Tuesday, July 1, 2025
Google search engine
HomeTechnologyCyber SecurityHacker 'NullBulge' pleads responsible to stealing Disney's Slack information

Hacker ‘NullBulge’ pleads responsible to stealing Disney’s Slack information


A California man who used the alias “NullBulge” has pleaded responsible to illegally accessing Disney’s inside Slack channels and stealing over 1.1 terabytes of inside firm information.

In line with the U.S. Division of Justice, a 25-year-old named Ryan Kramer created a trojan horse in early 2024 that was promoted as an AI picture era software on GitHub and different platforms.

Nevertheless, the DOJ says this program was really malware that allowed Kramer to entry the pc of those that put in it to steal information and passwords from the system.

In line with the Wall Avenue Journalone of many individuals who downloaded this system was a Disney worker, Matthew Van Andel, who executed it on his pc. This gave Kramer entry to his system, together with the passwords saved in his 1Password password supervisor.

Utilizing Van Andel’s stolen credentials, Kramer gained entry to Disney’s Slack channels, the place he downloaded 1.1TB of company information.

“By accessing M.V.’s Disney Slack account, defendant gained entry to personal Disney Slack channels, and in or round Might 2024, defendant downloaded roughly 1.1 terabytes of confidential information from hundreds of Disney Slack channels,” reads a plea settlement seen by BleepingComputer.

The Division of Justice says that Kramer then contacted Van Andel, posing as a Russian hacktivist group referred to as “NullBulge,” warning that his private data and Disney’s stolen Slack information could be revealed if he did not cooperate.

After receiving no response, NullBulge posted a message on the BreachForums hacking discussion board on July 12, 2024, titled “DISNEY INTERNAL SLACK,” the place he claimed to have breached Disney and leaked the 1.1TB of stolen information, together with Van Andel’s private information.

“1.1TiB of knowledge. virtually 10,000 channels, each message and file potential, dumped. Unreleased initiatives, uncooked pictures and code, some logins, hyperlinks to inside api/ net pages, and extra! Have enjoyable sifting via it, there’s a lot there,” reads the discussion board publish.

In July 2024, defendant contacted M.V. via email and the online messaging platform Discord, pretending to be a member of a fake Russia-based hacktivist group called “NullBulge.” The emails and Discord message contained threats to leak M.V.’s personal information and Disney’s Slack data. One message defendant sent to M.V. on July 8, 2024, threatened that in order to “ensure this information remains undisclosed, I need your cooperation,” and warned that if M.V. contacted anyone about the message, “we will drop our data publicly and loudly without so much as a warning.” Defendant also threatened that this would be a “major, major mistake” for M.V.’s “information and career at Disney.” Another email sent to M.V. on July 12, 2024, with the subject line “You sure that’s how you want to play?”, stated, in part, “Respond, do what we want, or end up on the net. Your choice. We will not contact you again.”  On July 12, 2024, after M.V. did not respond to defendant’s threats, defendant publicly released the stolen Disney Slack files, as well as M.V.’s bank, medical, and personal information on multipleKramer’s Disney publish on the BreachForum hacking discussion board
Supply: BleepingComputer

Kramer has pleaded responsible to at least one depend of accessing a pc and acquiring data and one depend of threatening to break a protected pc. Every cost carries a statutory most sentence of 5 years in federal jail.

He has additionally confirmed that two extra folks downloaded his malware, permitting him to realize entry to their computer systems. The FBI is at the moment investigating these extra folks.

His preliminary courtroom look in Los Angeles federal courtroom is anticipated to be within the coming weeks.


Red Report 2025

Based mostly on an evaluation of 14M malicious actions, uncover the highest 10 MITRE ATT&CK strategies behind 93% of assaults and find out how to defend in opposition to them.

Learn the Purple Report 2025



Supply hyperlink

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments