Ubiquiti 'Catastrophic' Data Breach

Published Mar 31, 2021 17:49 PM

Ubiquiti has grown to be a major networking supplier, growing strongly in 2020, but now the company has suffered a breach that cybersecurity researcher Krebs has called 'catastrophic'.

IPVM Image

Inside this report, we examine:

  • Details of the breach
  • Whistleblower claims
  • Potential for impact in surveillance
  • Comparison to Verkada hack
  • Ubiquiti lack of response
  • Effect on user confidence
  • Impact on Ubiquiti stock price

The **** ******

** ******* ****, ****,******** ******** ***** ** * **** breach, **** ************ ****** ** **** of ***** ******* ****** ** * "third-party ***** ********" (****** **** *** not **** *** ********). ******** **** this **** "*** *******" *****, ***** addresses, *** ****** *** ****** *********, but **** **** ***** *** ** indication ** ************ ******** ********* *** user ********.

**** ******* *********** **** ***** ****** passwords *** ****** ***-****** **************, *** did *** ***** ******** ******.

Whistleblower ****** "************"

*******,** * ***** **** ****, ******** ********** ***** ***** **** that * ************* *** ****** ******** respond ** *** ****** ********* ** as *** **** ****** **** ********'* email ******* *********, ******* ** "************."

“** *** **************** ***** **** ********, and ***** ******** *** ********* ******* to ********** ******* *********,” [*** *************] wrote ** * ****** ** *** European **** ********** **********. “*** ****** was *******, ******** **** *** ** risk, ****** ** *********’ ******* ******** in ************ *** ***** ****** *** world *** ** ****.”

*** ************* ******* ****** **** ******** legal ******* ******* ** ****** ***** of *** **** **** ** *** breach *** ***** ******** ******.

Ubiquiti *** ******* ********

*******, *** ************* ****** **** *** unnamed "*****-***** ***** ********" ********* *** simply ********'* ******* ** ****** *** Services, ***** **** ******* *** ******* by ******** **********, *** ******. ** further **** **** ********* ****** **** administrator ****** **:

"*** ******** *** ********, ********* *** S3 **** *******, *** *********** ****, all *********, *** **** ******** ***********, and ******* ******** ** ***** ****** sign-on (***) *******."

**** ***** ********'* ***** ** "** are *** ********* ***** ** ******** of ****** ** *** ********* **** host **** ****" **** ********. *** whistleblower **** **** **** ******** *** not **** ****** **** ** *********, so ** ** ******** ******** ***** not **** ***** ** **** **** was ******** ** ***.

*******, ********* **** ***** *** ********* to *** ****** *** ******** ** bitcoin (~$*.* ******* ***) ** ******** them *** ****** ***** ***** ***** hack, ****** ******** ******* *** ******* these ********* ******* ******** **** *******.

Potentially ***** ******

** *** *************'* ******** ** **** attackers ******** *** ****, ** ** possible **** *****' ******* *** **** been ********, ****** ** **** ***** no ******** ** ************ ****** ***** the ******. ***** ********'* ******** ** video *** ****** ******* *** *****, their ******** **** ********** ******* ** ***** ************ (*** our *******).

**** ***** **** ***** *** ****** of ********* ******** ******* ***** ** unlocking ***** ** *******, *** ******* impact ** ************ ******** ** *********** large. **** *** ***** ******* ***** are *******/**-** ****, **** ****** ***** disable *********, ******/*** ******** ******* ***********, or ****** *** ****** ** ***** security ******.

** ******** ********* *** ***** ** these ******* ***** ****** **** *** unauthorized ****** ***, ** **** **** not *******, ****** ********* *** ****** two-factor **************.

Compared ** ******* ****

**** ********** **** ****, ********* ** *** ******** ****** gained ****** ** ******** ******* *** administrator ***********, ** **** **** *** credentials ****** ** * *********** ******** account.

****** *** ******* ****, **** *** not * ********* ***** ***** ******* simple *******/************* ****** ** ******** *******. Only **** ********* **** **********. ********* still ***** **** ****** ** ******* passwords *** ************ ****** ******* ********.

No ******** *** **** ******** (** ***** ****)

******** *** *** ********* ** ***** on *** *************'* ***********. ***** **** they **** *** ********* ** ******** requests *** *******, *** **** **** responded ** ****** ********* ** *** story, **************.

************, ******** *** *** ********* *** ***** *********** *****' ****** (*** ** ***** main ***** ** ************* **** *****). That ****** *** ******* **** *** comments ** ** *** **** ** writing **** ** ********.

Update: ******** ******** ********* (** ***** ****)

******** *** *** ******** ********* ** Krebs ** ***** **** ******* *** has******** * ********* ** *** ******.

******** ** ******** ** ***** ******** analysis ** *** ******* **** ***** that ******** **** *** *** ********:

...****** **** **** ******* *** ******* with ******* ** *** ******** ** customer **** *** *** ******** ** our ******** ***** *** ************ ** January **.

**** **** *** *** ******** ********* to ****** **** ***** ****** ** releasing ****** **** *** **** ******** IT *********** *** ***** ******* ** have ******** ******** ****. **** **** go ** ** *** **** *** working **** *** *********** *** ****** comment *******.

*******, ******* ******* *** ** ********* ******** ** ********'* *********, *** whistleblower ****** **** ******** *** *** logging ******** ******, ** **** ****** know *** **** **** **** ********* have/do *** ****.

IPVM Image

Users ****** **********?

**** **** ** ****** ** ******* shake **** ********** ** ********. ** early *****,******** ******** ****** ******** ***** *********** made **** *****' ******* ************, **** *********** *** ******** ** issues ** **** ******* (********** ** * **-**** ***** ******). ******** **** *** **** ***** to ******* ***** ******** *** ****** operation ********** **** ******** **** ***** ***** line, ******* **** ***** ** ******** whether ** ******* ******** *** ********** ***.

*****' ****** ** ****** ** ******* increase **** *********.

Stock ***** ******** / ********* ********** *****

********'* ***** *** ****** **** **** 10% ***** *** ***** ****** *** the ***** ** ***** ******* ****** what ** *** **** * ****** ago:

IPVM Image

************, ******** *****-****** ******** (*,*) **** **** ***** ******* ******** for ********* ********** *****. ***** ***** allege **** ******** ********** ************* ********** the ******** ** *** ****** ** order ** ***** ****** ** ***** stock *****.

Editor's ****:

** ****** **, ****, ***** ********* ********* ******* ** *** ****, titled "***** ******** ** ********":

**** ****, * ****** * ****** of ******** ***** * ********* “******” at ********. ** **** ****** *** that ********* *** *** ****** *** has ***** **** ******** ** ******* prosecutors *** *** ******* ********** – which ******** ********* ***** *********** ** the *****.

** * ****** ** *** *** information **** *** **** ******** ** me, * ** ****** **** ***** in *** ******** ** ** ****** or *** *********** ** ******** ** me. * ****** ******** ** ****** that ** ******** *** ******** ******* and *******.

**** ****, * ****** *** **** and, ** * ******, * ***** like ** ****** ** ********* ********* to ********, *** * **** ******* to ****** ***** ******** **** ** website.

Vote ***

**** ** *** ****:

Comments (32)
UE
Undisclosed End User #1
Mar 31, 2021

**** **** ** ****** ** ******* shake **** ********** ** ********. ** early *****,******** ******** ****** ******** ***** *********** made **** *****' ******* ************, **** *********** *** ******** ** issues ** **** ******* (********** ** * **-**** ***** ******). ******** **** *** **** ***** to ******* ***** ******** *** ****** operation ********** **** ******** **** ***** ***** line, ******* **** ***** ** ******** whether ** ******* ******** *** ********** ***.

