Off-Prem

SaaS

Engineer admits he wiped 456 Cisco WebEx VMs from AWS after leaving the biz, derailed 16,000 Teams accounts

Switchzilla's cloud infrastructure trashed. And his new employer doesn't want to fire him


Updated A former Cisco employee pleaded guilty in a San Jose federal court on Wednesday to unlawfully accessing Switchzilla's Amazon Web Services infrastructure and damaging the networking giant's cloud computing resources.

Sudhish Kasaba Ramesh, who worked at Cisco as a software engineer from July 2016 to April 2018, admitted in a plea agreement with prosecutors that he had deliberately connected to Cisco's AWS-hosted systems without authorization in September 2018 – five months after leaving the manufacturer. He then proceeded to delete virtual machines powering Cisco's WebEx video-conferencing service.

"During his unauthorized access, Ramesh admitted that he deployed a code from his Google Cloud Project account that resulted in the deletion of 456 virtual machines for Cisco’s WebEx Teams application, which provided video meetings, video messaging, file sharing, and other collaboration tools," the US Attorney's Office for the Northern District of California said in a statement.

According to prosecutors, Ramesh's actions resulted in the shutdown of more than 16,000 WebEx Teams accounts for up to two weeks, which cost Cisco roughly $1.4m in employee time for remediation and over $1m in customer refunds.

Holy smokes! Ex-IT admin gets two years prison for trashing Army chaplains' servers

READ MORE

Ramesh is said to have admitted that he acted "recklessly" by deploying the code and that he "consciously disregarded the substantial risk that his conduct could harm to Cisco."

The specifics of the plea agreement remain under seal. And no mention is made in the accessible court filings of a motive. Nonetheless, Ramesh's current employer, personalized fashion biz Stitch Fix, appears keen to keep him on, if possible.

According to a court document, Ramesh is in the US on an H-1B visa and has a green card application pending. "Although he and his employer recognize that his guilty plea in this case may have immigration consequences, up to and including deportation, his employer … is willing to work with him regarding the possibility of his remaining in the country and continuing to work for the company," the document [PDF] says.

As far as Cisco is concerned, the main issue is that customer data wasn't lost or stolen.

"Cisco addressed the issue in September 2018 as quickly as possible, ensured no customer information was lost or compromised, and implemented additional safeguards," a Cisco spokesperson told The Register in an emailed statement.

"We brought this issue directly to law enforcement and appreciate their partnership in bringing this person to justice. We are confident processes are in place to prevent a recurrence."

Ramesh faces up to five years in the clink and a fine of $250,000 when he is sentenced, an event scheduled for December. ®

Updated to add

"Sudhish Ramesh no longer works at Stitch Fix," the company told The Register in a statement.

Send us news
56 Comments

Google's got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft's $20B+ security biz

How Chocolate Factory hopes to double down on enterprise-sec

Signalgate solved? Report claims journalist’s phone number accidentally saved under name of Trump official

PLUS: Google re-patches Quick Share flaws; Critical Cisco flaw exploited; WordPress plugin trouble; and more

LLMs can't stop making up software dependencies and sabotaging everything

Hallucinated package names fuel 'slopsquatting'

Google wins 1-1: Judge rules ad giant broke some antitrust law

After battle with Uncle Sam over online competition, web giant vows to appeal the bit it lost, celebrates the half it won

Apps-from-prompts Firebase Studio is a great example – of why AI can't replace devs

Big G reckons this agentic IDE speeds up or simplifies coding. Developers who've used it aren't so sure

Hacktivism resurges – but don't be fooled, it's often state-backed goons in masks

Military units, government nerds appear to join the fray, with physical infra in sights

Chrome to patch decades-old flaw that let sites peek at your history

After 23 years, the privacy plumber has finally arrived to clean up this mess

<i>The Reg</i> translates the letter in which Oracle kinda-sorta tells customers it was pwned

TL;DR: Move along, still nothing to see here - an idea that leaves infosec pros aghast

Legal clock ticking for Microsoft over alleged software license abuses

With weeks to meet terms of settlement agreement, engineers in Redmond still don't have a product to show CISPE

Bezos cost Amazon more than Jassy did in 2024 compensation stakes

Exec pay outlined in Proxy Statement, and things did not go well for either workforce or calls for climate transparency reports

Google offers 7th-gen Ironwood TPUs for AI, with AI-inspired comparisons

Sure, we're doing FP8 versus a supercomputer's FP64. What of it?

Japan serves Google a cease and desist order over its Android bundling deals

Won't let the Big G require its apps and search to be installed on smartphones