco engineer charged with wiping Webex Teams accounts

Sudhish Kasaba Ramesh has pleaded guilty to accessing Cisco's cloud infrastructure and deploying code that deleted 456 VMs

The Cisco Webex as seen on a computer display with the webcam light activated

A former Cisco employee has pleaded guilty to damaging Cisco’s internal network in an incident during 2018, leading to the deletion of 16,000 Webex Teams accounts belonging to company employees.

Sudhish Kasaba Ramesh was charged with intentionally accessing a protected computer without authorisation and recklessly causing damage after he accessed Cisco’s cloud infrastructure and deleted 456 virtual machines (VMs).

Several months after resigning from the company in April 2018, he concsiously deployed a piece of code from his Google Cloud Project that destroyed these VMs in Cisco’s cloud infrastructure, hosted by Amazon Web Services (AWS)

These VMs hosted Cisco’ Webex Teams application, which meant that more than 16,000 employees lost access to video conferencing, video messaging, file sharing and other collaboration tools, as their accounts were wiped.

This shutdown lasted two weeks and caused Cisco to spend around $1.4 million in time to restore the damage, as well as more than $1 million in refunds to consumers. No customer data was compromised as a result of these actions, according to the US Attorney’s Office fo the Northern District of California.

“Cisco addressed the issue in September 2018 as quickly as possible, ensured no customer information was lost or compromised, and implemented additional safeguards,” a Cisco spokesperson told IT Pro

“We brought this issue directly to law enforcement and appreciate their partnership in bringing this person to justice. We are confident processes are in place to prevent a recurrence.”

Ramesh was charged on 13 July and pled guilty to the single count, admitting that he acted recklessly in deploying the code, and consciously disregarded the substantial risk of his actions harming Cisco. His hearing is scheduled for 9 December 2020. 

The maximum penalty for committing such an offence is five years imprisonment and a fine of $250,000, although Ramesh’s guilty plea is likely to mean the final sentence is much softer than this.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

BEC scammers using Google Forms to identify easy victims
phishing

BEC scammers using Google Forms to identify easy victims

21 Jan 2021
FBI warns of ongoing corporate vishing attacks
phishing

FBI warns of ongoing corporate vishing attacks

19 Jan 2021
Hackers using COVID vaccine as a lure to spread malware
hacking

Hackers using COVID vaccine as a lure to spread malware

15 Jan 2021
Cyber criminals bypassing MFA to access cloud service accounts
two-factor authentication (2FA)

Cyber criminals bypassing MFA to access cloud service accounts

14 Jan 2021

Most Popular

SolarWinds hackers hit Malwarebytes through Microsoft exploit
hacking

SolarWinds hackers hit Malwarebytes through Microsoft exploit

20 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021
What is a 502 bad gateway and how do you fix it?
web hosting

What is a 502 bad gateway and how do you fix it?

12 Jan 2021