**** ***** *********, *** ********, *** the **** ******* ** **** ***** combined ** ****. **'* * ******* in ** **** ********* ****** ** operation. ***** ** * *****, ******* as ********** ********, ****'** **** ********* in ** **********. **** ** *** member **** ********* **** *********. * trust *****, *** ** **** ***** his ****** ** **** ** ******* on **** *** *** *********. ********** to *** ***** **** ****, ** anywhere ** ***.

(3)
(1)
Avatar
Ethan Ace
Mar 31, 2021

** **** ** ******** *** ******** to *** ** **** ** ********. It's ****** *** ***** ** ****. There's **** ** ******* ** *** stock ** ***** ** ******** ** fall. ** ****** **** **.**% ** the ***, *** **** ***** **** where ** *** **** ** *********. It's **** ******** ****** ***** *** most ** *** ***.

**'** ****** **/**** ******** ******** ** the ***** ******. ***** ***** *** waiting, ** **** — ***** ******** to **** ** ******* ***** **** on ***** ****** **** ** ********.

(3)
Avatar
Ethan Ace
Mar 31, 2021

***** **** **** *** ********, *'** asked **** ******** ***** ** **** were ***** ** *** ****** *** saw *** ******* **** *****, ** addition ** **** **** ********* **** Ubiquiti ********. **** *** ****** *** of ** *** *** ***** ***** to *****. *** **** ** ** found ** ** *** ****. ** we *** *** **********, *** *** sure ** ** *** (** *** use *****), **'* ******* *** **** users ******** *** *** ******** ******.

** **** ** *** ***** ****** else ** ******* ***** **, *'* also ** ******* ** ****.

(2)
(5)
Avatar
Brian Karas
Mar 31, 2021
Pelican Zero

* ***'* ****** ********* ** ***** from ********. * *** **** ***** this ******* ***** ****** ******* ** the ****, *** ******* **** ****.

(2)
(2)
UI
Undisclosed Integrator #3
Mar 31, 2021

* *** ******* ** *****.

(3)
UI
Undisclosed Integrator #4
Mar 31, 2021

***** ***** ***** ** ** *** last *** ****. **** **** ******* email (****) *** ***** ** ** inbox. * **** **** **** *** read ** ** **** ** *** emails * *** **** **** *** marketing. ******* * **** * ****** password *** **** ******* *** ******* but * **** **** *** **** to **. *'** **** ****** **** LastPass ** ****-****** ********* *********...***** *'** be ********** **** *******.

UI
Undisclosed Integrator #9
Apr 03, 2021

** ****'* *** ***** **** ********? LastPass ******** *** *** *** *** set *** ******* ** ****** **** closing *** *******. *** ***** **** password ******** ** ****** ***** **** logged ** ** *****. ** **** users * *** *** ****** ****** for ***** ******** *******. **** *** are ** * ********'* ******** *** they ****** *** ********, * ********* suggest ** ** **** ****** ****** as **'* ******** ** *****. **** choose *********** **** ********. * *** LastPass *** **** *** * *****, but ** ** *****, ** *****'* remain ****** **.

(2)
UI
Undisclosed Integrator #9
Apr 04, 2021

****** *** *** ****. * **** every ******** *** *** ** ***** is *** *** **** **** **** someone ***** **** ****** ****** ** the ******** *******. * ****** **** LastPass *** ****** *** ** * recall *********, ** **** *** ******** due ** *** ****** ********** ** place. * ***** * ** ******* for ** **** * ***** ****. She **** ****** *** ****** ******** and *** ** ***** *** *******. However, *** ***** **** *** **** and ***** ** *** *******.

* ******* ******* ** ***** **** which *****'* **** ** ****** ***** accessed ******** **** **** *****.

** ** ******** ***'* *** ***** for ********, ***** *** ******** ******** must ** ** *****. ** ******* could **** ****** ** *** ****** password **** ****** ***********, **** *******'* have *** ****** *** ** *** industry ** **** ******* ***** **** are ****** ** ** *** ******* should **** **** *********** *** **** how ** ** ***** **** **.

** **** ****'* **** *** ******* or *** * .*** ****** ****** of *** ******** *********, ****'* ** them, *** ********. ******** ***** ******* 2FA, *** *** *** **** ** going ** ****** ** *********** ** be *** *** ** ***********.

* **** **** *** ** ********* for **** ******** * ***'* ****** care ***** (**** *** ****) *** need ** ******. * ******* *** password ** ******* ** ** ******* issue. ** **'* *** *********, ** can't ******** **. ** **'* *** complex, ** **** ** ***** ** down ** ***** ** *********. ******** managers **** ***** ******* ** ***'* remember * ********* ******* ******** *** every ****** ******* *** ********* **** so **** ******** ** **** ***** of.

**** ** *** ***** **** *******; many ***** ***'* **** ****** ********* or *** ** ***** ***** ******** and **** ***'* ******* **** *** email ******* *** ** * *** to **** ********, ********** ** *** isn't ******* ** * *** ** accounts. ** **** **** ***** *** too **** ** ******* *** ******* it's ** ***** **** *** **** users *** ********* *** **** *** convenience.

(1)
AM
Andrew Myers
Apr 05, 2021

**********. ** *** ****** ******** ******* gets ******, ****'* ******** *** ** LastPass. *****'* *** **** ******** *** do ** *** ** ***** ***** does ********* ****. **'* ** ** Ubiquiti ** ***** ***** ****** ****** and *** *** ***** ******** ** place.

* **** ****** ***'* **** *** wrong ******* **** ****. ** **** Hunt *** **** ****** *** *****,******** ******** ***'* **** ** ** perfect, **** ****** **** *** ***** one. (******** *** *** ****************, ******)

**** ***** ***'* **** ****** ********* or *** ** ***** ***** ******** and **** ***'* ******* **** *** email ******* *** ** * *** to **** ********, ********** ** *** isn't ******* ** * *** ** accounts.

****** **

(1)
(2)
UM
Undisclosed Manufacturer #2
Mar 31, 2021

***** ** ***** **?

Avatar
Ethan Ace
Mar 31, 2021

********** **********, *** ***** ****, **.

(1)
(2)
UI
Undisclosed Integrator #5
Apr 01, 2021

** **** ***** *** ********* *** enable *** *** *** **** *****.

**** ** ******** ****** *******. **********, only * ** * ******** **** affected ****.

(1)
Avatar
Ethan Ace
Apr 01, 2021

Update: ******** ******** *********

******** *** *** ******** ********* ** Krebs ** ***** **** ******* *** has******** * ********* ** *** ******.

******** ** ******** ** ***** ******** analysis ** *** ******* **** ***** that ******** **** *** *** ********:

...****** **** **** ******* *** ******* with ******* ** *** ******** ** customer **** *** *** ******** ** our ******** ***** *** ************ ** January **.

**** **** *** *** ******** ********* to ****** **** ***** ****** ** releasing ****** **** *** **** ******** IT *********** *** ***** ******* ** have ******** ******** ****. **** **** go ** ** *** **** *** working **** *** *********** *** ****** comment *******.

*******, ******* ******* *** ** ********* ******** ** ********'* *********, *** whistleblower ****** **** ******** *** *** logging ******** ******, ** **** ****** know *** **** **** **** ********* have/do *** ****.

IPVM Image

(2)
Avatar
Ethan Ace
Apr 01, 2021

********'* ****** *** ********* ****** **** discussions ** **** *****, *** * lot ** ******* **********:

IPVM Image

(1)
UI
Undisclosed Integrator #6
Apr 01, 2021

** **** **** ***** ***** ******** for ***** *** *** **** ****** been ***** **** *** *******. ** terms ** ** *********** ********** *** majority ** ******* ** *** ** conjunction **** ***-******** ******** ******** **** not ******* *** **** ** ***** access (*******, **'*, ***...) *** **** again ***** ** *** **** ***** that ** ****** ** "******" ** manage ******** ** *** ************ ****** safeguards *** **** **** ************ *** your ******* *** *******. ********* ******** will ** * ****** **** *********** moving ******* ***** ***** ** **** using ***** ******* ***** **** ** support ** *** ******* ***** **** issue **** **** ** ******** ***** other ******* **** ****** ** ***'* use ***** ***** *** ******** *** utilize *** *** *** ***********.

(2)
(1)
U
Undisclosed #7
Apr 01, 2021

* *** ******** ** ****. * searched ** ***** ******* *** *** account ** **** **** ******** *** I **** *** ******** *** ************ about ****.

(1)
Avatar
Christopher Halvorson
Apr 01, 2021
@securitybaer • IPVMU Certified

*** ************* ** **** ***** ***'* automatically ** *******, ** **** ** reported **** ** ***'* *** **** did *******; *'* *** *** *** epic **** ********* ** ****** ******* meets **. *****... *** **** **. They *** **** ****** ***** ************, and *'* *** ********* *** ************* with *** ********, * **** ***** that **** ***** ** *** *** this ***** ***** ****,

* ** **** ***** ********** ******, this ***** *** **** ***** **** a ***** ***** *** ** ****** several **** ** ***** ***** ** Ubiquiti. * **** ** **** ******* blower *** ***, **'* ******* ****** now.

(3)
(1)
AM
Andrew Myers
Apr 01, 2021

* ** **** ***** ********** ******, this ***** *** **** ***** **** a ***** ***** *** ** ****** several **** ** ***** ***** ** Ubiquiti. * **** ** **** ******* blower *** ***, **'* ******* ****** now.

***, ****'* ********, *** ***'** ********** that *** ************* ********* * ******* crime.******* ******* - *********

* *******'* ************ *********** ... ********* as ******** ** ***** *** ******* has * ***** ** ********* ***. The *********** **************** ** **** *********** in ********* ** * ********* **** ... *********** ***** **** ** ************ *** ********** ************* ** ***'* own *** ** *** ***** ** goods ********* ** ***'* **** ** another.

Avatar
Christopher Halvorson
Apr 01, 2021
@securitybaer • IPVMU Certified

***. *** * **.

(1)
(2)
AM
Andrew Myers
Mar 30, 2022

***, * **** ***** ** **** story ***** *****.

***** **** *** **** ******* ***** about *** ************* *** ***** ** trustworthy. ** ********, ****** ******* *** ***************** ***** *** **** ** *** first ***** *** ****** ** ****** Ubiquiti *******. ***** ******** ****'* *** up, ** ***** *** ***** ** Krebs. ***** ****** * ****** ** here:******** ********* ******* **** *********, ******* 2020 “******” – ***** ** ********

***, ** ***** ************ ** ***** ***** *** **** of *** ****** ** ****. * *** **** *** ********* was ****** ******** ** *** ****, but *'* *** **** **** **** much ** ***** **.

Avatar
Ethan Ace
Apr 01, 2021

* ***'* ************* ***** **************, *** Brian ***** *** **** ****** *** a **** **** *** ***** ***** things *********. ** ** ****** ******** that ** ***** ******* ** ***** claims ******* ********* ******* *** ************* first. **'* ******** **'* *** ******, but * ***'* ***** **'* ******.

(2)
Avatar
Christopher Halvorson
Apr 01, 2021
@securitybaer • IPVMU Certified

* *****. * ***'* ***** ****** it ***** ******** ** ********** ***** if *** ******* ****** ****'* ******* the *****. *** ** * ***** Krebs ****** ******** ** ********** *** whistle ******....

**** ** *** ******* ***.. ** hold * **** ***** ** ** comments. * ***** **** **** ** the **** ******* **** ** **** be *********** ** *** * **** investigation.

(1)
JH
John Honovich
Apr 01, 2021
IPVM

*** ***** ** *** ** **** this ** ****** ***** ** ****** a **** *************, ** ***** ****:

“** *** **************** ***** **** ********, and ***** ******** *** ********* ******* to ********** ******* *********,” **** ***** in * ****** ** *** ******** Data ********** **********.

******* ** *** ******** **** ********** Supervisor ***, ** ******, ** **** cases, ********** **** **** ****** ******* an *************. **** ** *** ******* I ** ******* ** *** ******.

(2)
(2)
UI
Undisclosed Integrator #8
Apr 02, 2021

** **** ***** ** ***-******* *** started ******** **** ********* ***** ********** efforts *** ********** ********. **'** **** selling *** ********** ******** ***** '**. Even **** *** ******* ******** *** feature ************* ****** *** *****-****** **** always **** *** ******. ** *** many ** *** ********* **** ***** all **** ******* ***** ***** ***** services *** ***** ********** *** **** before ********* **** **** ***** ******. We **** ******** ******** ***** ********, so **** ** **** ***'* ***** their ***** ********** ******** ** ***** last *****(******** **** ******** ** *****).

UI
Undisclosed Integrator #9
Apr 03, 2021

*** ***** ** **** ***** ***** controller ***** *****'* ******* *** ******* using * ***** *******. * ***'* want ** *** * ***** *******. I **** ***, *** **'* *** connected ** *** **********. *** **** find **** ***** ***** ********** ***, especially ***** **** ****** *********** ** into ****.

* ***** ******** ** ****** ******* shit ** ***** ** ************* ******. They **** *** ****** **** **** want ** ** *** ***** *** then **** ** **** ****** *** excuse ** *** ****** * ***** team ** * ***** ***** *** they **** ****** *** ** * result. * **** **** **** ******** way *** **** ******** *** ******* (especially ** ****** *****) *** **** have ** ***** *********. *** *** pissed * *** ** ****** *** when ** ****'* ******* ***** ***********. They ***** *** ********* ** *** forum *** ******** ****** ** ** support. *** **** ******** * **** as ** *** ****.

*'* *** **** **** ********* **** realize **** ***** ** ***** **** without ****** ********-******* *************. ********'* ********'* aren't ********* *** ***** ** *** typical ********* ******** ********* ***'* **** as **** **** **** ******* **** base ** ***** *********** *** ****** make **** ******** ** *****.

* ***** *** ***** ********, *** I'm ****** ********* ***** ***** ********* and *** ****** **** *****'* ******* much *************.

(2)
(1)
PG
Pavel Grozdov
Apr 04, 2021

*'** ***** **** **** ** * fan. * **** ***** *** ********* and **** ****** ******* *** ******** build ******* ** **** *** *********** of ***** ******** ***** ** **** or ***** **** ***** ***********.

Avatar
Hauke Kerl
Apr 07, 2021

*************, **** **** *****:Never ***** *** ******** *** * ********... *** **** ** ***** *** ****...Damn shame, highly innovative and top products. But security is often sloppy (at many companies). If all this is true, it is close to "intent".

UI
Undisclosed Integrator #9
Apr 07, 2021

* *****'* **** **** *** * firewall ****** ** * *** *********** applications * **** *** ***. ***** firewalls ****'* **** ***** *** ****'* very ******** ** ***** ** *** Unifi ****. * **** *** ******* firewalls **** ********'*.

*******, *** ******** ***** **** ****** then ** **** *** *** * firewall. ** *** *** *** ******* from **** *** ***** ** **** major **********, **** ***** *********** *** in *** ******* ******* * ****** of ******* **** *** ********* ** a ***** ******.

**** ***** ****** ** ** ******* to ******* ********* ** ***** *** cloud **** ********.

Avatar
Ethan Ace
Apr 08, 2021

***** ***+ ******** *** ** *****, Ubiquiti **** ****** ************ ****** ********** *** ***** *******.

IPVM Image

* ****'* *** *** ******** ** the ******, *** * *****'* **** up **** ** ***** *** *******. I'm *** **** **** *** ********** were, *** *** ****** ** ******* that ****** ****'* *****.

(1)
(2)
(2)
TJ
Tay Joo Tang
Apr 09, 2021

** * **** ****, ** ***** that ******** *** **** *********** *** days **** *** ** ************ ***.

******* ** ****** ** *** **** on *** **** ** ****...

U
Undisclosed #10
Apr 21, 2021

(2)